MD Signout

Anonymous. Encrypted. Physician-owned.

MD Signout exists so physicians, NPs and PAs can tell each other the truth about where they work. That only works if honesty carries zero risk — so anonymity isn't a policy here, it's built into the database. Your reports are stored with no link to your name. Every byte is encrypted. No hospital, group, recruiter or director can ever find out it was you.

0

links between your name and your reports in the database

AES-256

encryption at rest, TLS 1.2+ in transit — bank-grade, always on

SOC 2

Type II certified infrastructure (Supabase + Netlify), ISO 27001, HIPAA-eligible

1

Your name is never attached to a report

Reports are stored under a random token, not your account. The table that links tokens to people is locked away from the website entirely. Even our own site code cannot read it.

2

Hospitals get nothing

No hospital, medical group, or director can see who reviewed them, request the list, or pay for it. Claimed program pages can respond publicly to a review; they cannot learn who wrote it.

3

What readers see about you

"Verified hospitalist (MD) · nights · works here now." That's the whole byline. No name, no photo, no employer unless you choose to name the group you worked with.

4

Your NPI is hashed, not stored

We use your NPI once to confirm you're a real clinician against the federal registry, then keep only a one-way hash. The number itself is not in our database.

5

Encrypted, locked-down database

Data is encrypted at rest (AES-256) and in transit (TLS). Every table has row-level security: the database itself refuses any query that isn't yours to make, regardless of what the website asks for.

6

Pay data is private by default

Salary and shift-rate entries live in a separate table with no public access at all. They're used only to build aggregate pay ranges, never shown per person, never shared.

How anonymity actually works

Most review sites store "who wrote this" right next to the review and promise not to show it. We separated the two so that showing it isn't possible by accident.

Your accountName, email, credential, hashed NPI
members → id 8f2a…
→ ✂ →
Your reportsRatings, tip, facts — tagged only with a random token
reports → author 3c91… (no link to you)

The bridge between the two lives in a restricted table that the website is not allowed to read. It exists for one reason: so you can edit or delete your own report, and so we can act on a court order. Every time an administrator opens that bridge, the lookup is written to a permanent audit log with the reason — and that log is something we would show you.

What we will and won't do

SituationWhat happens
A hospital asks who wrote a reviewWe decline. Reviews are opinions and firsthand facts by verified clinicians; we don't identify authors on request.
A hospital says a review is falseThey can claim their page and post a public response, or flag the review. A physician moderator checks it against the Review Guidelines (no patient details, no naming individuals, firsthand only). Fixing a factual error does not reveal you.
A subpoena or court order arrivesWe follow the law — and we tell you first if we're legally allowed to, so you can object. See our legal-process policy.
Someone wants to contact youThey send a connect request through your review. You see who they are; they see nothing about you unless you accept.
You want your review goneDelete it from your Profile. It's removed, not hidden.
RecruitersNot admitted. Personal-email signups are checked against the NPI registry; accounts without a real clinician behind them are removed.

What we never do

The plumbing, for the technically curious

Founder's note. I'm a hospitalist. I built this because the best information about a job — the census, the nursing, whether consultants answer, what nights are really like — only ever moved by text message and word of mouth. That knowledge should belong to all of us, and nobody should have to risk their standing to share it. If you ever think we've fallen short on this page, email privacy@mdsignout.com and you'll get a real answer from me. — Alex

This page describes how the service is built and operated today. It's not a legal document; the Privacy Policy and Terms are. Last updated September 2026.