PAMAwatch

Privacy Policy

PAMAwatch collects the minimum it needs to work, and nothing it does not.

What is collected

PAMAwatch has no accounts, no login, and no database. The checker at /check works by looking up an NPI or a lab name you type against a static dataset built ahead of time from CMS's own public Medicare billing data; what you enter is never stored, only used to render the page you asked for. Anonymous usage analytics (pageviews and the checker's own submit event) run via Vercel Analytics, with no cross-site tracking cookies. Where product analytics is switched on, PostHog also records pageviews, interaction events and error reports; in the EU, EEA and UK nothing identifiable is captured until the cookie banner is answered, and declining switches it to a rotating hash with no cookie at all.

What is never done with it

Nothing here is sold, rented, or shared for advertising. No marketing lists, no third-party ad trackers, no profiling, no email capture. The only outside processors are Vercel (hosting and anonymous analytics) and, where product analytics is switched on, PostHog (usage analytics and error reporting), each holding the minimum their job needs.

The lab data shown by the checker

Lab names, cities, states, NPIs and Medicare billing figures shown on a /check result page are CMS's own public disclosure, already available to anyone at data.cms.gov. Nothing about the visitor running the check is attached to that lab's record; there is no way, from this site, to know who looked up a given NPI or name.