Effective Date: March 5, 2026
MedFabric provides healthcare provider data infrastructure through an API service. This Privacy Policy explains what data we collect, how we use it, how we protect it, and your rights regarding that data. This policy applies to all users of the MedFabric website, API, and related services.
It is important to distinguish between the types of data MedFabric processes:
MedFabric aggregates publicly available healthcare provider information from government registries, including the CMS National Plan and Provider Enumeration System (NPPES), state medical boards (currently the Medical Board of California), the Office of Inspector General List of Excluded Individuals/Entities (OIG LEIE), and the CMS Provider Enrollment, Chain, and Ownership System (PECOS). This data concerns healthcare providers in their professional capacity — including NPI numbers, license status, practice locations, taxonomy codes, and enrollment status. This is public record data, NOT consumer health data or Protected Health Information.
When you register for an API key or create an account, we collect: business name, contact name, email address, and billing information. Payment card information is processed by our third-party payment processor — we do not store credit card numbers, CVVs, or full card details on our systems.
We collect API call logs, including endpoints accessed, query parameters (e.g., NPI numbers looked up), timestamps, response status codes, response times, IP addresses, and user agent strings. This data is collected automatically as part of normal API operations.
MedFabric processes data about healthcare providers in their professional capacity, including NPI numbers, license status, practice locations, and enrollment information. We do NOT process Protected Health Information (PHI) as defined by the Health Insurance Portability and Accountability Act (HIPAA). All data processed by MedFabric is sourced from publicly available government registries, not from covered entities or their business associates.
However, we recognize that many of our customers are HIPAA-covered entities or business associates. While MedFabric's standard service does not involve the processing of PHI, we will enter into Business Associate Agreements (BAAs) upon request for Enterprise-tier customers who require such agreements as part of their compliance program.
We share data with the following categories of recipients:
We do NOT sell customer personal data. We do NOT share customer usage data with third parties for advertising or marketing purposes.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
To exercise any of these rights, please contact us at privacy@medfabric.com. We will respond to verified requests within the timeframes required by applicable law.
We implement industry-standard security measures to protect the data we process, including: encrypted API connections using TLS 1.2 or higher, cryptographically hashed API keys, rate limiting and abuse detection, comprehensive access logging, regular security reviews, and secure infrastructure hosted on reputable cloud providers. While no system can guarantee absolute security, we are committed to maintaining appropriate technical and organizational measures to protect your data.
The MedFabric API is stateless and does not use cookies. The MedFabric website uses only minimal, strictly necessary cookies for basic functionality (such as remembering your preferences). We do not use third-party tracking cookies, advertising cookies, or analytics tracking that shares data with advertisers.
MedFabric services are business-to-business professional tools designed for healthcare organizations and technology companies. We do not knowingly collect personal information from children under the age of 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly.
We may update this Privacy Policy from time to time. We will notify customers of material changes via email to the address associated with their API key account at least thirty (30) days before the changes take effect. The “Effective Date” at the top of this page will be updated to reflect the date of the most recent revision. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy.
For data protection inquiries, privacy rights requests, or questions about this Privacy Policy, please contact us at: privacy@medfabric.com