GPH Intelligence - Healthcare Vendor Finder
REMOTE · GPH-MCP-SERVER.PAGES.DEV · SCANNED SEP 22
Find 76,000+ curated healthcare service vendors across 25 categories and all 50 US states.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security74
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability76
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 1778 tokens (~444/item across 4 items; 4 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 4 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 4 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities20
- Spec-recency check failed: implements MCP spec 2024-11-05; the latest is 2026-07-28. See how to fix → Fail
How do I install the GPH Intelligence - Healthcare Vendor Finder MCP server?
GPH Intelligence - Healthcare Vendor Finder is a hosted endpoint at https://gph-mcp-server.pages.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · gph-mcp-server.pages.dev
claude mcp add --transport http crindo2-gph-mcp-server 'https://gph-mcp-server.pages.dev/mcp'
{
"mcpServers": {
"crindo2-gph-mcp-server": {
"url": "https://gph-mcp-server.pages.dev/mcp"
}
}
} {
"servers": {
"crindo2-gph-mcp-server": {
"type": "http",
"url": "https://gph-mcp-server.pages.dev/mcp"
}
}
} [mcp_servers.crindo2-gph-mcp-server] url = "https://gph-mcp-server.pages.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"crindo2-gph-mcp-server": {
"type": "remote",
"url": "https://gph-mcp-server.pages.dev/mcp",
"enabled": true
}
}
} openclaw mcp add crindo2-gph-mcp-server --url 'https://gph-mcp-server.pages.dev/mcp' --transport streamable-http
mcp_servers:
crindo2-gph-mcp-server:
url: "https://gph-mcp-server.pages.dev/mcp" {
"McpServers": {
"crindo2-gph-mcp-server": {
"Transport": "http",
"Url": "https://gph-mcp-server.pages.dev/mcp"
}
}
} assistant mcp add crindo2-gph-mcp-server -t streamable-http -u 'https://gph-mcp-server.pages.dev/mcp'
{
"mcpServers": {
"crindo2-gph-mcp-server": {
"type": "http",
"url": "https://gph-mcp-server.pages.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 17 Sept 26 0
- Tool “get_provider_detail” rewrote its description, which is the text the model reads security
- “search_providers” reworded the description of “city” cosmetic
- 13 Sept 26 0
- Tool “get_provider_detail” rewrote its description, which is the text the model reads security
- Tool “match_practice” rewrote its description, which is the text the model reads security
- Tool “search_providers” rewrote its description, which is the text the model reads security
- Schema quality: 394 → 438 ▼ functional
- “search_providers” reworded the description of “min_rating” cosmetic
- “search_providers” reworded the description of “practice_size_fit” cosmetic
- 11 Sept 26 0
- Tool “get_provider_detail” rewrote its description, which is the text the model reads security
- 26 Aug 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 25 Aug 26 +1
- Stability: 0.97 → pass security
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 2 Aug 26 0
- Schema quality: 313 → 380 ▼ functional
- New tool “list_categories” functional
- “match_practice” reworded the description of “category” cosmetic
- “match_practice” reworded the description of “city” cosmetic
- “match_practice” reworded the description of “practice_size” cosmetic
- “match_practice” reworded the description of “state” cosmetic
- “search_providers” reworded the description of “category” cosmetic
- “search_providers” reworded the description of “min_rating” cosmetic
- “search_providers” reworded the description of “state” cosmetic
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 22 Sept 2026 · Probed https://gph-mcp-server.pages.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=gph-mcp-server.pages.dev | CN=YE2,O=Let's Encrypt,C=US | 10 Aug 2026 | 8 Nov 2026 | ECDSA 256 | ECDSA-SHA384 | 5e79a231831af279004eb7b9e50b163c0d8 |
| SANs: *.gph-mcp-server.pages.dev, gph-mcp-server.pages.dev | ||||||
| CN=YE2,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 4df3b15dd6c0784c507cd37b58e6f115 |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of gph-mcp-server.pages.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| pages.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://gph-mcp-server.pages.dev/mcp | Verified | 200 | |
| http (plaintext) | http://gph-mcp-server.pages.dev/mcp | HTTPS enforced | 301 | https://gph-mcp-server.pages.dev/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
get_provider_detail Get Vendor Profile Detail ~272
Get the full profile of one healthcare vendor by slug. Use this after match_practice or search_providers when the user asks to "tell me more about [vendor]", "what services does [vendor] offer", "is [vendor] verified", or wants contact info or services for a specific provider. Returns company_name, category, city/state, quality_score (0-100; profile completeness, not a quality rating; 0 means never scored), verified status, description, services offered, practice_size_fit, phone and website where listed, Google rating and Google review count where present, and the profile URL. Where a vendor has been enrichment-extracted, the description, services and practice-size fit come from that extraction, the profile adds certifications and compliance attestations, locations served and founding year where extracted, and the response states the extraction confidence and what it was grounded in (where the extraction abstained on practice-size fit, the legacy listing value is returned and labelled as not extracted); otherwise the legacy listing fields are returned. Slug comes from match_practice or search_providers results; returns an error if the slug is unknown.
| Name | Type | Req | Description |
|---|---|---|---|
| slug | string | yes | Provider slug identifier (e.g. 'ams-solutions-inc-dallas-tx'). Obtained from match_practice or search_providers response. |
| Name | Type | Req | Description |
|---|---|---|---|
| content | array | yes | – |
| count | – | – | Always 1 on success; absent when isError. |
| ids | object | – | Absent when isError. |
| isError | boolean | – | Present and true only when the slug is unknown or the fetch fails. |
No examples provided.
list_categories List Healthcare Vendor Categories ~99
List every service category in the GPH vendor directory with its live provider count. Call this FIRST when you do not already know which category fits the user's need, when a category search returned nothing, or when the user asks what kinds of vendors are available. Returns all 25 categories with {category, slug, providers}. The category names returned here are the exact values match_practice and search_providers expect (common aliases also resolve). Takes no arguments.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| content | array | yes | – |
| count | integer | – | Number of categories returned; absent when isError. |
| isError | boolean | – | Present and true only on failure. |
No examples provided.
match_practice Recommend Healthcare Vendors for a Practice ~640
Recommend and rank the best healthcare vendors for a specific medical practice. Use this when a practice manager, physician, or administrator asks for a recommendation, e.g. "recommend a medical billing / RCM company for my practice", "who should I use for credentialing / payer enrollment", "find an EHR for my small [specialty] practice", or "which practice-management software fits a [size] practice in [city, state]". Scores and ranks providers against the practice profile (specialty, size, location, EHR system, budget) and returns up to 5 merit-ranked matches (completeness-scored, no paid placement) with {company_name, category, city, state_abbr, quality_score (0-100; profile completeness -- how many listing fields are filled in -- not a quality or reputation rating; 0 means never scored), final_score (0-100), verified status, description, website, profile_url, slug}. For open-ended browsing without a practice profile, use search_providers. Pass a match's slug to get_provider_detail for the full profile.
| Name | Type | Req | Description |
|---|---|---|---|
| budget_range | string | – | Approximate monthly budget |
| category | string | yes | Service category needed. One of the 25 categories: 'Medical Billing & RCM', 'Credentialing Services', 'Healthcare IT & EHR', 'Practice Management Consulting', 'Healthcare Legal Services', 'Healthcare… |
| city | string | – | City where the practice is located. Send city and state separately, not as a combined `location` string. |
| ehr_system | string | – | EHR system used by the practice (e.g. 'Epic', 'athenahealth', 'AdvancedMD', 'eClinicalWorks'). Helps score providers with compatible integrations higher. |
| practice_size | string | – | Size of the practice by provider count. The parameter is named `practice_size`, not `size`. |
| specialty | string | – | Medical specialty of the practice (e.g. 'Family Medicine', 'Cardiology', 'Pediatrics', 'Dermatology') |
| state | string | yes | Two-letter state abbreviation (e.g. 'TX', 'CA', 'NY'). Send as `state`, not `state_abbr` (`state_abbr` is an output field name only). |
| Name | Type | Req | Description |
|---|---|---|---|
| content | array | yes | – |
| count | integer | – | Total scored candidates before the top-5 slice; absent when isError. |
| ids | object | – | Absent when isError. |
| isError | boolean | – | Present and true only on failure (match request error or no candidates). |
No examples provided.
search_providers Search the Healthcare Vendor Directory ~767
Browse and filter the healthcare vendor directory. Use this for open-ended exploration, e.g. "show me medical billing companies in Texas", "list credentialing services", "what EHR vendors are there for cardiology", or when the user wants to page through options rather than get a scored shortlist. Paginated results filtered by category, location, minimum profile-completeness score, curated Tier-1 grade, and practice-size fit; returns a page of providers with {company_name, category, city, state_abbr, quality_score (0-100; profile completeness, not a quality rating; 0 means never scored), verified status, contact info, slug}. For a scored recommendation to a specific practice profile, use match_practice instead. Pass a returned slug to get_provider_detail for the full profile.
| Name | Type | Req | Description |
|---|---|---|---|
| category | string | yes | Service category to search. One of the 25 categories: 'Medical Billing & RCM', 'Credentialing Services', 'Healthcare IT & EHR', 'Practice Management Consulting', 'Healthcare Legal Services', 'Healthc… |
| city | string | – | City to filter by. Matches one exact city only: the value is compared as a city slug (case and punctuation ignored, e.g. 'San Antonio' matches 'san-antonio'); partial names and prefixes do not match. |
| min_rating | number | – | Minimum profile-completeness score (0-100; how many listing fields are filled in, not a quality or reputation rating). Most providers score 50-85. The parameter is named `min_rating`, not `min_qualit… |
| page | number | – | Page number for pagination (default 1) |
| per_page | number | – | Results per page (1-25, default 10) |
| practice_size_fit | string | – | Filter providers by the practice size they best serve, on the directory's one closed vocabulary: Solo, Small, Mid-size, Large, All. The filter reads the extracted size where one exists and the listin… |
| state | string | – | Two-letter state abbreviation (e.g. 'TX'). Send as `state`, not `state_abbr` (`state_abbr` is an output field name only). National providers always included. |
| tier1_grade | string | – | Filter to the curated Tier-1 provider set by grade: 'A' (top-graded) or 'B' (strong). Tier-1 is a hand-reviewed ~4,400-provider subset; most directory records are not Tier-1, so this narrows results… |
| Name | Type | Req | Description |
|---|---|---|---|
| content | array | yes | – |
| count | integer | – | Total matching providers across all pages; absent when isError. |
| ids | object | – | Absent when isError. |
| isError | boolean | – | Present and true only on failure. |
No examples provided.
What is the GPH Intelligence - Healthcare Vendor Finder MCP server?
GPH Intelligence - Healthcare Vendor Finder is an MCP server listed in the public MCP registry as io.github.Crindo2/gph-mcp-server. Find 76,000+ curated healthcare service vendors across 25 categories and all 50 US states. This page covers its hosted endpoint (https://gph-mcp-server.pages.dev/mcp).
Is the GPH Intelligence - Healthcare Vendor Finder MCP server safe to use?
GPH Intelligence - Healthcare Vendor Finder scores 82 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the GPH Intelligence - Healthcare Vendor Finder MCP server expose?
GPH Intelligence - Healthcare Vendor Finder exposes 4 tools: match_practice, search_providers, get_provider_detail, list_categories. Their descriptions and schemas cost roughly 1,778 tokens of context every time the server is loaded.
Does the GPH Intelligence - Healthcare Vendor Finder MCP server require authentication?
No. We connected to GPH Intelligence - Healthcare Vendor Finder without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the GPH Intelligence - Healthcare Vendor Finder MCP server still maintained?
GPH Intelligence - Healthcare Vendor Finder is still listed as active in the MCP registry. We last reached this channel on 22 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.