ExclusionWatch Acceptable Use Policy
Version 1.0
Effective date: September 16, 2025
This Acceptable Use Policy (“AUP”) applies to all use of ExclusionWatch and is incorporated into the ExclusionWatch Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
1. Authorized Purpose
ExclusionWatch may be used to support lawful healthcare-program exclusion, sanction, debarment, credentialing, vendor, contractor, and workforce compliance activities.
The Service is not a general-purpose background-check service, credit-reporting service, medical-record system, patient-record system, or identity-verification service.
2. Prohibited Data
Users must not upload, enter, transmit, or store:
- patient information or Protected Health Information;
- claims, diagnoses, treatments, prescriptions, medical record numbers, or other clinical information;
- Social Security numbers, including partial Social Security numbers;
- complete EINs, tax-identification numbers, passport numbers, or driver’s license numbers;
- payment-card or bank-account information;
- passwords, authentication codes, API keys, or private keys;
- biometric identifiers, genetic information, or precise geolocation;
- information about minors unless legally authorized and strictly necessary for a permitted exclusion-screening purpose; or
- information unrelated to the permitted screening purpose.
The optional last four digits of a vendor EIN may be used only when reasonably necessary to distinguish vendor entities and when Customer is authorized to use that information.
3. Prohibited Conduct
Users must not:
- use a candidate match as a final determination without appropriate review;
- knowingly make false, misleading, discriminatory, or unlawful decisions;
- use the Service in violation of employment, credentialing, privacy, consumer-reporting, sanctions, or anti-discrimination laws;
- screen a person or organization without a legitimate, authorized purpose;
- impersonate another person or share accounts;
- access another customer’s organization or data;
- bypass access controls, multifactor authentication, source restrictions, rate limits, or security controls;
- probe, scan, or test the Service without ExclusionWatch’s written authorization;
- introduce malware, destructive code, or automated traffic that interferes with the Service;
- scrape, bulk-copy, republish, sublicense, or resell source data or Service output as a competing database;
- reverse engineer the Service except where a prohibition is unenforceable;
- use reports or exports to harass, threaten, or publicly shame a roster subject; or
- assist another person in doing any of the above.
4. Review and Decision Requirements
Candidate matches may be caused by common names, incomplete roster data, publisher errors, or differences in identifiers. Before confirming or acting on a match, Customer should evaluate available identifiers, including middle name, date of birth, NPI, license, address, provider type, exclusion details, and primary-source information.
Customer is responsible for providing legally required notice, opportunity to respond, correction procedures, or adverse-action process to an affected person.
5. Credentials and Exports
Users must protect passwords, authenticator devices, SSO credentials, downloaded reports, and CSV exports. Exports should be stored only in approved locations and deleted when no longer needed.
Suspected account compromise or unauthorized disclosure must be reported promptly to contact@exclusionwatch.org.
6. Enforcement
ExclusionWatch may investigate potential violations and may remove prohibited data, restrict functionality, suspend access, or terminate use. When circumstances permit, ExclusionWatch will notify Customer and provide a reasonable opportunity to correct the violation.
ExclusionWatch may preserve and disclose information when reasonably necessary to protect the Service or comply with law. ExclusionWatch will handle Customer Data in accordance with the Terms, Privacy Notice, and DPA.
7. Reporting
Report abuse, suspected security issues, or prohibited data to:
contact@exclusionwatch.org