← Back to MedFabric

Privacy Policy

Effective Date: March 5, 2026

1. Introduction

MedFabric provides healthcare provider data infrastructure through an API service. This Privacy Policy explains what data we collect, how we use it, how we protect it, and your rights regarding that data. This policy applies to all users of the MedFabric website, API, and related services.

2. Data We Process

It is important to distinguish between the types of data MedFabric processes:

Provider Data (B2B Public Record Data)

MedFabric aggregates publicly available healthcare provider information from government registries, including the CMS National Plan and Provider Enumeration System (NPPES), state medical boards (currently the Medical Board of California), the Office of Inspector General List of Excluded Individuals/Entities (OIG LEIE), and the CMS Provider Enrollment, Chain, and Ownership System (PECOS). This data concerns healthcare providers in their professional capacity — including NPI numbers, license status, practice locations, taxonomy codes, and enrollment status. This is public record data, NOT consumer health data or Protected Health Information.

Customer Data

When you register for an API key or create an account, we collect: business name, contact name, email address, and billing information. Payment card information is processed by our third-party payment processor — we do not store credit card numbers, CVVs, or full card details on our systems.

Usage Data

We collect API call logs, including endpoints accessed, query parameters (e.g., NPI numbers looked up), timestamps, response status codes, response times, IP addresses, and user agent strings. This data is collected automatically as part of normal API operations.

3. How We Use Data

  • Provider data: To build, maintain, and serve our data products, including provider lookup, license verification, compliance determination, quality scoring, and OIG/PECOS screening.
  • Customer data: For account management, billing, customer support, service-related communications, and to enforce our Terms of Service.
  • Usage data: For rate limiting, abuse prevention, service performance monitoring, service improvement, debugging, and aggregate analytics. We may use anonymized, aggregated usage statistics to understand API usage patterns and improve the Service.

4. HIPAA Considerations

MedFabric processes data about healthcare providers in their professional capacity, including NPI numbers, license status, practice locations, and enrollment information. We do NOT process Protected Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA). All data processed by MedFabric is sourced from publicly available government registries, not from covered entities or their business associates.

However, we recognize that many of our customers are HIPAA-covered entities or business associates. While MedFabric's standard service does not involve the processing of PHI, we will enter into Business Associate Agreements (BAAs) upon request for Enterprise-tier customers who require such agreements as part of their compliance program.

5. Data Sharing

We share data with the following categories of recipients:

  • API customers: Provider data is served to authenticated API customers as requested through API calls, subject to their subscription tier and authorized scopes.
  • Service providers: We use third-party services for payment processing, cloud hosting infrastructure, and email delivery. These providers process data only as necessary to perform their services and are bound by contractual obligations to protect your data.
  • Legal requirements: We may disclose data when required by law, subpoena, court order, or government request, or when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

We do NOT sell customer personal data. We do NOT share customer usage data with third parties for advertising or marketing purposes.

6. Data Retention

  • Provider data: Retained and updated continuously from government sources. Historical data snapshots are retained for audit and change-tracking purposes.
  • Customer data: Retained for the duration of your active account plus two (2) years after account closure for legal, tax, and regulatory compliance purposes.
  • Usage and API logs: Detailed API logs are retained for ninety (90) days. After that period, logs are aggregated and anonymized. Anonymized aggregate statistics may be retained indefinitely.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • California residents (CCPA/CPRA): You have the right to know what personal information we collect, the right to request deletion of your personal information, and the right to opt out of the sale of personal information. MedFabric does not sell personal information.
  • EU/EEA residents (GDPR): If applicable, you have rights of access, rectification, erasure, restriction of processing, data portability, and the right to object to processing.

To exercise any of these rights, please contact us at privacy@medfabric.com. We will respond to verified requests within the timeframes required by applicable law.

8. Security

We implement industry-standard security measures to protect the data we process, including: encrypted API connections using TLS 1.2 or higher, cryptographically hashed API keys, rate limiting and abuse detection, comprehensive access logging, regular security reviews, and secure infrastructure hosted on reputable cloud providers. While no system can guarantee absolute security, we are committed to maintaining appropriate technical and organizational measures to protect your data.

9. Cookies and Tracking

The MedFabric API is stateless and does not use cookies. The MedFabric website uses only minimal, strictly necessary cookies for basic functionality (such as remembering your preferences). We do not use third-party tracking cookies, advertising cookies, or analytics tracking that shares data with advertisers.

10. Children

MedFabric services are business-to-business professional tools designed for healthcare organizations and technology companies. We do not knowingly collect personal information from children under the age of 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify customers of material changes via email to the address associated with their API key account at least thirty (30) days before the changes take effect. The “Effective Date” at the top of this page will be updated to reflect the date of the most recent revision. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy.

12. Contact

For data protection inquiries, privacy rights requests, or questions about this Privacy Policy, please contact us at: privacy@medfabric.com