Home › Security

Security & data handling

Interstate Medicine Ledger · Last updated: September 26, 2026

The Ledger holds a clinician’s licensing and credentialing record. This page says, in plain terms, where that record lives, who can see it, and what we do and do not claim. When something here changes, we change this page.

What we hold, and what we don’t

We hold a clinician’s own professional record: licenses and renewal dates, DEA and state controlled-substance registrations, board certifications, life-support cards, malpractice coverage, work history, CME certificates, the clinician’s own immunization and TB records if they add them, and the documents behind each of these. Date of birth and a photo ID are optional.

We do not hold patient records. Nothing in the Ledger is protected health information about patients. We do not accept or store Social Security numbers: the document reader is told never to read one, and any nine-digit number shaped like one is removed from its answer before it reaches your screen.

Where it lives

Who can see what

Every table in the database has row-level security switched on, and new tables get it automatically. The database itself, not the app, decides what each signed-in person can read.

LevelWhat the organization can do
1 · Compliance onlySee licenses held, requirements met or owed, and renewal dates. No identifiers.
2 · Full profileLevel 1, plus license numbers, contact details, date of birth and the stored documents.
3 · ManageLevel 2, plus uploading documents and correcting records on the clinician’s behalf.
4 · Full controlLevel 3, plus creating the account and handing it to the clinician’s email.

Signing in

How documents are read

Email and payments

Keeping and deleting data

Exclusion and registry checks

Once a month we compare each clinician’s name and NPI with public lists: the OIG exclusion list (LEIE), the CMS opt-out and Order & Referring files, and the NPPES registry. We download those lists and do the comparison ourselves, so your details are not sent to anyone for this. An organization can also run a SAM.gov exclusion check, which sends the clinician’s name to SAM.gov’s public search. Results are shown to the clinician, and to an organization only if the clinician has given it access; a match made on the NPI is shown to an organization only at level 2 or above. A name match is shown as a possible match for a person to review, never as a finding on its own.

Browser protections

The app sends HSTS, a Permissions-Policy that turns off camera, microphone, location, payment and similar browser features, and a rule that stops other sites from framing it. Our Content Security Policy currently runs in report-only mode. We collect its reports and will switch it to enforcing once they are clean.

What we do not claim

Report a security issue

If you think you have found a vulnerability, email hello@interstatemedicine.com with “Security” in the subject. Please give us a reasonable chance to fix it before you share it. See also our Privacy Policy.