Privacy Policy
What NPISignal collects from visitors and from customers, what it deliberately does not collect, how roster data is protected, and how long everything is kept.
Updated
NPISignal has two kinds of user with very different relationships to it, and this policy covers both separately: anybody who uses the free public tools without an account, and an organization that creates an account to monitor a roster.
Using the free tools, without an account
Searching for a provider, looking up an NPI or running an exclusion search requires no account and asks for nothing about you. There is no saved profile and no history kept against you.
What is recorded automatically
Like any website, NPISignal's server and the infrastructure in front of it record standard technical information for every request — IP address, browser and device information, the page requested and a timestamp — for security, abuse prevention and understanding performance. This is server-log-level information, not a profile of an individual visitor.
What you type into a search
A search query is processed to return results and may appear in those same operational logs. NPISignal does not sell, publish or share what any individual searched for.
One deliberate design choice follows from that: a public exclusion search does not accept a date of birth, even though supplying one would produce a sharper result. A query string ends up in browser history, in a shared link and in server logs, and a third party’s date of birth does not belong in any of those. Dates of birth are accepted only on a roster, where they are encrypted and never appear in a URL.
With an account
What NPISignal collects from you
| Data | Why |
|---|---|
| Email address | To identify the account, sign you in, and send screening alerts |
| Name, if you provide one | To attribute a review decision to a person — the record an auditor reads |
| Password | Stored only as an Argon2id hash. NPISignal cannot read it or recover it |
| Organization name | To identify the account and to name it on generated reports |
| IP address and browser, at sign-in | Session security and the audit log |
What your organization puts on its roster
A roster record describes a person or entity your organization monitors. It is your data, held on your behalf, and it is never visible on any public NPISignal page.
| Field | Handling |
|---|---|
| Name, business name | Stored as supplied, plus a normalised form used for matching |
| Your own employee or vendor ID | Stored as supplied and echoed back in exports |
| NPI | Stored as supplied; resolved against the public NPPES registry |
| Date of birth | Encrypted at rest with AES-256-GCM. Never in a URL, an export, a report or an email |
| Address, city, state, ZIP | Stored as supplied; used to corroborate or rule out a match |
| Screening results and review decisions | Retained as the audit record; append-only |
What NPISignal will not collect
Who can see it
- Only members of your organization, according to their role. A member of one organization cannot read another’s roster, matches, screening history or reports — every query is scoped to the organization, and a valid identifier from another one returns nothing.
- NPISignal’s operator can technically access the database, as any hosted service’s operator can. It is not accessed in the ordinary course of running the service.
- Nothing on a roster is ever published, indexed, or shown on a public provider profile.
Data about people who are not users
This is worth stating plainly, because it is the unusual part. NPISignal holds records about people who have never used it: public NPPES provider records, and public exclusion records published by HHS-OIG and the General Services Administration.
- Everything in those records comes from a government publication and is republished as the source states it.
- NPISignal does not write descriptive prose about any individual, does not infer facts about them, and does not use a model to characterise them.
- The date of birth HHS-OIG publishes in the LEIE is imported because matching needs it — and is never rendered publicly, never exported, and never emailed.
- Exclusion search results are never indexed by search engines. NPISignal does not intend to rank for a person’s name alongside an exclusion outcome; the reputational cost of a false positive falls on somebody who never used this site.
If you believe a record about you is wrong, see Corrections. A correction to source data has to be made with the publishing agency — NPISignal republishes what they publish — and NPISignal will make sure its own copy reflects the correction once it is made.
Third parties
NPISignal uses as few as it can. The ones it does use, and what each receives:
| Provider | What it receives |
|---|---|
| The hosting provider and CDN in front of the site | Ordinary request traffic, as any host does |
| Stripe, when a paid plan is purchased | Billing details, which go to Stripe directly and are never held by NPISignal |
| The transactional email provider, when alerts are enabled | The recipient address and the message — which never contains a date of birth |
| SAM.gov, when a SAM screening runs | The name and state being screened, as the query |
NPISignal does not send roster contents or screening results to any analytics service. If advertising is enabled on the public site, an advertising provider may set its own cookies under its own privacy practices; advertising never appears on an account holder’s pages.
Retention
- Screening history, review decisions and generated reports are kept for as long as the account exists, and are not editable or deletable from within the product. They are the audit record, and a record that can be tidied up is worth nothing as evidence.
- A roster record removed from monitoring is marked removed rather than erased, so the history of what was screened stays intact.
- Deleting an organization deletes its roster, screening history, matches, decisions and reports.
- Sessions expire after thirty days of disuse. Password reset links expire in one hour; invitations in fourteen days.
Your choices
- You can export your roster and your screening history at any time.
- You can correct or remove any roster record.
- You can ask for your account and its data to be deleted, through Contact.
- You can turn automatic screening off without deleting anything.
Security
- Everything is served over HTTPS.
- Passwords are stored as Argon2id hashes; session tokens are stored hashed, so a database leak yields no usable session.
- Dates of birth on a roster are encrypted at rest with AES-256-GCM.
- Sign-in is rate limited, and mutations carry a CSRF token in addition to same-site cookies.
- Every organization-scoped query is filtered on the organization, and the identifiers used in URLs are random rather than sequential.
The technical detail behind each of those is written up in the methodology and in the repository’s security documentation.
Children’s privacy
NPISignal is a professional reference and compliance tool about business and professional information. It is not directed at children and does not knowingly collect personal information from them.
Changes to this policy
A changed policy is posted here with a new date at the top. A change that materially affects account holders will also be sent by email.
Contact
Questions about this policy, or a request about your own data, can be sent through Contact.