Included · Not yet included
SOC 2 not held, stated plainly, beats SOC 2 implied. This table is honest. Procurement teams respect transparency.
| Status | Item | Note |
|---|---|---|
| ✅ | Delaware LLC registration | Fonteum LLC — formed December 2024. |
| ✅ | Active production source registry documented | Registry status does not establish loaded, complete, or fresh coverage. 11.9M NPPES and PECOS rows are counted separately rather than as historical versions. |
| ✅ | Source-specific cadence disclosure | The count-observation date is separate from each upstream source release and ingestion date. |
| 🟡 | Provenance fields on supported exports | Fields vary by source and export. Fourteen of 26,211,234 directly counted provenance rows lacked a source-file SHA-256 on July 12. |
| ✅ | BAA template available | Template in this pack. Fonteum processes no PHI; BAA is a procurement formality. |
| ✅ | FHIR R4 API (Practitioner, Organization, Location, PractitionerRole, HealthcareService) | US Core 6.1.0. SMART on FHIR auth. p99 under 300ms on single-record lookups. |
| ❌ | SOC 2 Type 1 — not held | Fonteum does not currently hold a SOC 2 Type 1 attestation, and displays no badge it does not hold. |
| ❌ | SOC 2 Type 2 — not held | Fonteum does not currently hold a SOC 2 Type 2 attestation. The hosting and data tiers run on SOC 2 Type 2 attested infrastructure (Vercel, Supabase). |
| ❌ | HITRUST certification | Not held. Federal-data-only scope, with no PHI processed, covers procurement requirements. |
| ❌ | FedRAMP authorization | Out of scope for current procurement tier. |
Dataset documentation
Audit evidence by dataset.
Each dataset pack names its source families, documented fields, limitations, and snapshot scope. The paired methodology page records the reproducibility rules and version history.
Dermatology Provider Supply by State
Active U.S. dermatologists per 100,000 residents, by state, from the public CMS NPI Registry.
Psychiatry Provider Supply by State
Active U.S. psychiatrists per 100,000 residents, by state.
Cardiology Provider Supply by State
Active U.S. cardiologists per 100,000 residents, by state.
Obstetrics & Gynecology Provider Supply by State
Active U.S. OB-GYN physicians per 100,000 residents, by state.
Pediatrics Provider Supply by State
Active U.S. pediatricians per 100,000 residents, by state.
Neurology Provider Supply by State
Active U.S. neurologists per 100,000 residents, by state.
Oncology Provider Supply by State
Active U.S. medical oncologists per 100,000 residents, by state.
Orthopedic Surgeon Supply by State
Active U.S. orthopedic surgeons per 100,000 residents, by state.
Ophthalmology Provider Supply by State
Active U.S. ophthalmologists per 100,000 residents, by state.
Gastroenterology Provider Supply by State
Active U.S. gastroenterologists per 100,000 residents, by state.
Urology Provider Supply by State
Active U.S. urologists per 100,000 residents, by state.
Otolaryngology (ENT) Provider Supply by State
Active U.S. otolaryngologists (ENT) per 100,000 residents, by state.
Chiropractor Provider Supply by State
Active U.S. chiropractors per 100,000 residents, by state.
Nursing-Home Quality by State (CMS Care Compare)
State-level rollups of CMS Care Compare nursing-home overall quality ratings.
Dialysis Facility Quality by State (CMS Care Compare)
State-level rollups of CMS Care Compare dialysis-facility ratings.
Home-Health Quality by State (CMS Care Compare)
State-level rollups of CMS Care Compare home-health agency ratings.
Hospice Provider Availability by State (CMS Care Compare)
State-level rollups of CMS Care Compare hospice provider counts.
Inside the pack
Corporate
- —Delaware limited liability company — formed December 2024.
- —Legal name: Fonteum LLC
- —Registered agent: on file with Delaware Division of Corporations.
- —EIN: available to contracted customers under NDA.
Security
- —SOC 2 — not held. Fonteum does not currently hold a SOC 2 attestation; the hosting and data tiers run on SOC 2 Type 2 attested infrastructure (Vercel, Supabase).
- —Infrastructure: Vercel (US-East) + Supabase managed Postgres.
- —Encryption in transit: TLS 1.2+. At rest: AES-256.
- —Access controls: row-level security on all public tables. Service-role keys never exposed to browser.
- —Vulnerability disclosure: security@fonteum.com · /.well-known/security.txt (RFC 9116).
Data
- —15 cataloged ingest datasets within the active production registry; registry status does not establish loaded, complete, or fresh coverage. 11.9M NPPES and PECOS rows counted separately.
- —License grant: CMS data is U.S. Government Works (public domain). HHS-OIG LEIE is publicly distributed federal data.
- —No claims data, no EHR data, no commercial data, no consumer PII.
- —Available provenance fields: source, snapshot date, methodology version, and confidence tier where supplied; fields may be null.
- —Provenance schema documented at /methodology.
Operations
- —Freshness reporting: source and loaded-observation dates are stated per dataset where available; this pack does not claim a platform-wide refresh SLA.
- —Incident notification: 72h from confirmed breach, plus public corrections-log entry.
- —Corrections log: /corrections-log — public entries for published data corrections.
- —Response-time commitment: P0 (service-down) within 2h. P1 (data-quality) within 24h.
Legal
- —BAA template: included in this pack. Fonteum processes no PHI.
- —AI training license: federal public-record data is public domain. No restriction on downstream model training.
- —Terms of use: /terms. Data use for research, analytics, and commercial applications is permitted with attribution.
- —GDPR position: DSAR requests honored within 30 days. We do not sell personal data.
Fonteum Audit Pack v2026.05 · 2026-05-25 Active production source registry; status is not loaded, complete, or fresh coverage 11.9M NPPES and PECOS rows, counted separately SOC 2: not held BAA template: included License: US Government Works
Pilot and contracted customers
Customer-scoped packs on request.
Pilot, standard, and enterprise customers receive audit packs scoped to their contracted dataset list and delivery cadence. Methodology version is pinned to the snapshot they received. Rollback to a prior version is documented in the change history. This pack is the downloadable artifact behind the audit evidence & defensible programs use case, where the same provenance drives a dual-buyer screening and query workflow.
API export endpoint
Bulk export for contracted customers.
Contracted pilots get programmatic access via /api/v1/audit-pack/export. The endpoint returns NDJSON, JSON, or CSV. Source inventory is drawn from the SPRINT1_EXPORT_SOURCES registry (a scoped healthcare export catalog; provenance availability varies by source).
# Sample request
curl -H "Authorization: Bearer fnt_<your_key>" \
"https://fonteum.com/api/v1/audit-pack/export?format=ndjson"
Supported exports document the provenance columns they include; do not assume every source emits the same source, snapshot, method, and confidence fields. Export keys are issued at pilot onboarding. Contact pilot@fonteum.com to request a key.