What Is NPPES?
NPPES is the federal system that assigns and stores every NPI. Here is what it actually collects, what it publishes, what it withholds, and how often it updates.
Reviewed
NPPES — the National Plan and Provider Enumeration System — is the system the Centers for Medicare & Medicaid Services (CMS) built to assign National Provider Identifiers and store the information providers report when they apply for or update one. Every NPI in existence was issued through NPPES, and NPPES is the single source of record for it.
What NPPES actually collects
When a provider applies for an NPI, they report identifying and contact information: name (or legal business name), practice and mailing addresses and phone numbers, taxonomy codes describing their type of practice, and — for organizations — an Employer Identification Number and an Authorized Official. CMS's National Provider System is responsible for maintaining that information for as long as the NPI exists, and the provider is responsible for keeping it current.
What NPPES publishes
Under the NPPES Data Dissemination Notice (CMS-6060-N), the information providers report that is disclosable under the Freedom of Information Act is published in a free, downloadable file. CMS makes this available three ways:
| File | Contents | Cadence |
|---|---|---|
| Monthly full file | All FOIA-disclosable data for every enumerated provider; replaces the previous month's file | Every month |
| Weekly incremental file | Only the records that changed since the last weekly or monthly file | Every week |
| Deactivated NPI report | Deactivated NPIs and their deactivation dates | Monthly |
These files, along with the NPI Registry — the interactive web search most people actually use — are the two public faces of NPPES. NPISignal's own data is built entirely from the downloadable files; see Data Sources for exactly which files and how NPISignal uses them.
What NPPES withholds
Some fields providers submit are collected internally but never appear in the public file, because disclosing them would expose sensitive personal information or because CMS never intended them for public use:
- Social Security Numbers and IRS ITINs — some providers historically entered these in fields meant for other identifiers. CMS masks them rather than publishing them.
- Employer Identification Numbers (EINs) — suppressed for the same reason, along with a subpart organization's parent-company tax ID.
- NPI Deactivation Reason Code — CMS's own file-layout documentation states this field is not publicly disseminated. The public file shows that a deactivation happened and the date it happened, but not the recorded reason.
Data quality is the provider's responsibility
NPPES is a self-reported registry. CMS does not independently verify that a practice address is still current or that a listed phone number still rings at that office — the provider is required to report changes within 30 days, but enforcement of that requirement is limited, and providers who leave a practice, retire, or close a location do not always update their record promptly. A current-looking NPPES record is evidence of what the provider last reported, not a live confirmation of where they practice today.
The bulk file and the web registry are not the same thing
NPPES has two public faces built from the same underlying data but serving different needs. The downloadable bulk files described above are periodic, versioned snapshots meant for bulk or programmatic use — matching large numbers of records, building a directory, or running an internal audit. The NPI Registry web search is the interactive tool built for a one-off, human lookup: type in a name, an NPI, or a location, and get an answer immediately, without downloading anything. Both ultimately draw on the same NPPES data, but the web registry's own refresh cycle is not necessarily identical to the calendar the downloadable files follow, so it is possible, at the margins, to see a very recent change on one before the other catches up.
How providers interact with NPPES
Providers apply for and manage their NPI online through the NPPES web application, authenticated through CMS's Identity & Access Management (I&A) system, or by paper form. Updating an existing record — a new address, a new taxonomy, a name change — goes through the same system. See How to Update an NPI Record for the exact steps and the 30-day requirement.
Sources
- NPPES Data Dissemination — Readme (file contents, monthly/weekly cadence, FOIA-disclosable scope, field suppression) — CMS. Accessed August 20, 2026.
- NPPES Data Dissemination — Code Values (Deactivation Reason categories and disclosure note) — CMS. Accessed August 20, 2026.
- National Plan and Provider Enumeration System (NPPES) — CMS. Accessed August 20, 2026.
- 45 CFR § 162.410 — Implementation specifications: Health care providers — Cornell Law School Legal Information Institute. Accessed August 20, 2026.