Skip to content
FonteumPublic-records evidence

About → Privacy

Privacy policy.

Effective 2026-05-10 · Last revised 2026-05-10

Scope

Fonteum operates source-of-truth healthcare provider data infrastructure. We aggregate, normalize, and re-publish data originating in U.S. federal public-record sources — CMS NPPES, CMS PECOS, CMS Care Compare, OIG LEIE, HRSA HPSA, BLS OEWS, BEA Regional, CMS Open Payments, CMS Provider Utilization. This policy describes how Fonteum handles personal data collected through fonteum.com and its API surfaces.

No-PHI processing posture

Fonteum does not receive, process, or store Protected Health Information (PHI) as defined by HIPAA. We do not handle patient identifiers, medical records, claims data, test results, or treatment narratives. Every published field ties to an entry in provider_field_provenance that in turn ties to a row in data_sources — a 14-tuple provenance contract documented at /data. Because no published field originates from PHI, Fonteum is not a HIPAA Covered Entity, Business Associate, or Subcontractor under 45 CFR § 160.103.

Public-records sourcing

Provider-level data published on this site originates in U.S. federal public-record sources. The National Provider Identifier (NPI) Registry (CMS NPPES) is publicly distributed under 5 U.S.C. § 552 (FOIA) and is in the public domain. CMS Care Compare, CMS Open Payments, OIG LEIE, and HRSA HPSA all publish their underlying datasets under open-government licensing. Fonteum does not pay providers to be listed and does not solicit data submissions from individual providers.

California (CCPA/CPRA) data subject rights

California residents have the right under the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.) to request access to, correction of, or deletion of personal information collected about them. For Fonteum-published provider records, exercise these rights via /corrections-log or by emailing privacy@fonteum.com. We respond within 45 days. Note: where the underlying field originates in a federal public record (NPI, OIG-published exclusion, CMS facility certification), Fonteum cannot remove the upstream record — corrections must be filed with the source agency. We can and will remove the field from Fonteum surfaces while the upstream correction is pending.

EU (GDPR) Article 14 notice

For EU/EEA-resident providers whose data is published in U.S. federal sources we ingest, this section serves as the Article 14 GDPR notice for indirectly collected data. The data controller is Fonteum LLC, reachable at privacy@fonteum.com. The lawful basis is Article 6(1)(f) (legitimate interests) — operating a public-record provenance graph for healthcare research and transparency. Categories of data processed: provider name, license number, NPI, practice address, federal credentialing status, and CMS-published quality metrics. Recipients are limited to Fonteum infrastructure providers (Vercel, Supabase, Inngest, Sentry, Resend) and the public web. EU residents have rights of access, rectification, erasure, restriction, objection, and portability under GDPR Articles 15-22, exercised via the same email. Sanctions, company-register, procurement, and other non-provider public records are covered by the separate public records privacy notice.

Operator-side personal information

For people who interact with the site directly (researchers who request API access, journalists who fill the contact form, providers who submit a record correction), we collect only the information explicitly submitted: name, email, organization, ORCID, and the message body. This information is stored in Supabase, retained for the lifetime of the relationship plus two years for audit purposes, and never sold or shared with third-party advertisers. Logs and observability: Plausible cookieless aggregate analytics and Sentry error telemetry with no request bodies. All processors are reviewed for production use.

90-day retention on derived analytics

Cookieless aggregate analytics are retained according to the analytics provider’s aggregate reporting settings. Public-record provider data has no retention limit because the upstream sources have no retention limit; corrections and presentation-layer suppressions are additive records rather than source-snapshot deletions.

Cookies and tracking

Fonteum uses cookies only for authenticated operational surfaces such as admin tools. Public pages do not set analytics cookies, write browser storage, or run third-party advertising trackers. Plausible remains enabled because it is cookieless and does not store identifiers on the device.

Children

Fonteum surfaces healthcare-provider data to a professional audience and is not directed at children under 13 (COPPA) or under 16 (GDPR-K). We do not knowingly collect personal information from minors.

Changes to this policy

Material changes will be announced on /corrections-log with a revision date. The Effective and Last revised dates at the top of this page reflect the most recent edit.

Contact

Privacy inquiries: privacy@fonteum.com
Corrections / takedowns: corrections@fonteum.com
General contact: /contact

What’s on file, by the numbers

Platform snapshot · 2026-08-25

13.4Mproviders & companiesProviders, organizations, owners, and facilities on file
26.2Msource-linked factsSource-linked field facts in the dated platform snapshot
90sources with dataDistinct snapshot source IDs with at least one positive record count
70fresh sourcesDistinct source IDs whose latest positive-data snapshot falls within the preceding 45 days
111sources integratedActive registry rows; integration does not establish a load
13state Medicaid jurisdictionsDistinct states represented in the state-exclusions serving table

Integrated, with-data, and fresh-observation counts are separate. No platform-wide source-completeness count is published. Completeness is source-specific and must be evaluated against the named source's expected scope. State coverage is a separate jurisdiction measure.

Source authority is record-specific

Use the issuer named on the record.

Fonteum spans federal, state, and global public publishers. A source page or returned record identifies its issuer and dataset where that metadata is available. A platform registry count does not assign every page to one authority or establish loaded, fresh, or complete coverage.

Browse source records and their stated limitations →

Reproducible by design

Inspect the evidence each published figure actually supplies.

Source and date

Research pages expose the named public file and observation date where those fields are available. Source-file SHA-256 coverage is separate; facts do not currently link deterministically to signatures.

Available derivation

Studies with a retained release and committed derivation link the SQL or method used. Other studies state the evidence and reproduction limits they actually have.

Daily observations

Dated table row-count observations can detect local drift. They do not imply that an upstream publisher released or Fonteum ingested new data that day.

Named medical review

Reviewed by Jennifer Montecillo, MD, medical reviewer. Non-practicing medical reviewer.

Read the full provenance and attestation methodology →

Request access