io.github.cyanheads/medical-codes-mcp-server
REMOTE · MEDICAL-CODES.CASEYJHAND.COM · 2 COMPONENTS · SCANNED AUG 3
Offline US medical code lookup and crosswalk — ICD-10-CM/PCS, HCPCS Level II, RxNorm. Keyless.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score →
Endpoint Security66
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation not fully verified: no authorisation is required to call this server, and 6 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe. See how to fix → View diagnostics → Unverified
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC is configured correctly; the domain's records validate against the full chain to the root. View diagnostics → Pass
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability61
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 2144 tokens (~357/item across 6 items; 6 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management27
- Stability observed for 8 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
- Structured output schemas are declared (100% of tools); any adoption earns full credit.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
remote · medical-codes.caseyjhand.com
claude mcp add --transport http cyanheads-medical-codes-mcp-server https://medical-codes.caseyjhand.com/mcp
[mcp_servers.cyanheads-medical-codes-mcp-server] url = "https://medical-codes.caseyjhand.com/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"cyanheads-medical-codes-mcp-server": {
"type": "remote",
"url": "https://medical-codes.caseyjhand.com/mcp",
"enabled": true
}
}
} openclaw mcp add cyanheads-medical-codes-mcp-server --url https://medical-codes.caseyjhand.com/mcp --transport streamable-http
mcp_servers:
cyanheads-medical-codes-mcp-server:
url: "https://medical-codes.caseyjhand.com/mcp" {
"mcpServers": {
"cyanheads-medical-codes-mcp-server": {
"type": "http",
"url": "https://medical-codes.caseyjhand.com/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 23 to 27. That category is still filling its 30-day observation window: 7 days of observed history at the previous scan, 8 at this one. The score rises as the window fills, whether or not the server changes.
- 1 Aug 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 17 to 20. That category is still filling its 30-day observation window: 5 days of observed history at the previous scan, 6 at this one. The score rises as the window fills, whether or not the server changes.
- 31 Jul 26 +2
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 29 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 7 to 10. That category is still filling its 30-day observation window: 2 days of observed history at the previous scan, 3 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Jul 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 3 to 7. That category is still filling its 30-day observation window: 1 days of observed history at the previous scan, 2 at this one. The score rises as the window fills, whether or not the server changes.
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Jul 26 62
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Aug 2026 · Probed https://medical-codes.caseyjhand.com/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=caseyjhand.com | CN=WE1,O=Google Trust Services,C=US | 7 Jul 2026 | 5 Oct 2026 | ECDSA 256 | ECDSA-SHA256 | 5aad900eb2055a0b0ea55912ec19680c |
| SANs: caseyjhand.com, *.caseyjhand.com | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
DNSSEC secure
Validation of medical-codes.caseyjhand.com. — Secure
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| com. | present | 19718 | 13 | Verified |
| caseyjhand.com. | present | 2371 | 13 | Verified |
| medical-codes.caseyjhand.com. | Verified address RRset verified with the apex keys |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
| Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://medical-codes.caseyjhand.com/mcp | Verified | 200 | |
| http (plaintext) | http://medical-codes.caseyjhand.com/mcp | HTTPS enforced | 301 | https://medical-codes.caseyjhand.com/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
medcode_browse_hierarchy medical-codes-mcp-server ~351
Walk a US medical code system's hierarchy for discovery without a search term. With no `node`, returns the top-level entries (ICD-10-CM categories, HCPCS range buckets, or ICD-10-PCS first-axis values). With a `node`, returns its immediate children. ICD-10-CM and HCPCS use a prefix hierarchy (a shorter code is the parent of a longer one); ICD-10-PCS is axis-based — each of its 7 characters is an independent axis (section, body system, root operation, body part, approach, device, qualifier), but only the top-level Section axis is browsable (omit `node`): positions 2–7 are context-dependent on the preceding axis path and are not enumerable from a flat partial code. Lets an agent orient in an unfamiliar system or enumerate a category's specific codes. A large child set paginates: when the response carries a `nextCursor`, pass it back as `cursor` to fetch the next page.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Opaque continuation token from a previous response's `nextCursor`, to fetch the next page of children/entries. Omit for the top of the list. |
| limit | integer | — | Max entries per page. Defaults to MEDCODE_MAX_RESULTS (50), ceiling 200. |
| node | — | — | A node to expand — or omit / pass an empty string for the top level. For ICD-10-CM/HCPCS, a code whose children to list; ICD-10-PCS supports only top-level Section browsing. Must not be blank or whit… |
| system | string | yes | The code system to browse. |
| Name | Type | Req | Description |
|---|---|---|---|
| axes | array | yes | The top-level ICD-10-PCS Section axis values (only the Section axis is enumerable). Empty when kind is "codes". |
| cap | number | yes | The page size that was applied. |
| codes | array | yes | Child codes under the requested node or top level. Empty when kind is "axes". |
| kind | string | yes | "codes" for prefix-hierarchy children (ICD-10-CM/HCPCS); "axes" for ICD-10-PCS axis values. |
| nextCursor | string | — | Opaque token to pass back as `cursor` for the next page. Present only when more entries exist beyond this page. |
| notice | string | — | Guidance when a node has no children/axes — suggests the top level or a valid node. |
| shown | number | yes | Number of entries returned on this page (codes or axes). |
| truncated | boolean | yes | True when more entries exist beyond this page. |
No examples provided.
medcode_check_code medical-codes-mcp-server ~208
Validate whether a US medical code exists, is current, and is billable in the active bundled release. Returns a discriminated status — valid_billable, valid_not_billable, valid_header, or terminated — with a `whyNot` explaining non-billable and terminated cases (e.g. "valid ICD-10-CM category but not billable — submit a more specific child code"). This is the detail a coder needs before submitting a claim. Auto-detects the system from the code's shape; pass an explicit `system` to disambiguate. A non-billable or terminated code is a successful result with a whyNot, not an error — only a code that exists in no bundled system raises unknown_code.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | The code to validate, with or without dots. Must not be blank or whitespace-only. |
| system | string | — | Force the lookup into this system. Omit to auto-detect from the code's shape. |
| Name | Type | Req | Description |
|---|---|---|---|
| billable | boolean | yes | True only when status is valid_billable. |
| code | string | yes | The code in display form (ICD-10-CM carries the dot). |
| status | string | yes | Validity status. valid_billable = submit as-is; valid_header/valid_not_billable = needs a more specific code; terminated = retired. |
| system | string | yes | The system the code was resolved in, echoed for chaining. |
| whyNot | — | yes | Explanation for non-billable/terminated statuses, or null when valid_billable. |
No examples provided.
medcode_get_code medical-codes-mcp-server ~334
Decode one or more US medical codes to their official descriptions across ICD-10-CM (diagnoses), ICD-10-PCS (inpatient procedures), HCPCS Level II (supplies/drugs/services), and RxNorm (drugs, by RXCUI). Also decodes a National Drug Code (NDC) — hyphenated or 10/11-digit — directly to its RxNorm product offline, tagged `source: "NDC"`. Auto-detects the system from each code's shape; pass an explicit `system` only when a value is genuinely ambiguous. Accepts 1–50 codes and returns partial success: resolved codes in `found`, unresolved in `notFound` with a per-code reason, so one bad code never fails the batch. Set `includeHierarchy` to attach each code's parent and immediate children (with a `childrenTruncated` flag when a code has more children than the cap returns — walk the full set via medcode_browse_hierarchy or medcode_map_codes). The resolved `system` is echoed on every result for chaining into medcode_map_codes or a billability check.
| Name | Type | Req | Description |
|---|---|---|---|
| codes | array | yes | Codes to decode (1–50). Mixed systems are fine — each is detected independently. An NDC (hyphenated or 10/11-digit) decodes to its RxNorm product. |
| includeHierarchy | boolean | — | When true, attach each found code's parent and immediate children. |
| system | string | — | Force every code to be looked up in this system. Omit to auto-detect per code. |
| Name | Type | Req | Description |
|---|---|---|---|
| found | array | yes | Successfully decoded codes, in request order. |
| notFound | array | yes | Codes that did not resolve, with per-code reasons. |
No examples provided.
medcode_list_systems medical-codes-mcp-server ~124
List the bundled US medical code systems with their release identifiers, effective dates, and code counts. Confirms which ICD-10-CM fiscal year, ICD-10-PCS fiscal year, HCPCS Level II release, and RxNorm normalized set are active before acting on any decode, search, or crosswalk result. The corpus is offline and built at package-build time — this call reports exactly which release is baked into the running server. ICD-10-CM/PCS are the US clinical modifications, not the ICD-10/ICD-11 base.
Input schema present but exposes no named parameters.
| Name | Type | Req | Description |
|---|---|---|---|
| systems | array | yes | One entry per bundled code system, in canonical order. |
No examples provided.
medcode_map_codes medical-codes-mcp-server ~501
Crosswalk a US medical code or drug across systems and within a hierarchy. Hierarchy directions: `parents` and `children` walk a code's prefix hierarchy one level per call — immediate parent/children only (depth-1); call iteratively for the full ancestor or descendant path (ICD-10-CM/HCPCS; ICD-10-PCS codes have no prefix parent). A resolvable code with no edge in the requested direction is a successful empty result with a notice, not an error. Drug directions (RxNorm): `name_to_rxcui` (drug name → RXCUI), `ndc_to_rxcui` and `rxcui_to_ndc` (NDC ↔ RXCUI; NDCs accepted hyphenated or 10/11-digit), `rxcui_to_ingredients` and `rxcui_to_brands` (RXCUI → ingredient/brand RXCUIs). Every result carries `source` provenance (which system or edge answered) so a chained call (e.g. into openfda with a resolved NDC) uses the right identifier. The `children` and `name_to_rxcui` directions can return large sets and paginate: a `nextCursor` in the response is passed back as `cursor` (with an optional `limit` page size) to walk the full set; the point directions ignore both.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | — | Opaque continuation token from a previous response's `nextCursor`, for the paginated directions (children, name_to_rxcui). Omit for the first page. |
| direction | string | yes | What to map to. parents/children return the immediate parent or children only (depth-1) — call iteratively to walk a full path; the rxcui/ndc/name directions are RxNorm drug crosswalks. |
| from | string | yes | The source value: a code (for parents/children), a drug name, an NDC, or an RXCUI. Must not be blank or whitespace-only. |
| limit | integer | — | Max results per page for the paginated directions (children, name_to_rxcui). Defaults to MEDCODE_MAX_RESULTS (50), ceiling 200. Ignored by the point directions. |
| system | string | — | For parents/children, force the source code into this system. Omit to auto-detect. |
| Name | Type | Req | Description |
|---|---|---|---|
| cap | number | — | Paginated directions only: the page size that was applied. |
| direction | string | yes | The mapping direction that was applied. |
| from | string | yes | The source value, echoed back. |
| hits | array | yes | Crosswalk results, each tagged with the edge that produced it. |
| nextCursor | string | — | Paginated directions only: opaque token to pass back as `cursor` for the next page. Present only when more results exist beyond this page. |
| notice | string | — | Guidance when a resolvable code has no edge in the requested direction (e.g. a top-level code has no parent; a leaf has no children; ICD-10-PCS codes have no prefix parent). |
| resolvedSystem | — | yes | The system the source resolved in, or null when not system-scoped. |
| shown | number | — | Paginated directions only: number of hits returned on this page. |
| truncated | boolean | — | Paginated directions (children, name_to_rxcui) only: true when more results exist beyond this page. |
No examples provided.
medcode_search_codes medical-codes-mcp-server ~363
Find US medical codes whose official descriptions match a described concept, via full-text search over the bundled index. Every search term must appear — matched first as a token prefix, then as a substring so inflected and compound forms are also found (a "neuropathy" search surfaces "mononeuropathy"/"polyneuropathy" siblings too, not only a standalone "neuropathy" token). Filter by `system` (ICD10CM/ICD10PCS/HCPCS/RXNORM), `billableOnly` to exclude headers/categories, and `chapter`. Use when you have a clinical description and need the code — the reverse of medcode_get_code. Results echo the resolved system per row for chaining, rank exact prefix matches ahead of substring-only matches with a deterministic tie-break, and disclose truncation with a `nextCursor`: pass it back as `cursor` to page through the full ranked set.
| Name | Type | Req | Description |
|---|---|---|---|
| billableOnly | boolean | — | When true, return only billable leaf codes (exclude headers/categories). |
| chapter | string | — | Restrict to a chapter/range bucket (the value from a code's `chapter` field). |
| cursor | string | — | Opaque continuation token from a previous response's `nextCursor`, to fetch the next page of the same ranked result set. Omit for the first page. |
| limit | integer | — | Max codes per page. Defaults to the server's MEDCODE_MAX_RESULTS (50), ceiling 200. |
| query | string | yes | Clinical description to match, e.g. "type 2 diabetes with neuropathy". Must not be blank or whitespace-only. |
| system | string | — | Restrict results to one system. Omit to search all bundled systems. |
| Name | Type | Req | Description |
|---|---|---|---|
| appliedFilters | object | yes | Filters the server applied to the search. |
| cap | number | yes | The page size that was applied. |
| codes | array | yes | Matching codes, ranked by full-text relevance. |
| effectiveQuery | string | yes | The query as the server parsed it for matching. |
| nextCursor | string | — | Opaque token to pass back as `cursor` for the next page. Present only when more matches exist beyond this page. |
| notice | string | — | Guidance when nothing matched — echoes the query and suggests how to broaden. |
| shown | number | yes | Number of codes returned on this page. |
| truncated | boolean | yes | True when more matches exist beyond this page. |
No examples provided.