{"id":54162,"date":"2026-02-01T12:25:53","date_gmt":"2026-02-01T18:25:53","guid":{"rendered":"https:\/\/heartbeat.ai\/healthcare\/data-sources-we-use\/"},"modified":"2026-08-29T07:04:40","modified_gmt":"2026-08-29T12:04:40","slug":"data-sources-we-use","status":"publish","type":"post","link":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/","title":{"rendered":"Data sources for provider contact data (provenance, limits, and how to test)"},"content":{"rendered":"<p class=\"article-last-updated\"><strong>Last updated:<\/strong> August 29, 2026<\/p>\n<p><strong>By Ben Argeband, Founder &amp; CEO of Heartbeat.ai<\/strong><\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\r\n<div class=\"ez-toc-title-container\">\r\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">What\u2019s on this page:<\/p>\r\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\r\n<nav><ul class='ez-toc-list ez-toc-list-level-1' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Who_this_is_for\" >Who this is for<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Quick_answer\" >Quick answer<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Identity_is_not_reach_why_public_IDs_dont_equal_contactability\" >Identity is not reach: why public IDs don&#8217;t equal contactability<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#At_a_glance_identity_sources_vs_reach_sources\" >At a glance: identity sources vs. reach sources<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Step-by-step_method\" >Step-by-step method<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Step_1_Establish_identity_anchors\" >Step 1: Establish identity anchors<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Step_2_Normalize_and_resolve_identity\" >Step 2: Normalize and resolve identity<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Step_3_Add_channel_reach_signals\" >Step 3: Add channel reach signals<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#How_this_plays_out_in_practice\" >How this plays out in practice<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Step_4_Apply_suppression_and_preference_handling\" >Step 4: Apply suppression and preference handling<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Step_5_Refresh_cadence_and_decay_reality\" >Step 5: Refresh cadence and decay reality<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Step_6_Limits_you_should_expect_in_writing\" >Step 6: Limits you should expect in writing<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Diagnostic_table_for_procurement_review\" >Diagnostic table for procurement review<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Weighted_checklist_for_scoring_vendors\" >Weighted checklist for scoring vendors<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Outreach_templates\" >Outreach templates<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Template_1_First-touch_email_identity-confirming\" >Template 1: First-touch email (identity-confirming)<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Template_2_Voicemail\" >Template 2: Voicemail<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Template_3_Office_line_gatekeeper_script\" >Template 3: Office line gatekeeper script<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Common_pitfalls\" >Common pitfalls<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Treating_NPI_as_a_contact_record\" >Treating NPI as a contact record<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Not_labeling_channel_types\" >Not labeling channel types<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#No_shared_metric_definitions\" >No shared metric definitions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-23\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Provenance_without_limits\" >Provenance without limits<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-24\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#How_to_improve_results\" >How to improve results<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-25\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Run_a_%E2%80%9Cshow_your_work%E2%80%9D_pilot\" >Run a &#8220;show your work&#8221; pilot<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-26\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Improve_reach_without_increasing_risk\" >Improve reach without increasing risk<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-27\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Build_state-by-state_verification_into_the_workflow\" >Build state-by-state verification into the workflow<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-28\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Legal_and_ethical_use\" >Legal and ethical use<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-29\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Evidence_and_trust_notes\" >Evidence and trust notes<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-30\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Procurement_artifacts_to_request\" >Procurement artifacts to request<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-31\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#FAQs\" >FAQs<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-32\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#What_are_the_best_data_sources_for_provider_identity\" >What are the best data sources for provider identity?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-33\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Why_cant_a_public_registry_guarantee_contactability\" >Why can&#8217;t a public registry guarantee contactability?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-34\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#What_metrics_should_we_require_in_a_pilot\" >What metrics should we require in a pilot?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-35\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#How_do_we_evaluate_%E2%80%9Cfreshness%E2%80%9D_without_relying_on_vendor_promises\" >How do we evaluate &#8220;freshness&#8221; without relying on vendor promises?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-36\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#What_documentation_should_a_vendor_provide_to_prove_provenance\" >What documentation should a vendor provide to prove provenance?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-37\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Does_Heartbeatai_use_patient_data\" >Does Heartbeat.ai use patient data?<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-38\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#Next_steps\" >Next steps<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-39\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#About_the_Author\" >About the Author<\/a><\/li><\/ul><\/nav><\/div>\r\n<h2><span class=\"ez-toc-section\" id=\"Who_this_is_for\"><\/span>Who this is for<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This page is for buyers, compliance reviewers, and internal evaluation teams who need a straight answer to one question: where did this provider contact data come from, and what are its limits?<\/p>\n<p>Three commitments run through everything below: transparency over marketing, disclosed limitations over vague promises, and no patient data. This is clinician and professional contactability data for legitimate recruiting outreach, not clinical or patient information.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Quick_answer\"><\/span>Quick answer<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<dl>\n<dt>Core answer<\/dt>\n<dd>Provider contact data holds up when identity sources (NPPES\/CMS NPI, state medical boards, FSMB) are kept separate from channel reach signals, then refreshed and suppressed on an ongoing basis.<\/dd>\n<dt>Key insight<\/dt>\n<dd>Identity sources confirm who a provider is. Reach sources tell you whether a recruiter can actually contact them today.<\/dd>\n<dt>Best for<\/dt>\n<dd>Buyers, compliance reviewers, and procurement teams evaluating vendor provenance.<\/dd>\n<\/dl>\n<blockquote>\n<p><strong>Compliance and safety<\/strong><\/p>\n<p>This method is for legitimate recruiting outreach only. Respect candidate privacy, opt-out requests, and local data laws. Heartbeat does not provide medical or legal advice.<\/p>\n<\/blockquote>\n<h2><span class=\"ez-toc-section\" id=\"Identity_is_not_reach_why_public_IDs_dont_equal_contactability\"><\/span>Identity is not reach: why public IDs don&#8217;t equal contactability<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A lot of procurement reviews go wrong because teams treat identity registries as if they were contact databases. They serve different jobs.<\/p>\n<ul>\n<li><strong>Identity<\/strong> answers: who is this provider, and can we uniquely identify them?<\/li>\n<li><strong>Reach<\/strong> answers: can we reliably contact them through a phone or email channel in a way that fits a recruiting workflow?<\/li>\n<\/ul>\n<p>NPPES and other public registries are strong identity anchors. The NPI registry itself is explicit that having a National Provider Identifier does not confirm that a provider is currently licensed or credentialed \u2014 the identifier is an administrative number, not a live directory. That distinction matters for procurement: identity sources aren&#8217;t built to maintain a working phone number or a currently-delivering email address, and treating them as if they were leads to wasted recruiter time.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"At_a_glance_identity_sources_vs_reach_sources\"><\/span>At a glance: identity sources vs. reach sources<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<div class=\"table-scroll\" style=\"overflow:auto;-webkit-overflow-scrolling:touch;width:100%\">\n<table class=\"separated-content\">\n<thead>\n<tr>\n<th>Category<\/th>\n<th>What it answers<\/th>\n<th>Examples<\/th>\n<th>What it does not guarantee<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Identity sources<\/td>\n<td>Unique identification and professional status<\/td>\n<td>NPPES; CMS NPI; state medical boards; FSMB<\/td>\n<td>A working direct line or a currently delivering email<\/td>\n<\/tr>\n<tr>\n<td>Reach sources<\/td>\n<td>Channel contactability for recruiting workflows<\/td>\n<td>Channel scoring, refresh, verification, suppression (Heartbeat.ai system)<\/td>\n<td>That every record is reachable, or reachable the same way<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2><span class=\"ez-toc-section\" id=\"Step-by-step_method\"><\/span>Step-by-step method<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This is the provenance workflow a serious vendor, Heartbeat.ai included, should be able to walk you through without hand-waving.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Step_1_Establish_identity_anchors\"><\/span>Step 1: Establish identity anchors<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>NPPES<\/strong>: the public registry behind the CMS NPI, maintained by CMS to assign unique identifiers to healthcare providers. It&#8217;s useful for stable identifiers, taxonomy codes, and baseline practice information, and CMS updates the query database daily.<\/li>\n<li><strong>State medical boards<\/strong>: authoritative for licensure status. Coverage, formats, and update schedules vary widely by state.<\/li>\n<li><strong>FSMB<\/strong>: supports cross-board identity context, useful for reconciling providers with multi-state licensure footprints.<\/li>\n<\/ul>\n<p>Identity sources are necessary but insufficient. They don&#8217;t guarantee you can reach the provider through a working channel.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Step_2_Normalize_and_resolve_identity\"><\/span>Step 2: Normalize and resolve identity<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>This is where messy data usually surfaces: name variants, multiple practice locations, shared clinic phone numbers.<\/p>\n<ul>\n<li>Normalize names, including suffixes and common variants.<\/li>\n<li>Use stable identifiers like NPI to reduce false merges.<\/li>\n<li>Track multiple locations as separate reach contexts \u2014 a hospital switchboard behaves nothing like a private practice front desk.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Step_3_Add_channel_reach_signals\"><\/span>Step 3: Add channel reach signals<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Channel data isn&#8217;t a single field. It&#8217;s a set of signals that need evaluation for recency, role (direct vs. office), and workflow fit.<\/p>\n<ul>\n<li><strong>Phone<\/strong>: could be a direct mobile, office line, call center, or switchboard. Each behaves differently in a recruiting context.<\/li>\n<li><strong>Email<\/strong>: could be personal, institutional, a group inbox, or simply outdated. Deliverability shifts as providers move roles.<\/li>\n<\/ul>\n<p>Channel reach should be treated as probabilistic, not binary. For speed-to-conversation workflows, prioritizing signals that reduce wasted dials \u2014 like ranked mobile numbers by answer probability \u2014 improves recruiter throughput more than raw list volume does.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"How_this_plays_out_in_practice\"><\/span>How this plays out in practice<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>Anchor identity first<\/strong> using NPPES\/CMS NPI and licensure context so records are auditable and deduped.<\/li>\n<li><strong>Keep identity fields separate from channel fields<\/strong> so nobody confuses &#8220;verified identity&#8221; with &#8220;reachable channel.&#8221;<\/li>\n<li><strong>Label channel types<\/strong> \u2014 direct vs. office vs. switchboard, institutional vs. personal email \u2014 so recruiters pick the right approach.<\/li>\n<li><strong>Refresh and suppress continuously<\/strong> so wrong-party numbers, opt-outs, and known-bad channels stop consuming recruiter time.<\/li>\n<li><strong>Report outcomes with shared definitions<\/strong> so procurement can compare pilots apples-to-apples.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Step_4_Apply_suppression_and_preference_handling\"><\/span>Step 4: Apply suppression and preference handling<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Provenance isn&#8217;t only about what&#8217;s included \u2014 it&#8217;s also what&#8217;s excluded.<\/p>\n<ul>\n<li>Honor opt-outs and internal do-not-contact lists.<\/li>\n<li>Suppress known-bad channels: hard bounces, disconnected numbers, confirmed wrong-party contacts.<\/li>\n<li>Respect role boundaries, such as office lines that explicitly decline recruiting calls.<\/li>\n<\/ul>\n<p>The trade-off: suppression shrinks raw list size, but it improves recruiter efficiency and lowers compliance risk. A smaller, cleaner list usually outperforms a larger, stale one.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Step_5_Refresh_cadence_and_decay_reality\"><\/span>Step 5: Refresh cadence and decay reality<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Static lists decay. The workable standard is access, refresh, verification, and suppression working together. If a vendor can&#8217;t explain how those four pieces interact, you&#8217;re not buying a system \u2014 you&#8217;re buying a snapshot that starts going stale the day you receive it.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Step_6_Limits_you_should_expect_in_writing\"><\/span>Step 6: Limits you should expect in writing<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>State-by-state variability<\/strong>: medical boards publish different fields on different schedules in different formats, which can create identity mismatches that surface as wrong-party confirmations.<\/li>\n<li><strong>Clinic-hour gating<\/strong>: office lines may only be reachable during narrow windows, and switchboards route unpredictably \u2014 this typically lowers Connect Rate (connected calls divided by total dials).<\/li>\n<li><strong>Institutional churn<\/strong>: institutional emails and group inboxes change as providers switch roles or systems update directories, which tends to lower Deliverability Rate and raise Bounce Rate.<\/li>\n<li><strong>Channel ambiguity<\/strong>: a number that&#8217;s &#8220;good&#8221; for one workflow can be wrong for another, which can drag down Answer Rate even when Connect Rate looks fine.<\/li>\n<\/ul>\n<p>For email deliverability monitoring practices referenced in pilots, Google Postmaster Tools is a common reference point for domain and IP reputation.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Diagnostic_table_for_procurement_review\"><\/span>Diagnostic table for procurement review<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Use this to separate identity provenance from reach provenance. It&#8217;s built to drop into an RFP response matrix.<\/p>\n<div class=\"table-scroll\" style=\"overflow:auto;-webkit-overflow-scrolling:touch;width:100%\">\n<table class=\"separated-content\">\n<thead>\n<tr>\n<th>Source type<\/th>\n<th>Examples<\/th>\n<th>Best for<\/th>\n<th>Typical limitations<\/th>\n<th>What to ask (procurement)<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Identity registry<\/td>\n<td>NPPES; CMS NPI<\/td>\n<td>Unique identification, taxonomy, baseline practice info<\/td>\n<td>Not designed for contactability; fields can be stale<\/td>\n<td>How do you handle multiple locations and name variants? How do you prevent false merges?<\/td>\n<\/tr>\n<tr>\n<td>Licensure authority<\/td>\n<td>State medical boards<\/td>\n<td>License status verification, state-by-state context<\/td>\n<td>Formats vary; update timing varies; some data isn&#8217;t standardized<\/td>\n<td>Which boards are integrated? How do you handle states with limited online detail?<\/td>\n<\/tr>\n<tr>\n<td>Federated licensure context<\/td>\n<td>FSMB<\/td>\n<td>Cross-state identity reconciliation support<\/td>\n<td>Not a direct channel source<\/td>\n<td>How is FSMB used in matching and exception handling?<\/td>\n<\/tr>\n<tr>\n<td>Channel reach system<\/td>\n<td>Heartbeat.ai (reach scoring + suppression)<\/td>\n<td>Operational reach for recruiter workflows<\/td>\n<td>Channels decay; wrong-party risk; compliance constraints<\/td>\n<td>How do you refresh? How do you suppress? What metrics do you report, and with what denominators?<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2><span class=\"ez-toc-section\" id=\"Weighted_checklist_for_scoring_vendors\"><\/span>Weighted checklist for scoring vendors<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>A 100-point rubric. Adjust weights to your own risk tolerance and workflow needs.<\/p>\n<ul>\n<li><strong>30 pts \u2014 Provenance clarity<\/strong>: can the vendor separate identity sources from channel sources and explain each in plain terms?<\/li>\n<li><strong>20 pts \u2014 Refresh and suppression system<\/strong>: is there an explicit access, refresh, verification, suppression process, and can they show how it runs?<\/li>\n<li><strong>15 pts \u2014 Metric definitions and reporting<\/strong>: do they report Connect Rate, Answer Rate, Deliverability Rate, Bounce Rate, and Reply Rate with denominators?<\/li>\n<li><strong>15 pts \u2014 Compliance controls<\/strong>: opt-out handling, do-not-contact suppression, audit logs, policy alignment.<\/li>\n<li><strong>10 pts \u2014 Workflow fit<\/strong>: can recruiters use it without standing up a data team?<\/li>\n<li><strong>10 pts \u2014 Limits disclosed<\/strong>: do they publish coverage gaps and known failure modes, or just make claims?<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"Outreach_templates\"><\/span>Outreach templates<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Designed to lower wrong-party and complaint risk. Keep opt-out handling simple and consistent with your policy.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Template_1_First-touch_email_identity-confirming\"><\/span>Template 1: First-touch email (identity-confirming)<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p><strong>Subject:<\/strong> Quick check \u2014 is this the best email for recruiting outreach?<\/p>\n<p>Hello Dr. [Last Name],<\/p>\n<p>I&#8217;m reaching out about a [specialty\/role] opportunity and want to confirm I have the right contact for you. If this isn&#8217;t the best email, could you reply with the preferred address (or tell me to stop contacting you)?<\/p>\n<p>Thanks,<\/p>\n<p>[Name], [Title]<\/p>\n<p>[Organization]<\/p>\n<p>[Phone]<\/p>\n<p>Reply &#8220;opt out&#8221; and I&#8217;ll remove you.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Template_2_Voicemail\"><\/span>Template 2: Voicemail<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Hi Dr. [Last Name], this is [Name] with [Org]. I&#8217;m calling about a [role] opportunity. If you&#8217;re open to a quick conversation, call me at [number]. If you prefer no recruiting calls, tell me and I&#8217;ll mark you do-not-contact. Thanks.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Template_3_Office_line_gatekeeper_script\"><\/span>Template 3: Office line gatekeeper script<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Hi \u2014 quick question. I&#8217;m trying to reach Dr. [Last Name] about a professional opportunity. Is there a better number or email for recruiting outreach, or should I send something to a general inbox?<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Common_pitfalls\"><\/span>Common pitfalls<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"Treating_NPI_as_a_contact_record\"><\/span>Treating NPI as a contact record<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>NPI is an identity anchor, not proof of reach. Teams that assume &#8220;NPI equals direct line&#8221; burn recruiter time and inflate dial volume without improving connects.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Not_labeling_channel_types\"><\/span>Not labeling channel types<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Without labeling direct mobile vs. office line vs. switchboard, recruiters can&#8217;t choose the right approach, and your metrics turn into noise.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"No_shared_metric_definitions\"><\/span>No shared metric definitions<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Require consistent definitions and denominators across vendors and internal reporting:<\/p>\n<ul>\n<li><strong>Connect Rate<\/strong> = connected calls \/ total dials<\/li>\n<li><strong>Answer Rate<\/strong> = human answers \/ connected calls<\/li>\n<li><strong>Deliverability Rate<\/strong> = delivered emails \/ sent emails<\/li>\n<li><strong>Bounce Rate<\/strong> = bounced emails \/ sent emails<\/li>\n<li><strong>Reply Rate<\/strong> = replies \/ delivered emails<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Provenance_without_limits\"><\/span>Provenance without limits<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Listing sources isn&#8217;t enough. You need written limitations and a repeatable test plan your team can rerun later.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"How_to_improve_results\"><\/span>How to improve results<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"Run_a_%E2%80%9Cshow_your_work%E2%80%9D_pilot\"><\/span>Run a &#8220;show your work&#8221; pilot<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>This forces clarity on scope, definitions, and limitations, and it makes vendor comparisons fair without relying on marketing claims.<\/p>\n<blockquote>\n<p><strong>Copy\/paste pilot report template (for procurement)<\/strong><\/p>\n<p><strong>Timestamp:<\/strong> [YYYY-MM-DD to YYYY-MM-DD]<\/p>\n<p><strong>Scope:<\/strong> Specialty [ ], States [ ], Setting [ ], Seniority [ ], Total records tested [ ]<\/p>\n<p><strong>Identity anchors used:<\/strong> [NPI] [license] [both]<\/p>\n<p><strong>Channel types tested:<\/strong> [direct mobile] [office line] [institutional email] [personal email]<\/p>\n<p><strong>Suppression applied:<\/strong> [opt-outs] [prior wrong-party] [hard bounces] [internal DNC]<\/p>\n<p><strong>Definitions (must match):<\/strong><\/p>\n<p>Connect Rate = connected calls \/ total dials<\/p>\n<p>Answer Rate = human answers \/ connected calls<\/p>\n<p>Deliverability Rate = delivered emails \/ sent emails<\/p>\n<p>Bounce Rate = bounced emails \/ sent emails<\/p>\n<p>Reply Rate = replies \/ delivered emails<\/p>\n<p><strong>Results:<\/strong><\/p>\n<p>Calls: total dials [ ], connected calls [ ], human answers [ ]<\/p>\n<p>Emails: sent [ ], delivered [ ], bounced [ ], replies [ ]<\/p>\n<p><strong>Limitations observed:<\/strong> [clinic-hour gating] [switchboard routing] [gatekeeper-heavy offices] [state-by-state variability]<\/p>\n<p><strong>Decision:<\/strong> [expand] [adjust scope] [reject] + why<\/p>\n<\/blockquote>\n<p>Run the same template across two time windows \u2014 week one vs. week three, for example \u2014 and compare decay and suppression impact using the same denominators.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Improve_reach_without_increasing_risk\"><\/span>Improve reach without increasing risk<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li><strong>Segment by workflow<\/strong>: urgent roles may justify more calling; longer-cycle roles may work better email-first.<\/li>\n<li><strong>Use suppression as a performance tool<\/strong>: removing wrong-party and opted-out contacts cuts wasted touches and complaints.<\/li>\n<li><strong>Route recruiters to the right channel<\/strong>: direct lines for speed, office lines for context, email for asynchronous confirmation.<\/li>\n<\/ul>\n<h3><span class=\"ez-toc-section\" id=\"Build_state-by-state_verification_into_the_workflow\"><\/span>Build state-by-state verification into the workflow<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>If compliance requires licensure confirmation, build it into the process rather than asking recruiters to improvise. Start here: <a href=\"http:\/\/heartbeat.ai\/resources\/state-license-lookups\/\">state license lookups<\/a>.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Legal_and_ethical_use\"><\/span>Legal and ethical use<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Not legal advice \u2014 a practical checklist for staying compliant while keeping recruiting moving.<\/p>\n<ul>\n<li>Use contact data for legitimate recruiting outreach only, with clear identification and an easy opt-out.<\/li>\n<li>Maintain and honor suppression lists: opt-outs, wrong-party, internal do-not-contact.<\/li>\n<li>Document your pilot methodology and keep audit trails for procurement and compliance review.<\/li>\n<li>Follow applicable calling and texting rules, including the TCPA in the U.S., and local privacy laws.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"Evidence_and_trust_notes\"><\/span>Evidence and trust notes<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>This page exists to reduce &#8220;where did you get this?&#8221; skepticism and make evaluation repeatable. For how metrics are defined and audited across the trust pack, see <a href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/\">Heartbeat trust methodology<\/a> and <a href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/accuracy-and-metrics-definitions\/\">accuracy and metrics definitions<\/a>.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Procurement_artifacts_to_request\"><\/span>Procurement artifacts to request<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<ul>\n<li>A source taxonomy separating identity sources (NPPES\/CMS NPI, state medical boards, FSMB) from reach sources.<\/li>\n<li>A data dictionary defining fields, allowed values, and which fields are identity vs. channel.<\/li>\n<li>A written refresh description: what triggers updates and how decay is handled.<\/li>\n<li>A written suppression policy covering opt-outs, wrong-party, bounces, and internal do-not-contact.<\/li>\n<li>A sample pilot report using shared metric definitions and denominators.<\/li>\n<\/ul>\n<p>External references worth keeping on file: <a href=\"https:\/\/developers.google.com\/search\/docs\/fundamentals\/creating-helpful-content\">Google&#8217;s guidance on helpful, people-first content<\/a>, <a href=\"https:\/\/postmaster.google.com\/\">Google Postmaster Tools<\/a> for email deliverability monitoring, and the <a href=\"https:\/\/www.fcc.gov\/general\/telephone-consumer-protection-act-1991-tcpa\">FCC&#8217;s TCPA overview<\/a>.<\/p>\n<p>For a workflow view of how teams turn sourcing inputs into recruiter execution, see <a href=\"http:\/\/heartbeat.ai\/resources\/recruiting-ops\/market-mapping-for-physician-recruiting\/\">market mapping for physician recruiting<\/a>.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"FAQs\"><\/span>FAQs<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h3><span class=\"ez-toc-section\" id=\"What_are_the_best_data_sources_for_provider_identity\"><\/span>What are the best data sources for provider identity?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Start with NPPES (CMS NPI) and validate licensure through state medical boards; FSMB can help with cross-state context. Identity sources work best as anchors for matching and deduping, not as standalone contact lists.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Why_cant_a_public_registry_guarantee_contactability\"><\/span>Why can&#8217;t a public registry guarantee contactability?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Registries exist to identify providers, not to maintain current, preferred recruiting channels. NPPES itself notes that an assigned NPI doesn&#8217;t confirm current licensure or credentialing status. Phone numbers can route to switchboards, and emails can stop delivering as providers change roles or institutions.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_metrics_should_we_require_in_a_pilot\"><\/span>What metrics should we require in a pilot?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>At minimum: Connect Rate, Answer Rate, Deliverability Rate, Bounce Rate, and Reply Rate, each with clear denominators \u2014 per 100 dials, per 100 delivered emails, and so on.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"How_do_we_evaluate_%E2%80%9Cfreshness%E2%80%9D_without_relying_on_vendor_promises\"><\/span>How do we evaluate &#8220;freshness&#8221; without relying on vendor promises?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>Run two identical pilot windows and compare outcomes using the same definitions and denominators. Track suppression growth \u2014 opt-outs, wrong-party, bounces \u2014 and whether performance holds when you re-test the same segment.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"What_documentation_should_a_vendor_provide_to_prove_provenance\"><\/span>What documentation should a vendor provide to prove provenance?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>At minimum: a source taxonomy (identity vs. reach), a data dictionary, a refresh description, a suppression policy, and a pilot report template with shared metric definitions and denominators. If a vendor can&#8217;t produce these, you can&#8217;t audit what you&#8217;re buying.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Does_Heartbeatai_use_patient_data\"><\/span>Does Heartbeat.ai use patient data?<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>No. Heartbeat.ai focuses on clinician and professional identity and contactability for legitimate recruiting outreach, with suppression and compliance controls built in.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Next_steps\"><\/span>Next steps<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<ul>\n<li>Align your team on definitions first: <a href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/accuracy-and-metrics-definitions\/\">metric definitions and accuracy notes<\/a>.<\/li>\n<li>Pressure-test matching quality: <a href=\"http:\/\/heartbeat.ai\/resources\/provider-contact-data\/npi-license-matching\/\">NPI and license matching<\/a>.<\/li>\n<li>Run a controlled pilot with procurement-ready reporting: <a href=\"https:\/\/heartbeat.ai\/signup\">create a Heartbeat account<\/a>.<\/li>\n<\/ul>\n<h2><span class=\"ez-toc-section\" id=\"About_the_Author\"><\/span><b>About the Author<\/b><span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><a href=\"http:\/\/heartbeat.ai\/resources\/author\/ben-argeband\"><span style=\"font-weight: 400;\">Ben Argeband<\/span><\/a><span style=\"font-weight: 400;\"> is the Founder and CEO of Swordfish.ai and Heartbeat.ai. With deep expertise in data and SaaS, he has built two successful platforms trusted by over 50,000 sales and recruitment professionals. Ben&#8217;s mission is to help teams find direct contact information for hard-to-reach professionals and decision-makers, providing the shortest route to their next win. Connect with Ben on <\/span><a href=\"https:\/\/www.linkedin.com\/in\/ben-m-argeband-2427a8a3\/\"><span style=\"font-weight: 400;\">LinkedIn<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><br \/>\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"Article\",\"author\":{\"@type\":\"Person\",\"jobTitle\":\"Founder & CEO of Heartbeat.ai\",\"name\":\"Ben Argeband\"},\"dateModified\":\"2026-01-05\",\"datePublished\":\"2026-01-05\",\"description\":\"A procurement-ready breakdown of identity vs. reach sources (NPPES\/CMS NPI, state medical boards, FSMB), plus limitations, metric definitions, procurement artifacts to request, and a copy\/paste pilot report template.\",\"headline\":\"Data sources for provider contact data (provenance, limits, and how to test)\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/\",\"@type\":\"WebPage\"},\"publisher\":{\"@type\":\"Organization\",\"name\":\"Heartbeat.ai\"}}<\/script><\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"For identity, start with NPPES (CMS NPI) and validate licensure through state medical boards; FSMB can help with cross-state context. Identity sources are strongest when used as anchors for matching and deduping.\"},\"name\":\"What are the best data sources for provider identity?\"},{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Registries are built to identify providers, not to maintain current, preferred recruiting channels. Phone numbers can route to switchboards, and emails can stop delivering as providers change roles or institutions.\"},\"name\":\"Why can't a public registry guarantee contactability?\"},{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"At minimum: Connect Rate (connected calls \/ total dials), Answer Rate (human answers \/ connected calls), Deliverability Rate (delivered emails \/ sent emails), Bounce Rate (bounced emails \/ sent emails), and Reply Rate (replies \/ delivered emails). Require denominators (per 100 dials, per 100 delivered emails, and so on).\"},\"name\":\"What metrics should we require in a pilot?\"},{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"Run two identical pilot windows and compare outcomes using the same definitions and denominators. Track suppression growth (opt-outs, wrong-party, bounces) and whether performance holds when you re-test the same segment.\"},\"name\":\"How do we evaluate \\\"freshness\\\" without relying on vendor promises?\"},{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"At minimum: a source taxonomy (identity vs reach), a data dictionary, a refresh description, a suppression policy, and a pilot report template with shared metric definitions and denominators. If they can't provide these, you can't audit what you're buying.\"},\"name\":\"What documentation should a vendor provide to prove provenance?\"},{\"@type\":\"Question\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No patient data. Heartbeat.ai focuses on clinician\/professional identity and contactability for legitimate recruiting outreach, with suppression and compliance controls.\"},\"name\":\"Does Heartbeat.ai use patient data?\"}]}<\/script><\/p>","protected":false},"excerpt":{"rendered":"<p>A procurement-ready breakdown of identity vs. reach sources for provider contact data, with limits, metrics, and a pilot report template.<\/p>","protected":false},"author":5,"featured_media":54161,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_custom_permalink":"trust-methodology\/data-sources-we-use","footnotes":""},"categories":[1],"tags":[],"class_list":["post-54162","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\r\n<title>Data sources for provider contact data: provenance, limits, and how to test<\/title>\r\n<meta name=\"description\" content=\"See which sources support provider identity (NPPES\/CMS NPI, state boards, FSMB) vs. contact channels, plus limitations, procurement artifacts, and a copy\/paste pilot template.\" \/>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/\" \/>\r\n<meta property=\"og:locale\" content=\"en_US\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"Data sources for provider contact data: provenance, limits, and how to test\" \/>\r\n<meta property=\"og:description\" content=\"See which sources support provider identity (NPPES\/CMS NPI, state boards, FSMB) vs. contact channels, plus limitations, procurement artifacts, and a copy\/paste pilot template.\" \/>\r\n<meta property=\"og:url\" content=\"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/\" \/>\r\n<meta property=\"og:site_name\" content=\"Heartbeat.ai\" \/>\r\n<meta property=\"article:published_time\" content=\"2026-02-01T18:25:53+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2026-08-29T12:04:40+00:00\" \/>\r\n<meta property=\"og:image\" content=\"https:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/data-sources-we-use-48f27894.png\" \/>\r\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\r\n\t<meta property=\"og:image:height\" content=\"1024\" \/>\r\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\r\n<meta name=\"author\" content=\"Ben Argeband\" \/>\r\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ben Argeband\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/#article\",\"isPartOf\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/\"},\"author\":{\"name\":\"Ben Argeband\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#\\\/schema\\\/person\\\/7b323ddce9b211907423482e2f9db173\"},\"headline\":\"Data sources for provider contact data (provenance, limits, and how to test)\",\"datePublished\":\"2026-02-01T18:25:53+00:00\",\"dateModified\":\"2026-08-29T12:04:40+00:00\",\"mainEntityOfPage\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/\"},\"wordCount\":2382,\"commentCount\":0,\"publisher\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#organization\"},\"image\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/data-sources-we-use-48f27894.png\",\"articleSection\":[\"News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/\",\"url\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/\",\"name\":\"Data sources for provider contact data: provenance, limits, and how to test\",\"isPartOf\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/#primaryimage\"},\"image\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/#primaryimage\"},\"thumbnailUrl\":\"http:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/data-sources-we-use-48f27894.png\",\"datePublished\":\"2026-02-01T18:25:53+00:00\",\"dateModified\":\"2026-08-29T12:04:40+00:00\",\"description\":\"See which sources support provider identity (NPPES\\\/CMS NPI, state boards, FSMB) vs. contact channels, plus limitations, procurement artifacts, and a copy\\\/paste pilot template.\",\"breadcrumb\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/#primaryimage\",\"url\":\"http:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/data-sources-we-use-48f27894.png\",\"contentUrl\":\"http:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/data-sources-we-use-48f27894.png\",\"width\":1024,\"height\":1024},{\"@type\":\"BreadcrumbList\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/trust-methodology\\\/data-sources-we-use\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data sources for provider contact data (provenance, limits, and how to test)\"}]},{\"@type\":\"WebSite\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#website\",\"url\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/\",\"name\":\"Heartbeat.ai\",\"description\":\"\",\"publisher\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#organization\",\"name\":\"Heartbeat.ai\",\"url\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/Heartbeat.ai-logo.png\",\"contentUrl\":\"https:\\\/\\\/hc.heartbeat.ai\\\/wp-content\\\/uploads\\\/2021\\\/04\\\/Heartbeat.ai-logo.png\",\"width\":704,\"height\":126,\"caption\":\"Heartbeat.ai\"},\"image\":{\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/#\\\/schema\\\/person\\\/7b323ddce9b211907423482e2f9db173\",\"name\":\"Ben Argeband\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g\",\"caption\":\"Ben Argeband\"},\"url\":\"http:\\\/\\\/heartbeat.ai\\\/resources\\\/author\\\/ben-argeband\\\/\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data sources for provider contact data: provenance, limits, and how to test","description":"See which sources support provider identity (NPPES\/CMS NPI, state boards, FSMB) vs. contact channels, plus limitations, procurement artifacts, and a copy\/paste pilot template.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/","og_locale":"en_US","og_type":"article","og_title":"Data sources for provider contact data: provenance, limits, and how to test","og_description":"See which sources support provider identity (NPPES\/CMS NPI, state boards, FSMB) vs. contact channels, plus limitations, procurement artifacts, and a copy\/paste pilot template.","og_url":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/","og_site_name":"Heartbeat.ai","article_published_time":"2026-02-01T18:25:53+00:00","article_modified_time":"2026-08-29T12:04:40+00:00","og_image":[{"width":1024,"height":1024,"url":"https:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/data-sources-we-use-48f27894.png","type":"image\/png"}],"author":"Ben Argeband","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ben Argeband","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#article","isPartOf":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/"},"author":{"name":"Ben Argeband","@id":"http:\/\/heartbeat.ai\/resources\/#\/schema\/person\/7b323ddce9b211907423482e2f9db173"},"headline":"Data sources for provider contact data (provenance, limits, and how to test)","datePublished":"2026-02-01T18:25:53+00:00","dateModified":"2026-08-29T12:04:40+00:00","mainEntityOfPage":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/"},"wordCount":2382,"commentCount":0,"publisher":{"@id":"http:\/\/heartbeat.ai\/resources\/#organization"},"image":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#primaryimage"},"thumbnailUrl":"http:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/data-sources-we-use-48f27894.png","articleSection":["News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#respond"]}]},{"@type":"WebPage","@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/","url":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/","name":"Data sources for provider contact data: provenance, limits, and how to test","isPartOf":{"@id":"http:\/\/heartbeat.ai\/resources\/#website"},"primaryImageOfPage":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#primaryimage"},"image":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#primaryimage"},"thumbnailUrl":"http:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/data-sources-we-use-48f27894.png","datePublished":"2026-02-01T18:25:53+00:00","dateModified":"2026-08-29T12:04:40+00:00","description":"See which sources support provider identity (NPPES\/CMS NPI, state boards, FSMB) vs. contact channels, plus limitations, procurement artifacts, and a copy\/paste pilot template.","breadcrumb":{"@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#primaryimage","url":"http:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/data-sources-we-use-48f27894.png","contentUrl":"http:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2026\/02\/data-sources-we-use-48f27894.png","width":1024,"height":1024},{"@type":"BreadcrumbList","@id":"http:\/\/heartbeat.ai\/resources\/trust-methodology\/data-sources-we-use\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"http:\/\/heartbeat.ai\/resources\/"},{"@type":"ListItem","position":2,"name":"Data sources for provider contact data (provenance, limits, and how to test)"}]},{"@type":"WebSite","@id":"http:\/\/heartbeat.ai\/resources\/#website","url":"http:\/\/heartbeat.ai\/resources\/","name":"Heartbeat.ai","description":"","publisher":{"@id":"http:\/\/heartbeat.ai\/resources\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"http:\/\/heartbeat.ai\/resources\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"http:\/\/heartbeat.ai\/resources\/#organization","name":"Heartbeat.ai","url":"http:\/\/heartbeat.ai\/resources\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"http:\/\/heartbeat.ai\/resources\/#\/schema\/logo\/image\/","url":"https:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2021\/04\/Heartbeat.ai-logo.png","contentUrl":"https:\/\/hc.heartbeat.ai\/wp-content\/uploads\/2021\/04\/Heartbeat.ai-logo.png","width":704,"height":126,"caption":"Heartbeat.ai"},"image":{"@id":"http:\/\/heartbeat.ai\/resources\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"http:\/\/heartbeat.ai\/resources\/#\/schema\/person\/7b323ddce9b211907423482e2f9db173","name":"Ben Argeband","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9cdd6acf262740ced0b6a1c76378e93640df32a98d2f4d29507f31fbce6817e7?s=96&d=mm&r=g","caption":"Ben Argeband"},"url":"http:\/\/heartbeat.ai\/resources\/author\/ben-argeband\/"}]}},"_links":{"self":[{"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/posts\/54162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/comments?post=54162"}],"version-history":[{"count":4,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/posts\/54162\/revisions"}],"predecessor-version":[{"id":65686,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/posts\/54162\/revisions\/65686"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/media\/54161"}],"wp:attachment":[{"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/media?parent=54162"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/categories?post=54162"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/heartbeat.ai\/resources\/wp-json\/wp\/v2\/tags?post=54162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}