Skip to content
NPISignal

Privacy Policy

What NPISignal collects from visitors and from customers, what it deliberately does not collect, how roster data is protected, and how long everything is kept.

Updated

NPISignal has two kinds of user with very different relationships to it, and this policy covers both separately: anybody who uses the free public tools without an account, and an organization that creates an account to monitor a roster.

The short version. Using the free tools requires no account and no personal information about you. Creating an account collects an email address, a name if you give one, and whatever your organization puts on its roster. NPISignal does not collect Social Security numbers and has nowhere to store one. Dates of birth on a roster are encrypted at rest and never leave the application. Nothing an organization stores is ever visible on a public page.

Using the free tools, without an account

Searching for a provider, looking up an NPI or running an exclusion search requires no account and asks for nothing about you. There is no saved profile and no history kept against you.

What is recorded automatically

Like any website, NPISignal's server and the infrastructure in front of it record standard technical information for every request — IP address, browser and device information, the page requested and a timestamp — for security, abuse prevention and understanding performance. This is server-log-level information, not a profile of an individual visitor.

A search query is processed to return results and may appear in those same operational logs. NPISignal does not sell, publish or share what any individual searched for.

One deliberate design choice follows from that: a public exclusion search does not accept a date of birth, even though supplying one would produce a sharper result. A query string ends up in browser history, in a shared link and in server logs, and a third party’s date of birth does not belong in any of those. Dates of birth are accepted only on a roster, where they are encrypted and never appear in a URL.

With an account

What NPISignal collects from you

DataWhy
Email addressTo identify the account, sign you in, and send screening alerts
Name, if you provide oneTo attribute a review decision to a person — the record an auditor reads
PasswordStored only as an Argon2id hash. NPISignal cannot read it or recover it
Organization nameTo identify the account and to name it on generated reports
IP address and browser, at sign-inSession security and the audit log

What your organization puts on its roster

A roster record describes a person or entity your organization monitors. It is your data, held on your behalf, and it is never visible on any public NPISignal page.

FieldHandling
Name, business nameStored as supplied, plus a normalised form used for matching
Your own employee or vendor IDStored as supplied and echoed back in exports
NPIStored as supplied; resolved against the public NPPES registry
Date of birthEncrypted at rest with AES-256-GCM. Never in a URL, an export, a report or an email
Address, city, state, ZIPStored as supplied; used to corroborate or rule out a match
Screening results and review decisionsRetained as the audit record; append-only

What NPISignal will not collect

NPISignal does not collect Social Security numbers, taxpayer identification numbers, employer identification numbers, driver’s licence numbers, passport numbers or bank details. There is no column for any of them anywhere in the product. A file uploaded with a column that looks like one is refused outright rather than partially imported — because a column that is silently ignored is a column somebody keeps exporting.

Who can see it

  • Only members of your organization, according to their role. A member of one organization cannot read another’s roster, matches, screening history or reports — every query is scoped to the organization, and a valid identifier from another one returns nothing.
  • NPISignal’s operator can technically access the database, as any hosted service’s operator can. It is not accessed in the ordinary course of running the service.
  • Nothing on a roster is ever published, indexed, or shown on a public provider profile.

Data about people who are not users

This is worth stating plainly, because it is the unusual part. NPISignal holds records about people who have never used it: public NPPES provider records, and public exclusion records published by HHS-OIG and the General Services Administration.

  • Everything in those records comes from a government publication and is republished as the source states it.
  • NPISignal does not write descriptive prose about any individual, does not infer facts about them, and does not use a model to characterise them.
  • The date of birth HHS-OIG publishes in the LEIE is imported because matching needs it — and is never rendered publicly, never exported, and never emailed.
  • Exclusion search results are never indexed by search engines. NPISignal does not intend to rank for a person’s name alongside an exclusion outcome; the reputational cost of a false positive falls on somebody who never used this site.

If you believe a record about you is wrong, see Corrections. A correction to source data has to be made with the publishing agency — NPISignal republishes what they publish — and NPISignal will make sure its own copy reflects the correction once it is made.

Third parties

NPISignal uses as few as it can. The ones it does use, and what each receives:

ProviderWhat it receives
The hosting provider and CDN in front of the siteOrdinary request traffic, as any host does
Stripe, when a paid plan is purchasedBilling details, which go to Stripe directly and are never held by NPISignal
The transactional email provider, when alerts are enabledThe recipient address and the message — which never contains a date of birth
SAM.gov, when a SAM screening runsThe name and state being screened, as the query

NPISignal does not send roster contents or screening results to any analytics service. If advertising is enabled on the public site, an advertising provider may set its own cookies under its own privacy practices; advertising never appears on an account holder’s pages.

Retention

  • Screening history, review decisions and generated reports are kept for as long as the account exists, and are not editable or deletable from within the product. They are the audit record, and a record that can be tidied up is worth nothing as evidence.
  • A roster record removed from monitoring is marked removed rather than erased, so the history of what was screened stays intact.
  • Deleting an organization deletes its roster, screening history, matches, decisions and reports.
  • Sessions expire after thirty days of disuse. Password reset links expire in one hour; invitations in fourteen days.

Your choices

  • You can export your roster and your screening history at any time.
  • You can correct or remove any roster record.
  • You can ask for your account and its data to be deleted, through Contact.
  • You can turn automatic screening off without deleting anything.

Security

  • Everything is served over HTTPS.
  • Passwords are stored as Argon2id hashes; session tokens are stored hashed, so a database leak yields no usable session.
  • Dates of birth on a roster are encrypted at rest with AES-256-GCM.
  • Sign-in is rate limited, and mutations carry a CSRF token in addition to same-site cookies.
  • Every organization-scoped query is filtered on the organization, and the identifiers used in URLs are random rather than sequential.

The technical detail behind each of those is written up in the methodology and in the repository’s security documentation.

Children’s privacy

NPISignal is a professional reference and compliance tool about business and professional information. It is not directed at children and does not knowingly collect personal information from them.

Changes to this policy

A changed policy is posted here with a new date at the top. A change that materially affects account holders will also be sent by email.

Contact

Questions about this policy, or a request about your own data, can be sent through Contact.