Draft — pending final legal review.
Last updated: July 2026. This page is a first draft based on an internal data practices inventory and research into comparable companies’ published terms.
Professional data, not PHI
No patient care on this site
Public federal databases
This site collects physician professional data
This site exists for one purpose: physicians and other healthcare providers apply here to join our provider networks. The information we collect is about you, the applicant, as a professional — your name, contact details, practice information, NPI, and credentials. It is professional and business information, similar to what appears in a public provider directory, not what’s commonly understood as “protected health information.”
This site and the application process involve no patient care, and we do not collect or process patient health information. The details of what we collect and how we handle it are set out in our Privacy Policy.
Where patient information is handled
Patient care — and any handling of patient health information that comes with it — happens inside the products physicians join through this network, under those products’ own safeguards and policies. This application platform is separate from those products and does not receive or store patient records.
How verification uses public federal databases
Before any physician is approved, we verify their NPI against the NPPES national provider registry and screen their information against the federal OIG List of Excluded Individuals/Entities (LEIE). Both are government-maintained sources used to confirm identity and credentials and to screen for healthcare program exclusions — they contain provider information, not patient information.
What we do not claim
We do not describe this site as “HIPAA certified” — there is no federal certification of HIPAA compliance, and the applicant data this site collects is not patient health information in the first place. What we do commit to is described in our Privacy Policy: reasonable administrative, technical, and physical safeguards designed to protect your information, access restricted to staff who need it, and service providers with their own security commitments.