MD Signout exists so physicians, NPs and PAs can tell each other the truth about where they work. That only works if honesty carries zero risk — so anonymity isn't a policy here, it's built into the database. Your reports are stored with no link to your name. Every byte is encrypted. No hospital, group, recruiter or director can ever find out it was you.
links between your name and your reports in the database
encryption at rest, TLS 1.2+ in transit — bank-grade, always on
Type II certified infrastructure (Supabase + Netlify), ISO 27001, HIPAA-eligible
Reports are stored under a random token, not your account. The table that links tokens to people is locked away from the website entirely. Even our own site code cannot read it.
No hospital, medical group, or director can see who reviewed them, request the list, or pay for it. Claimed program pages can respond publicly to a review; they cannot learn who wrote it.
"Verified hospitalist (MD) · nights · works here now." That's the whole byline. No name, no photo, no employer unless you choose to name the group you worked with.
We use your NPI once to confirm you're a real clinician against the federal registry, then keep only a one-way hash. The number itself is not in our database.
Data is encrypted at rest (AES-256) and in transit (TLS). Every table has row-level security: the database itself refuses any query that isn't yours to make, regardless of what the website asks for.
Salary and shift-rate entries live in a separate table with no public access at all. They're used only to build aggregate pay ranges, never shown per person, never shared.
Most review sites store "who wrote this" right next to the review and promise not to show it. We separated the two so that showing it isn't possible by accident.
The bridge between the two lives in a restricted table that the website is not allowed to read. It exists for one reason: so you can edit or delete your own report, and so we can act on a court order. Every time an administrator opens that bridge, the lookup is written to a permanent audit log with the reason — and that log is something we would show you.
| Situation | What happens |
|---|---|
| A hospital asks who wrote a review | We decline. Reviews are opinions and firsthand facts by verified clinicians; we don't identify authors on request. |
| A hospital says a review is false | They can claim their page and post a public response, or flag the review. A physician moderator checks it against the Review Guidelines (no patient details, no naming individuals, firsthand only). Fixing a factual error does not reveal you. |
| A subpoena or court order arrives | We follow the law — and we tell you first if we're legally allowed to, so you can object. See our legal-process policy. |
| Someone wants to contact you | They send a connect request through your review. You see who they are; they see nothing about you unless you accept. |
| You want your review gone | Delete it from your Profile. It's removed, not hidden. |
| Recruiters | Not admitted. Personal-email signups are checked against the NPI registry; accounts without a real clinician behind them are removed. |
reports.author_token has no foreign key to members; the mapping table has no read policy. Only two server-side functions touch it: "get my own token" and "admin lookup with a logged reason."This page describes how the service is built and operated today. It's not a legal document; the Privacy Policy and Terms are. Last updated September 2026.