ExclusionWatch No-PHI Policy
Version 1.0
Effective date: September 16, 2025
Purpose
ExclusionWatch is designed for workforce, provider, contractor, and vendor exclusion screening. It is not designed to collect or process patient or clinical information.
Customers and users must not submit Protected Health Information (“PHI”) to ExclusionWatch. “PHI” has the meaning assigned under the Health Insurance Portability and Accountability Act and its implementing regulations.
Information That May Be Used
For a legitimate workforce or vendor screening purpose, the Service may accept:
- an employee’s, provider’s, contractor’s, owner’s, or vendor representative’s name and former names;
- date of birth when reasonably needed to distinguish candidate matches;
- National Provider Identifier;
- professional license number and state;
- position and employment or contract dates;
- vendor legal and DBA names;
- vendor type, business address, organization NPI, and the last four digits of a vendor EIN; and
- internal employee, provider, contractor, or vendor identifiers that do not contain a Social Security number.
The same data element may be PHI in one context and non-PHI in another. For example, a name and date of birth used to screen an employee may be workforce information, while that information connected to the individual’s patient care may be PHI. Only the workforce/vendor context is permitted.
Information That Must Not Be Used
Do not enter or upload:
- patient names or patient rosters;
- diagnoses, conditions, procedures, medications, or treatment information;
- claims, encounter, eligibility, or health-plan member information;
- medical record, patient, beneficiary, or insurance-member numbers;
- clinical notes or records;
- information showing that a person received healthcare;
- Social Security numbers or partial Social Security numbers; or
- any attachment or notes field containing PHI.
No Business Associate Agreement
Standard ExclusionWatch service is not offered under a Business Associate Agreement (“BAA”). The Terms of Service and this policy do not constitute a BAA.
No customer may use ExclusionWatch to create, receive, maintain, or transmit PHI on behalf of a HIPAA covered entity or business associate unless ExclusionWatch has expressly approved that use in writing and a BAA has been signed before the PHI is submitted.
Accidental Submission
If a customer believes PHI was submitted:
- stop further uploads of the affected information;
- do not copy the information into support messages;
- contact contact@exclusionwatch.org and identify the organization, affected screen or import, approximate time, and record identifier without repeating the PHI;
- preserve relevant internal facts needed for investigation; and
- cooperate with ExclusionWatch’s secure deletion and incident-assessment process.
ExclusionWatch may isolate or delete suspected PHI and temporarily restrict affected features. ExclusionWatch will coordinate with Customer concerning confirmed incidents, but Customer remains responsible for its own legal analysis, notifications, and obligations.
Customer Administration
Organization administrators should:
- train users on this policy;
- remove PHI and unnecessary columns before importing files;
- use the ExclusionWatch templates rather than exporting broad HR, EHR, or practice-management datasets;
- limit roster access to personnel who need it;
- review free-text notes before saving them; and
- report suspected violations promptly.
Questions about permitted data should be sent to contact@exclusionwatch.org before upload.