Data & privacy

Public data only. No PHI. No patient data.

Everything on this site comes from public federal records about providers and organizations — never about patients.

What we use

CMS NPPES

The public National Plan & Provider Enumeration System registry — every enumerated US provider's NPI, specialty, practice location and license. Published by CMS for public use.

HHS-OIG LEIE

The public List of Excluded Individuals/Entities — parties barred from federal healthcare programs. Published by OIG for public download.

openFDA

FDA's public enforcement/recall datasets, keyed by firm. Published by the FDA.

SAM.gov (optional)

The public federal exclusions list, queried live only when an API key is configured.

What we do NOT touch

No Protected Health Information (PHI). No patient records. No claims tied to individuals' care. No diagnoses, treatments, or medical history. We are not a covered entity or a business associate under HIPAA, because we never process patient data — only public provider-directory and public compliance records. Presence on an exclusion list is a public-record fact, not an allegation by us; verify against the primary source before any adverse action.

Provider data subject access / corrections are handled at the source (NPPES / OIG). We mirror the public record and link to it. Not affiliated with HHS, CMS, OIG or the FDA.