Healthcare provider & compliance intel: NPPES lookup, OIG/SAM exclusion screening, FDA enforcement.
Inferred from the transports this listing declares (streamable-http). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read from a real MCP initialize → tools/list handshake against the declared endpoint. No tool was ever invoked — tools/list is the read-only introspection call the protocol defines for this. It reflects what the server advertised at that moment; a hosted endpoint is not pinned to any version and can change without notice.
https://health.dropwatchhq.com/mcp4 tools · 157msprovider_lookupLook up US healthcare providers from the public CMS NPPES registry by NPI, or search by specialty + state (+ optional name/city). Returns NPI, name, specialty, license, location, and an OIG-LEIE exclusion flag on each. Public data only — no PHI.Look up US healthcare providers from the public CMS NPPES registry by NPI, or search by specialty + state (+ optional name/city). Returns NPI, name, specialty, license, location, and an OIG-LEIE exclusion flag on each. Public data only — no PHI.
| Parameter | Type | Description |
|---|---|---|
| npi | string | Exact 10-digit NPI for a single provider. |
| name | string | Provider or organization name substring. |
| specialty | string | Taxonomy/specialty, e.g. 'Cardiology'. |
| state | string | Two-letter state, e.g. 'TX'. |
| city | string | — |
| limit | number | Max results (default 50). |
screen_exclusionScreen a provider/organization against the federal exclusion lists (HHS-OIG LEIE, and SAM.gov if configured). NPI match is exact; name match is flagged and identity-cautious. Returns sourced findings + a disclaimer. Facts, never an allegation.Screen a provider/organization against the federal exclusion lists (HHS-OIG LEIE, and SAM.gov if configured). NPI match is exact; name match is flagged and identity-cautious. Returns sourced findings + a disclaimer. Facts, never an allegation.
| Parameter | Type | Description |
|---|---|---|
| npi | string | — |
| name | string | — |
| state | string | — |
new_exclusionsReturn providers newly added to the OIG-LEIE exclusion list, optionally scoped by state and/or specialty. The credentialing / payment-integrity alert feed.Return providers newly added to the OIG-LEIE exclusion list, optionally scoped by state and/or specialty. The credentialing / payment-integrity alert feed.
| Parameter | Type | Description |
|---|---|---|
| state | string | — |
| specialty | string | — |
| limit | number | Default 60. |
fda_enforcementReturn recent FDA enforcement/recall actions tied to a device/drug firm (openFDA). A manufacturer-risk layer for procurement and payor teams.Return recent FDA enforcement/recall actions tied to a device/drug firm (openFDA). A manufacturer-risk layer for procurement and payor teams.
| Parameter | Type | Description |
|---|---|---|
| firm* | string | Recalling firm / manufacturer name. |
4 of 4 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Healthcare provider & compliance intel: NPPES lookup, OIG/SAM exclusion screening, FDA enforcement.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
This entry publishes no npm package, so Forge has no dependency tree for it. That is a gap in coverage — not a statement that it has no dependencies.