How a brand is tied to a directory.
Every link in the chain from a brand name to an audited directory file comes from a named public federal record. Nothing is inferred, and the two places where a judgement is applied are written down here.
The chain
A brand page connects a marketing name to issuer registrations, each registration to the directory file it registers, and each file to the host that publishes it. The audit measures the published file; the brand page routes to it. The two are kept apart on purpose: a rate is a property of a file, and it is never attributed to a legal entity on these pages.
Brand → issuer registration → registered directory URL → publishing host. Each arrow is one join in one public file.
The two federal files
- CMS Plan Attributes PUF. Supplies the brand name a consumer actually sees, in CMS's own field for it. Rollcall keeps Individual-market medical issuers and drops standalone dental, using the file's own market and dental columns. Both filters matter: the URL file alone names 346 issuers and a third of them sell only dental.
- CMS Machine-Readable URL PUF. Supplies, for each state and issuer ID, the directory index URL the issuer registers under 45 CFR 156.230(b)(2). This is the issuer's own filing, not Rollcall's discovery.
The joined register is published at data/issuers.json and regenerated from the PUFs, never edited by hand. It names its plan year and carries no Rollcall figure.
How names group, and how they do not
The default is one brand page per exact CMS marketing name. Names group only through an explicit alias list, and every alias is a deliberate claim that the matched registrations are one operating brand. The alias list exists because CMS's own file needs it: it spells one company's name two ways across states.
- Blue Cross licensees are never merged. Seventeen independent companies share the words in their names. One page for the words would attribute each company's directory to an entity that does not operate it, so there are seventeen pages.
- No fuzzy matching, anywhere. A name either matches an alias prefix exactly or stands alone. When two distinct names would collide on one web address, the build refuses to run rather than quietly keeping one of them.
What attribution does not claim
- A host is not an operator. The server a directory file sits on may belong to a vendor or a shared platform. The registration says who filed the URL, not who runs the machine.
- A brand is not an underwriter. Marketing names and legal entities differ, and the legal entity behind a registration is the issuer of record in CMS's files, not this page's headline.
- A registration is not a measurement. Appearing in this chain says a directory was filed, nothing more. What the audit found is reported to the plan that publishes the file, under the published method.
Questions about an attribution, including a claim that a registration is tied to the wrong brand, go to findings@rollcall.health and are handled under the publication and corrections policy.