hHealti

Privacy Policy

Last updated September 22, 2026

This explains what Healti stores, why, and what happens to it. It covers the credentialing product as it exists today. If we ever start handling a category of data described here as out of scope, we will say so before it happens, not afterwards.

Healti does not hold patient information. Credentialing is about the clinician — their license, their NPI, their malpractice cover — not about anyone they treat. We ask you not to upload patient records, claims or clinical notes to Healti. There is no field for them and no reason to have one.

What we store

About your practice: its name, address, specialty, group NPI and tax ID, your locations, and the users you invite (name, work email, role).

About your providers: name, credential, specialty, NPI, CAQH ID, date of birth, gender, work email and phone, start date, licenses and their expiry dates, board certifications, and the documents you upload — typically licenses, DEA registrations and malpractice certificates.

About your work: the enrollment applications you track, their status and history, your notes, follow-ups and tasks, and an activity log of who changed what.

Technical: authentication tokens, and server logs of requests and errors used to keep the service running.

Sensitive fields, and how we treat them

  • Date of birth and the last four digits of a Social Security number are collected because payers and exclusion lists use them to tell two clinicians with the same name apart. We store the last four digits only — never a full SSN — and we do not display them outside the provider’s own profile.
  • Uploaded documents are stored privately and are never served by a public link. Every download goes through an authenticated request tied to your account.

Who else sees it

We share data with a small number of processors, each for one purpose:

  • Our hosting and database provider — to run the application and store your data.
  • Stripe — to process subscription payments. Stripe receives billing details; we never see your full card number.
  • Our email provider — to deliver expiry reminders, password resets and service notices.

When you use a lookup, a provider’s NPI is sent to NPPES, the public federal registry, to retrieve their registry record. Exclusion screening works the other way around: we download the OIG list to our own server and compare locally, so your provider list is not sent to OIG. If SAM.gov screening is enabled, a provider’s name is sent to SAM.gov to run the check.

We do not sell your data, we do not share it with advertisers, and we do not use it to train machine-learning models.

How long we keep it

  • Your practice data stays while your account is active.
  • After you cancel, we keep it for 30 days so you can export or reactivate, then delete it.
  • You can ask us to delete it sooner by writing to support@healti.com.
  • Billing records are kept as long as tax and accounting rules require, separately from your practice data.

Security

  • All traffic between your browser and Healti is encrypted in transit.
  • Passwords are stored hashed. Nobody at Healti can read yours.
  • Every request is scoped to your practice: one practice cannot read another’s data.
  • Uploaded documents require an authenticated request; there are no public file URLs.

No system is perfectly secure. If a breach affects your data, we will tell you what happened, what it affected and what we did about it — without waiting to have every answer first.

Your choices

  • See and correct it. Everything we hold about your practice is visible and editable in the app.
  • Export it. Roster as CSV and documents as a ZIP, from Settings, at any time.
  • Delete it. Cancel and ask us to delete, or write to support.
  • Control emails. Expiry reminders and digests are configured in Settings. Service emails — password resets, billing failures — cannot be turned off while the account is active.

A note on HIPAA

Because Healti holds information about clinicians and not about patients, it does not process protected health information, and a Business Associate Agreement is not required for the credentialing product. If that changes — if we add a feature that touches patient data — we will not ship it before the corresponding safeguards and agreements are in place, and we will tell you first.

Contact

Questions, corrections or deletion requests: support@healti.com.