NPI Data Services logoProvider Data, Intelligence & APIs
  • Provider Signals
    • Overview
    • Risk - Continuous Monitoring
    • Growth - New Providers
    • Screening API - On-demand
  • Provider API
  • Provider Data
    • Complete US Database
    • By State
    • By Specialty
  • Lookups
    • NPI Lookup
    • PECOS Lookup
    • New Providers
  • Contact

Privacy Policy

Last updated August 7, 2026

This Privacy Policy explains how VBC Risk Analytics, Inc. ("we," "us"), through NPI Data Services (npidataservices.com), collects, uses, and shares information when you use our products and services — including Provider Data, Provider Signals, the NPI Registry API, NPI Lookup, PECOS Lookup, and New Providers (collectively, "the Services").

1. Information we collect

  • Account information — name, work email, company, and team-member details you provide.
  • Billing information — handled by Stripe (see Section 6). We receive limited details such as plan, billing status, and the last four digits/brand of your card; we do not store full card numbers.
  • Usage data — saved searches, alerts, exports, log/device data (IP address, browser, timestamps), and how pages are used. We collect this from all visitors, including those without an account, to operate and secure the Service and to understand how it is used.
  • Provider rosters you upload — the NPIs and provider identifiers you add (for example, for Risk monitoring) so we can check those providers against exclusion and sanction sources. These identify public providers, not your end users. Do not upload PHI, patient data, or other sensitive personal information; submit only provider identifiers such as NPIs and provider names.
  • Local storage — we store preferences and session data in your browser to run the app.

2. How we use information

We use information to provide and improve the Service, authenticate users, process subscriptions, send alerts and service communications, prevent abuse, and comply with legal obligations.

3. Cookies & local storage

We use essential cookies/local storage to keep you signed in and remember preferences, and may use limited analytics to understand usage. We also store a randomly generated identifier in your browser that lets us recognise a returning browser without identifying you. You can control cookies through your browser; disabling them may affect functionality.

4. Advertising

We use Google AdSense to display ads. Google and its partners use cookies to serve ads based on your prior visits to this and other websites. You can opt out of personalised advertising at google.com/settings/ads, or opt out of third-party vendor cookies at aboutads.info.

5. How we share information

  • Service providers — Stripe (payments), hosting, email delivery, and analytics, acting on our behalf under contract.
  • Legal — when required by law or to protect rights, safety, and security.
  • Business transfers — in connection with a merger, acquisition, or asset sale.

We do not sell your personal information.

6. Payments (Stripe)

Payment processing is provided by Stripe, Inc. Your card details are submitted directly to Stripe and handled under Stripe's Privacy Policy. We do not collect or store your full payment card information.

7. Provider data (NPPES, OIG LEIE, PECOS)

The provider records and signals in the Services come from publicly available government and third-party datasets — including NPPES (CMS), the OIG List of Excluded Individuals/Entities (LEIE), GSA SAM.gov, OFAC, the Medicare Opt-Out list, PECOS / Medicare enrollment data, and state Medicaid exclusion and sanction lists. This is public professional/business information about providers, not personal data we collect about you as a user. It is not "protected health information" (PHI) under HIPAA, and the Services are not intended to process PHI — please do not upload PHI or patient data. Provider rosters you upload are processed on your behalf to check those providers against these sources. If you are a provider with questions about your NPPES or LEIE record, contact CMS/NPPES or the OIG directly.

8. Provider Data & Removal Requests

The provider records displayed on NPI Data Services are compiled from publicly available government and third-party datasets, including the NPPES NPI Registry (CMS), the OIG List of Excluded Individuals/Entities (LEIE), GSA SAM.gov, OFAC, the Medicare Opt-Out list, PECOS / Medicare enrollment data, and state Medicaid exclusion and sanction lists. This is public professional and business information about healthcare providers and entities. We do not create this data, and it is not "protected health information" (PHI) under HIPAA.

Correcting your information. Because your record originates from the NPPES NPI Registry, the authoritative way to correct your professional details (name, address, taxonomy, and similar) is to update your record directly with CMS at https://nppes.cms.hhs.gov. Corrections made at NPPES flow into the public dataset over time.

Requesting removal from this website. If you are a provider (or an authorized representative) and you would like your directory profile removed from npidataservices.com, please submit a request through our contact form at https://www.npidataservices.com/contact. To help us locate the correct record and verify your request, please include:

  • The provider's full name and NPI number
  • A link to the profile page you want removed, if available
  • Confirmation that you are the provider or are authorized to act on their behalf

What we will remove. A removal request applies to the general provider directory profile compiled from the public NPPES NPI Registry. Upon receiving a valid request, we will remove the identified directory profile(s) from our website. Please allow a reasonable period for us to process the request. Removal requests must be submitted through the contact form above so that we can track and verify each request; requests submitted by other means may be delayed.

What we cannot remove. Our compliance products exist to reflect official government enforcement records. Except where removal is required by applicable law, we do not suppress records sourced from exclusion, sanction, and debarment lists — including the OIG List of Excluded Individuals/Entities (LEIE), state Medicaid exclusion and sanction lists, GSA SAM.gov, OFAC, and the Medicare Opt-Out list — which we retain on the basis of our legitimate interest in providing accurate compliance information drawn from public records. We update these records to reflect changes at the source, including reinstatements and removals; if you believe an exclusion or sanction record we display is inaccurate or out of date, tell us via the contact form and we will review it against the authoritative source. These records originate with the issuing government agency; to correct the underlying record, you must contact that agency directly.

Note that removing a directory profile from npidataservices.com does not remove or alter the underlying record in the public NPPES registry or any other government source; to change the public record itself, you must contact CMS/NPPES or the applicable government agency directly.

9. Data retention

We retain account and usage data for as long as your account is active and as needed for legitimate business and legal purposes. You may request deletion of your account information as described in Section 11 (Your rights); providers seeking removal of a public profile should follow Section 8 (Provider Data & Removal Requests).

10. Security

We use industry-standard safeguards (encryption in transit, access controls) to protect information. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Your rights

Depending on your location, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing (e.g., under GDPR or CCPA/CPRA). To exercise these rights, contact us at the address below. We will not discriminate against you for exercising your rights.

12. Children

The Service is not directed to children under 18, and we do not knowingly collect their information.

13. International users

We are based in the United States; by using the Service you understand your information may be processed in the U.S. and other countries.

14. Changes to this policy

We may update this policy; material changes will be posted here with a new "Last updated" date.

15. Contact

VBC Risk Analytics, Inc. (NPI Data Services), 2844 Livernois Road, Suite 99553, Troy, MI 48099. Email: contact@npidataservices.com.

NPI Data Services — a product of VBC Risk Analytics, Inc. · Terms of Use · Home

NPI Data Services logo Provider Data, Intelligence & APIs

Since 2009, the trusted source of complete US healthcare provider data — plus a real-time NPI Registry API, exclusion & new-provider monitoring (Provider Signals), and free NPI & PECOS lookups.

LinkedIn Instagram Facebook X YouTube

Products

Provider Signals Screening API Provider API Provider Data NPI Lookup PECOS Lookup New Providers

Company

About Contact Blog Terms of Use Privacy

Contact

contact@npidataservices.com 248-247-6102 2844 Livernois Road, Suite 99553
Troy, MI 48099

© 2009–2026 NPI Data Services — a product of VBC Risk Analytics, Inc. All rights reserved.