Any organization using public healthcare provider records
Ethical use of public provider data
Practical boundaries for using public provider records without maximizing personal exposure or enabling harmful outreach.
Last updated July 20, 2026
Public availability does not eliminate privacy risk. Individual provider records can contain home-like locations or personal contact details, and careless reuse can enable harassment, discrimination, or intrusive outreach.
ProviderFront applies field-level display policy before data reaches a public template. Mailing addresses are non-public by default. Practice addresses can be reduced to city and state or suppressed when privacy heuristics or a reviewed correction indicate a residential or private location. Direct email, personal phone, fax, endpoint details, license numbers, and EIN data are not published as lead fields.
Users must not use ProviderFront for patient-care decisions, as a sole credentialing source, for unlawful discrimination, harassment, or deceptive outreach. Customer notes must not contain protected health information. Corrections, suppression reports, and a verified claim path provide a way to address errors without republishing them after the next import.
Official sources
ProviderFront is independent and not affiliated with CMS or NPPES.