Back to Browse

Ny Omig Exclusions MCP Server

Developer ToolsModerate7.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

New York State OMIG Medicaid provider exclusion screening — fleet #2788.

About

New York State OMIG Medicaid provider exclusion screening — fleet #2788.

Remote endpoints: streamable-http: https://gateway.pipeworx.io/ny-omig-exclusions/mcp

Security Report

7.2
Moderate7.2Low Risk

This is a well-structured MCP server for screening providers against NY State OMIG Medicaid exclusion lists. The server is keyless by design, uses baked static data rather than dynamic imports, has appropriate error handling, and poses no data exfiltration or malicious code risks. Minor code quality observations around input validation and logging do not substantially impact security. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity).

3 files analyzed · 4 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

@pipeworx/ny-omig-exclusions

New York State OMIG Medicaid provider exclusion screening — check a provider by name, NPI or license number against the NY Office of the Medicaid Inspector General's exclusion list, the state-level counterpart to the federal HHS OIG LEIE (leie pack) for New York specifically.

Part of Pipeworx — an MCP gateway connecting AI agents to 1715+ live data sources. This is an independent, unofficial integration — not affiliated with, endorsed by, or published by the upstream provider.

Tools

  • ny_omig_check_exclusion(name?, npi?, license?, limit?) — screens a provider against the ~9,100-row NY OMIG exclusion list. An NPI or license match is an identification (both are exact, provider-specific identifiers); a name match — even an exact one — is a candidate lead only, since OMIG's list carries no date of birth or address to tell same-named providers apart.
  • ny_omig_exclusion_coverage() — total exclusions held, how many carry an NPI or license number, provider-type diversity, the oldest/newest exclusion date, and OMIG's own "data last updated" date for the baked copy this pack serves.

Auth

Keyless.

Data sources

Why this is baked, not a live proxy

OMIG publishes the list only as flat files. Per root CLAUDE.md's standing rule for exactly this shape, the table (~9,117 rows, ~1.3MB as generated TypeScript) is baked by scripts/bake-index.mjs into src/ny-omig-index-data.ts, registered in workers/gateway/src/pack-baked-indexes.json, uploaded to KV at deploy, and injected into every call as args._bakedIndex — never a static module-scope import (fleet #2754: six packs doing that put ~48MB of retained heap into every gateway isolate and cost about one call in four as a Cloudflare 1102). A missing or malformed injection throws loudly rather than answering "not found" — see src/index.test.ts.

Re-run node mcps/ny-omig-exclusions/scripts/bake-index.mjs periodically to refresh the copy and recommit; data_as_of on every response says how stale it is relative to OMIG's own "last updated" banner, so staleness is visible rather than silent.

What this data does NOT include

Every OMIG export — tab-delimited, Excel, and the HTML formatted list — carries only provider name, license number, NPI, provider type and the exclusion effective date. There is no exclusion reason, statutory authority or case citation in this data, unlike the federal LEIE's statutory exclusion-type code. Per-record detail, if OMIG holds any, sits behind an ASP.NET VIEWSTATE postback tied to a freshly-loaded search session rather than a stable queryable endpoint, and was not pursued for this first cut. Every response says this plainly rather than inventing a field OMIG does not publish.

Reachability

Verified live 2026-10-07 from both a laptop curl and a throwaway wrangler dev --remote Worker on the prod account: identical 200 / 535,395 bytes from the Cloudflare edge on tabdelimited.aspx. Unlike oklahoma-code / utah-code / new-hampshire-code, this host needs no Supabase egress relay.

Quick Start

Add to your MCP client (Claude Desktop, Cursor, Windsurf, etc.):

{
  "mcpServers": {
    "ny-omig-exclusions": {
      "url": "https://gateway.pipeworx.io/ny-omig-exclusions/mcp"
    }
  }
}

What this endpoint actually serves

tools/list at https://gateway.pipeworx.io/ny-omig-exclusions/mcp returns the tools in the table above plus the shared Pipeworx meta-tools — ask_pipeworx, discover_tools, search_within, remember/recall and the rest of the gateway-wide set. So the tool count you see is larger than this table: a single-pack endpoint currently lists roughly 30 shared tools alongside the pack's own. The connection's initialize response states its exact scope, and is the authoritative answer for a given day.

This is deliberate, not multiplexing by accident. The meta-tools are what let a scoped connection answer a question this pack does not cover — via ask_pipeworx, which routes across the whole catalog — without you adding a second MCP server. There is currently no way to mount a pack endpoint without them; if the extra schemas cost you more context than the routing is worth, connect to the full gateway once rather than to several pack endpoints.

Or connect to the full Pipeworx gateway to get every pack's tools listed directly, instead of just this one's:

{
  "mcpServers": {
    "pipeworx": {
      "url": "https://gateway.pipeworx.io/mcp"
    }
  }
}

Both URLs reach the same gateway and the same 1715+ data sources. The only difference is which pack's tools are listed directly; ask_pipeworx reaches all of them from either one.

No MCP client? Call it over HTTP

curl -X POST https://gateway.pipeworx.io/v1/tools/ny_omig_check_exclusion \
  -H 'Content-Type: application/json' \
  -d '{"name":"1 STOP PHARMACY AND FOOD MART INC"}'

No account needed for the first calls. Inspect any tool: GET https://gateway.pipeworx.io/v1/tools/ny_omig_check_exclusion. Find one: POST https://gateway.pipeworx.io/v1/tools/search_packs with {"query":"..."}.

Standalone (no gateway account)

This package also runs as a local stdio MCP server — no Pipeworx account, no gateway round-trip:

{
  "mcpServers": {
    "ny-omig-exclusions": {
      "command": "npx",
      "args": ["-y", "@pipeworx/mcp-ny-omig-exclusions"]
    }
  }
}

Or run it directly to confirm it starts:

npx -y @pipeworx/mcp-ny-omig-exclusions

It speaks MCP over stdin/stdout and answers initialize/tools/list/tools/call for only this pack's tools — none of the shared meta-tools the gateway connection above adds. Same source, same tools, no ask_pipeworx routing.

Using with ask_pipeworx

Instead of calling tools directly, you can ask questions in plain English — this works on the pack endpoint above as well as on the full gateway:

ask_pipeworx({ question: "your question about Ny Omig Exclusions data" })

The gateway picks the right tool and fills the arguments automatically.

More

License

MIT

Reviews

No reviews yet

Be the first to review this server!