Privacy Policy
Effective Date: 09/16/2026
This Privacy Policy explains how ASFMS LLC, a Florida limited liability company ("ASFMS," "NPIData.org," "we," "us," or "our") collects, uses, discloses, and otherwise processes information in connection with NPIData.org and its websites, applications, databases, APIs, provider-tracking tools, sales-intelligence products, and related services (collectively, the "Service").
This Privacy Policy also explains how NPIData.org handles information concerning healthcare providers and healthcare organizations appearing within the Service.
By using the Service, you acknowledge the practices described in this Privacy Policy.
1. Information We Collect
The information we collect depends on how you interact with NPIData.org.
A. Account Information
When you create or maintain an account, we may collect information such as:
- name
- email address
- company or organization
- job title
- username or account identifier
- password or authentication information
- subscription plan
- account preferences
- communications with us
Passwords may be stored using cryptographic hashing or handled through an authentication provider rather than stored in readable form.
B. Billing and Transaction Information
When you purchase a subscription or other paid service, we may collect information relating to your transaction, including:
- billing name
- billing address
- company information
- subscription plan
- transaction amount
- payment status
- invoices
- billing history
- applicable tax information
Payments may be processed by third-party payment processors.
We generally do not receive or store complete payment-card numbers when payment information is entered directly into a third-party payment processor's systems.
C. API Information
If you use the NPIData.org API, we may collect and maintain:
- API credentials or identifiers
- API requests
- endpoints accessed
- request timestamps
- response status codes
- IP addresses
- usage volume
- monthly API-call counts
- rate-limit information
- errors
- technical logs
- other information necessary to operate, secure, meter, and troubleshoot the API
We use this information in part to calculate API usage and, where applicable, Enterprise overage charges.
D. Usage and Device Information
When you access NPIData.org, we may automatically collect information such as:
- IP address
- browser type
- device type
- operating system
- referring pages
- pages viewed
- features used
- searches performed
- dates and times of access
- session information
- approximate geographic information derived from an IP address
- diagnostic and performance information
E. Searches, Watchlists, and Preferences
When you use search, tracking, alerting, or monitoring features, we may store information about your activity, including:
- provider searches
- practice searches
- specialty searches
- geographic searches
- saved searches
- saved providers or practices
- watchlists
- territories or geographic areas you monitor
- alert settings
- other Service preferences
We use this information to provide the features you request and improve the Service.
F. Communications
If you contact us, we may collect the information contained in your communication, including your email address, the contents of your message, attachments, and information necessary to respond to your request.
2. Healthcare Provider and Practice Information
NPIData.org provides a healthcare-provider information and analytics service.
Accordingly, the Service contains information concerning physicians, clinicians, healthcare organizations, medical practices, and other healthcare providers ("Provider Information").
Provider Information may include:
- provider names
- professional credentials
- National Provider Identifiers ("NPIs")
- taxonomy codes
- specialties and subspecialties
- practice names
- business addresses
- mailing addresses
- telephone numbers
- fax numbers
- practice locations
- organizational affiliations
- publicly reported identifiers
- dates associated with provider records
- changes to provider records
- geographic information
- practice-opening or relocation signals
- specialty-expansion signals
- provider-movement information
- historical provider information
- analytics or classifications generated from available data
Provider Information is primarily professional and business-related information rather than information collected from providers as customers of NPIData.org.
3. Sources of Provider Information
NPIData.org may obtain Provider Information from sources including:
- the National Plan and Provider Enumeration System ("NPPES")
- Centers for Medicare & Medicaid Services ("CMS") datasets
- federal, state, and local government sources
- government open-data programs
- professional licensing information
- publicly available websites
- healthcare organization and practice websites
- provider directories
- publicly available business information
- licensed or commercial data providers
- other lawful sources
NPIData.org may also create additional information by organizing, comparing, normalizing, matching, aggregating, or analyzing source information.
For example, we may compare records from different dates to identify a possible new provider, relocation, practice opening, geographic movement, or specialty expansion.
CMS makes certain FOIA-disclosable NPPES healthcare-provider information publicly available. CMS states that NPPES information is reported by healthcare providers or persons acting on their behalf.
NPIData.org is independent of CMS and NPPES and is not endorsed by or affiliated with either organization.
4. How We Use Information
We may use information we collect to:
- provide and operate NPIData.org
- create and manage accounts
- authenticate users
- process subscriptions and payments
- meter API usage
- calculate Enterprise API overages
- enforce API limits and rate limits
- provide enhanced NPI search
- provide provider and practice analytics
- generate healthcare sales intelligence and leads
- identify new providers and practices
- identify possible provider relocations
- identify specialty expansions
- identify providers entering or leaving monitored areas
- operate saved searches and watchlists
- provide alerts and notifications
- personalize Service functionality
- maintain and improve our databases
- analyze Service performance
- develop new features
- troubleshoot errors
- detect fraud or abuse
- secure the Service and our infrastructure
- enforce our Terms of Service
- respond to customer-support requests
- send transactional and administrative communications
- comply with legal obligations
- protect our rights and those of our users and others
We may also create aggregated, statistical, or de-identified information and use that information for analytics, research, product development, and business purposes.
5. Provider Analytics and Inferences
Some information displayed by NPIData.org is generated through analysis rather than copied directly from a source.
For example, NPIData.org may compare records over time and identify an event as a:
- New Provider
- New Practice
- Provider Relocation
- Market Entry
- Market Exit
- Practice Expansion
- Specialty Expansion
These classifications are analytical signals based on information available to us.
They do not necessarily establish when, why, or whether the corresponding real-world event occurred.
For example, a provider's business-address change in a government dataset may reflect a delayed administrative update rather than the date on which the provider physically relocated.
6. Cookies and Similar Technologies
We and service providers acting on our behalf may use cookies, local storage, pixels, and similar technologies.
These technologies may be used to:
- keep users signed in
- maintain sessions
- remember preferences
- provide security
- prevent fraud
- measure Service usage
- understand how users navigate NPIData.org
- diagnose technical problems
- improve the Service
Where required by applicable law, we will obtain consent before using non-essential cookies or similar technologies.
Browser settings may allow you to restrict certain cookies, although doing so may affect Service functionality.
7. Analytics
We may use analytics providers to help us understand how NPIData.org is used.
Analytics providers may receive information such as IP addresses, device and browser information, pages visited, interactions, and approximate location.
We use analytics information to understand usage patterns, diagnose problems, improve features, and evaluate Service performance.
8. Payment Processing
We may use third-party payment processors to process subscription and other payments.
Payment processors may collect payment-card information and other billing information directly from you.
Their processing of your information is governed by their own privacy policies and contractual obligations.
9. Email and Communications
We may send you transactional or administrative emails concerning:
- your account
- subscription
- invoices
- billing
- password or security events
- API usage
- API limits
- Service changes
- requested provider alerts
- watchlist activity
- changes to our legal terms
For example, Enterprise API customers may receive an email when usage reaches approximately 80% of the plan's included monthly API allocation.
We may also send marketing communications where permitted by law.
You may unsubscribe from marketing emails using the unsubscribe mechanism included in those messages.
Unsubscribing from marketing communications does not prevent us from sending necessary transactional, account, billing, security, or Service communications.
10. How We Disclose Information
We may disclose information in the circumstances described below.
Service Providers
We may provide information to companies that perform services on our behalf, such as:
- cloud hosting
- database infrastructure
- authentication
- payment processing
- email delivery
- analytics
- customer support
- security
- monitoring
- other technical or business services
These providers may process information only as permitted by their agreements with us and applicable law.
Legal Requirements
We may disclose information if we reasonably believe disclosure is necessary to:
- comply with applicable law
- respond to valid legal process
- comply with a court order, subpoena, or governmental request
- investigate fraud or illegal activity
- enforce our agreements
- protect the security of the Service
- protect the rights, property, or safety of ASFMS, our users, or others
Business Transactions
Information may be disclosed or transferred as part of a merger, acquisition, financing, restructuring, bankruptcy, sale of assets, or other corporate transaction involving ASFMS or NPIData.org.
At Your Direction
We may disclose information when you request or authorize us to do so.
11. Sale and Sharing of Personal Information
Note for review: ASFMS should finalize this section based on the advertising, analytics, and data-provider services actually implemented at launch.
NPIData.org's core business involves providing professional healthcare-provider information and analytics to customers.
Provider Information appearing in the Service may therefore be made available to subscribers, API customers, and other authorized users as part of NPIData.org's products.
This may include publicly available professional information, business contact information, and analytics derived from such information.
We do not sell NPIData.org customer passwords or payment-card numbers.
Certain U.S. privacy laws define terms such as "sale," "sharing," or "targeted advertising" more broadly than their ordinary meanings. If our activities constitute a sale or sharing of personal information under a law applicable to you, we will provide any notices and rights required by that law.
12. Data Retention
We retain information for as long as reasonably necessary for the purposes for which it was collected, including to:
- provide the Service
- maintain accounts
- maintain historical provider datasets
- generate provider-change analytics
- comply with legal obligations
- maintain financial and tax records
- resolve disputes
- prevent fraud
- enforce agreements
- maintain security and audit records
Different categories of information may be retained for different periods.
Provider Information may be retained historically even after a source record changes because historical comparisons are part of the NPIData.org analytics service.
For example, retaining earlier provider locations may be necessary to identify provider relocations and market movements.
13. Data Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
However, no Internet transmission, database, or information-storage system can be guaranteed to be completely secure.
You are responsible for maintaining the confidentiality of your account credentials and API keys.
If you believe your account or API credentials have been compromised, contact us promptly.
14. HIPAA
NPIData.org is primarily a provider-data and healthcare business-intelligence service.
The presence of information about physicians, clinicians, practices, or healthcare organizations does not itself make that information protected health information ("PHI") under HIPAA.
NPIData.org is not intended for the submission, storage, or processing of patient medical records or patient PHI.
You should not submit PHI to NPIData.org unless ASFMS has expressly authorized such use in writing and, where legally required, entered into an appropriate Business Associate Agreement.
Unless we have expressly agreed otherwise in writing, ASFMS does not act as your HIPAA Business Associate through ordinary use of NPIData.org.
15. Children's Privacy
NPIData.org is a business and professional information service and is not directed to children.
The Service is intended for users aged 18 and over, and our Terms of Service require account holders to be at least 18. We do not knowingly collect personal information through user accounts from children under 13.
If you believe a child has provided personal information to us inappropriately, please contact us.
16. Your Privacy Choices
Depending on your location and applicable law, you may have rights concerning personal information about you, which may include rights to:
- request access to personal information
- request correction of inaccurate personal information
- request deletion of certain personal information
- obtain a portable copy of certain information
- opt out of certain sales or sharing of personal information
- opt out of targeted advertising
- limit certain processing
- appeal a decision concerning a privacy request
These rights are not absolute and may be subject to exceptions under applicable law.
For example, information may need to be retained to comply with legal obligations, maintain security records, complete transactions, exercise legal rights, or for other permitted purposes.
17. Provider Correction Requests
We recognize that provider records may sometimes be incomplete, outdated, or inaccurate.
Healthcare providers or authorized representatives who believe information associated with them on NPIData.org is inaccurate may contact us at:
privacy@npidata.org
Please identify the relevant provider and information you believe is inaccurate.
We may request reasonable information to verify your identity or authority before modifying information.
Where information comes directly from an external source such as NPPES, we may explain that the underlying record must also be corrected with the original source to prevent the information from reappearing in future updates.
NPPES provides mechanisms for healthcare providers to maintain information associated with their NPI records.
18. Provider Removal Requests
Because NPIData.org provides professional and public-record information services, a request to delete Provider Information does not necessarily result in removal.
Our response will depend on the nature of the information, its source, applicable law, and any legal exceptions.
Where applicable law provides a right to deletion or opt-out that applies to the information and is not subject to an exception, we will honor that right as required.
We may also maintain information internally where necessary for legal compliance, fraud prevention, suppression lists, record integrity, or other lawful purposes.
19. Verification of Privacy Requests
To protect personal information, we may need to verify your identity before fulfilling certain privacy requests.
Verification may require information sufficient to reasonably confirm that the request concerns you.
If an authorized agent submits a request on your behalf, we may require evidence of the agent's authority as permitted by applicable law.
20. Non-Discrimination
Where applicable law provides such a right, we will not unlawfully discriminate against you for exercising your privacy rights.
This does not prohibit us from offering different products, functionality, or pricing where legally permitted and reasonably related to differences in the services or data provided.
21. State-Specific Privacy Rights
Residents of certain U.S. states may have additional rights under applicable comprehensive consumer privacy laws.
Whether a particular law applies to ASFMS may depend on factors such as the company's size, revenue, volume and type of personal information processed, and business activities.
Where a state privacy law applies to our processing of your personal information, we will provide and honor the rights required by that law.
Florida's Digital Bill of Rights, for example, applies only to businesses meeting specified statutory criteria rather than every website serving Florida residents.
22. Do Not Track
Some browsers provide "Do Not Track" signals.
Because there is not a universally accepted standard governing all Do Not Track signals, our response may depend on the technologies and legal requirements applicable to the Service.
Where applicable law requires recognition of a legally valid browser-based opt-out preference signal, we will process that signal as required.
23. International Users
NPIData.org is operated from the United States and is primarily designed around United States healthcare-provider information.
If you access the Service from outside the United States, information may be transferred to, stored in, and processed in the United States or other countries where our service providers operate.
Those jurisdictions may have data-protection laws different from those in your country.
Where required, we will use legally recognized mechanisms for international transfers of personal information.
24. Third-Party Websites
NPIData.org may contain links to third-party websites, including government websites, healthcare organizations, provider practices, and other resources.
We do not control the privacy practices of third-party websites.
This Privacy Policy applies only to processing by ASFMS in connection with NPIData.org.
25. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
When we do, we will update the "Last Updated" date above.
If changes materially affect how we process personal information, we will provide additional notice where required by applicable law.
26. Contact Us
Questions, requests, or concerns regarding this Privacy Policy or NPIData.org's privacy practices may be directed to:
ASFMS LLC Operator of NPIData.org 936 SW 1ST AVE #101 MIAMI FL 33130 privacy@npidata.org
Last updated 2026-09-17.