1. What this policy covers
MedVerity ("we," "us," or "our") is a service of Signal Loom AI that provides medical license verification, physician profile enrichment, and "Fix at the Source" routing. This Privacy Policy describes how we collect, use, store, and protect your information when you use medverity.co and related services (the "Service").
2. Information we collect
a. Information you provide directly
- Account information: Email address, name, professional credentials (NPI, license number, board certifications you choose to add)
- Payment information: Processed by our payment processor (Lago + Stripe). We do not store your full credit card number.
- Communications: Support emails, feedback, and any messages you send us
b. Information from public sources
MedVerity aggregates data from publicly available sources to build physician profiles. We collect:
- NPI Registry: Name, license number, taxonomy, address, status
- State medical boards: License status, board actions, expiration dates
- Hospital websites: Affiliations, specializations
- Medical journals: Publications, board certifications (where publicly listed)
- Google search results: Aggregator listings, third-party directory entries
c. Information from your usage
- API usage: Timestamps, tool called, response time, request count, rate limit status
- Audit trail: SHA-256 evidence hash of every call (for compliance and fraud detection)
- Device & connection: IP address, user agent, Cloudflare ray ID (for security and abuse prevention)
3. How we use your information
We use the information we collect to:
- Provide the Service: Aggregate, verify, and display physician profile data
- Show source transparency: Display where each data point came from with timestamps
- Enable "Fix at the Source": Link directly to registries where corrections can be made
- Monitor for changes: Re-verify profiles weekly and alert on changes (paid tiers)
- Bill accurately: Per-call metering, pack credit consumption, monthly invoicing
- Prevent abuse: Rate limiting, fraud detection, security event logging
- Improve the Service: Aggregate usage patterns (anonymized) to identify bugs and optimize performance
- Comply with law: Respond to legal requests, comply with applicable laws (tax reporting, etc.)
4. What we do NOT do
- We do not sell your data to third parties. Ever.
- We do not share your data with marketing companies, ad networks, or data brokers.
- We do not store patient health information (PHI). We only aggregate publicly available provider data.
- We do not require your SSN, DEA number, or any non-public credentials.
- We do not read your emails or messages for advertising or training purposes.
5. HIPAA and PHI: why we don't need a BAA
⚠️ Our Terms of Service prohibit the submission of any Protected Health Information (PHI). By using MedVerity, you agree NOT to submit patient names, patient health information, or any PHI. If you accidentally share PHI, we will immediately delete it and notify you within 24 hours. See Terms of Service §2.2 for the full prohibition.
MedVerity does not store, process, or transmit Protected Health Information (PHI) as defined under HIPAA. We aggregate publicly available professional data about healthcare providers — not their patients' health information.
What we collect is NOT PHI:
- NPI Registry data: name, license number, taxonomy, address, phone, specialty, license status — all publicly available
- State medical board listings: license status, expiration, board actions — all publicly available
- Hospital website affiliations — publicly available
- Provider-enriched data: board certifications, languages, insurance accepted, telehealth availability — provider claims only (never patients)
- Self-service enrichment: providers add their own professional data (no patient data)
What is PHI under HIPAA? "Individually identifiable health information" about patients — diagnoses, treatment plans, insurance claims for specific patients, lab results, etc. We don't have any of that. HIPAA protects patients' health information, not providers' professional credentials.
Why no BAA is needed: Under HIPAA, a Business Associate Agreement is required when a vendor touches PHI on behalf of a covered entity. MedVerity does not touch PHI. Our service operates entirely on publicly available provider data and provider-claimed enrichment data. We are not a Business Associate of any covered entity.
What about dispute filings? If you (a physician) use our dispute filing service, we file corrections with the appropriate registry on your behalf. The dispute filing documentation must not include patient names, patient cases, or any PHI. If you accidentally share patient data with us in a dispute filing, we will:
- Immediately delete the patient data from our systems
- Notify you within 24 hours
- Not retain copies in any backups
For Practice and Health System customers who want extra safeguards: We can sign a BAA as a procurement checkbox (some enterprise customers require this even when not legally necessary). Contact team@medverity.co for BAA terms.
6. How we protect your data
- Encryption in transit: TLS 1.3 for all HTTP traffic (HSTS enforced)
- Encryption at rest: Cloudflare KV data is encrypted at rest by Cloudflare
- API key security: We hash API keys with SHA-256 before storage. We never store plain keys.
- Access control: Tier-based rate limits, IP-based rate limits for unauthenticated calls
- Audit trail: Every API call is logged with a SHA-256 evidence hash for 90 days
- Content Security Policy: Strict CSP prevents XSS attacks
- Subresource Integrity: We use SRI for any third-party scripts (none currently)
7. Data retention
- Audit logs: 90 days (KV TTL)
- Usage records: Until you delete your account + 30 days for billing reconciliation
- Aggregated physician profile data: Until you request deletion
- Billing records: 7 years (US tax requirement)
- API keys: Until revoked or account deleted
8. Your rights and choices
You have the right to:
- Access: Request a copy of all data we hold about you (export to JSON)
- Correct: Update your profile, claim enrichment data (additive only — registry data is immutable)
- Delete: Request full account deletion (KV data purged within 30 days; billing records retained 7 years per tax law)
- Export: JSON export of your profile, audit logs, and billing history
- Opt out of monitoring: Cancel Practice tier to stop weekly re-verification alerts
- API key rotation: Generate a new key anytime (old key invalidated immediately)
9. Third-party services we use
- Cloudflare: Hosting, DNS, edge network (privacy policy: cloudflare.com)
- Lago: Metering and billing infrastructure (privacy policy: getlago.com)
- Stripe: Payment processing (privacy policy: stripe.com)
- Resend: Transactional email (privacy policy: resend.com)
- Signal Loom AI: Parent company. Operates MedVerity and other products.
Each of these services has its own privacy policy. We choose providers that meet or exceed our data protection standards.
10. International data transfers
MedVerity is operated from the United States. If you are accessing the Service from outside the US, please be aware that your information will be transferred to, stored, and processed in the United States. By using the Service, you consent to the transfer of your information to the US.
For EU/UK users: We comply with GDPR data subject rights (access, rectification, erasure, restriction, portability) and use standard contractual clauses for international transfers.
11. Children's privacy
MedVerity is not intended for use by children under 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected such information, we will delete it.
12. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email (if you have an account) and by updating the "Last updated" date at the top of this page. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
13. Contact us
For privacy-related questions, data subject requests, or to file a complaint: