Home › Privacy & security
Privacy & security
What we collect, how we protect it, who sees it, and how to have it corrected or deleted. If your organization has a security questionnaire, we're happy to fill it in.
Last updated October 6, 2026
- No patient informationWe never ask for or store patient records or other protected health information.
- No Social Security numbersScreening uses staff names and, where you have them, NPI numbers.
- No data sales or adsWe don't sell, rent or trade information, and the site has no advertising trackers.
What we collect
- When you get started: your name, work email, organization, state, organization type, staff count and any note you add, plus the internet address the request came from, which we keep to prevent abuse.
- Your staff list: the names and NPI numbers you upload, and each month's screening results.
- If you subscribe: your plan and the reference numbers Stripe gives us. Your card details stay with Stripe.
- Visits to the site: we count page views with a code that changes every day, so we can tell how many people visited without tracking anyone over time. We don't store visitors' internet addresses with these counts, and we delete them after 120 days.
How we protect it
- Encrypted connections: every page is served over HTTPS through Cloudflare, which also filters malicious traffic.
- No passwords to steal: your account opens with a private link we email you (a random 32-character code). Treat it like a password. We don't store passwords.
- Payments by Stripe: Stripe is certified to PCI DSS Level 1, the highest level for card payment processors.
- Limited access: only the business owner has access to the server and its admin area, which is password-protected.
- Nightly backups: encrypted, stored privately and kept for 30 days.
Who we share it with
Only the services that run the site: Stripe (payments), Resend (email delivery) and Cloudflare (hosting and protection). We don't share information with anyone else, except where the law requires it. Your staff list and screening results are never shown publicly.
Your choices
- Correct or delete: email privacy@masslicensedirectory.com and we'll correct or delete your information within 30 days. Records we must keep for tax or payment purposes are kept only as long as required.
- Cancel any time: email us and we'll cancel your plan and delete your staff list.
Certifications and data sources
We don't currently hold SOC 2 or HITRUST certification. Because we don't handle patient information, we aren't a HIPAA business associate. Exclusion data comes from the public HHS-OIG List of Excluded Individuals/Entities and SAM.gov. StaffScreen is an independent service, not a government agency, and confirming a possible match with the official list remains the employer's responsibility.
StaffScreen is run by the same business as Massachusetts License Directory, and shares its systems and these practices.