Gigasheet uses a combination of encryption and technical safeguards to protect our customers’ data. Our information security program includes measures such as:
Our privacy obligations and the protection of your information is not taken lightly, and we comply with all applicable privacy laws and regulations.
Gigasheet does not share nonpublic information with any other companies or individuals except in cases where you ask us to do so, or in cases where we are legally required to do so. Our Privacy Policy explicitly details these situations, as well as information we may collect about you, and how we will use that information. Our policy aims to protect all parties that interact with our service.
Gigasheet employs a robust encryption and security framework to ensure the confidentiality, integrity, and availability of user data. We are proud to be SOC 2 Type 2 compliant, an attestation that demonstrates our commitment to industry leading standards of security practices and controls. This compliance is verified by an independent third-party auditor, ensuring that our security measures meet stringent criteria and are rigorously evaluated and tested over time.
Gigasheet encrypts customer information at rest in our databases with industry standard 256-bit AES encryption, data is encrypted in transit with HTTPS over SSL/TLS, and passwords are encrypted with salted hashes.
While we meet many of the GDPR standards, Gigasheet is not yet fully GDPR compliant. We are a fast growing company and are working to become fully GDPR compliant in the future.
Beyond user financial information required for billing purposes, and user emails and passwords to allow access to the service, Gigasheet stores the following user data:
All data can be deleted upon user request. Moreover, as stated above, Gigasheet has infrastructure in place to ensure that this data cannot be accessed by any unauthorized party. We do not sell or share user data with any other companies or individuals except in cases where you ask us to do so, or in cases where we are legally required to do so. Our Privacy Policy explicitly details these situations.
As detailed in the Gigasheet Privacy Policy, Gigasheet does not share any personal data or logged information with any other company, organization, or individuals except as required in the following situations:
Plus, any request that is received is extensively reviewed to ensure compliance with all applicable laws, and it is Gigasheet’s policy to respond as narrowly as possible to best protect our customers’ privacy.
Yes, Gigasheet provides single sign-on (SSO) support from the following providers:
Our Enterprise edition also supports custom SSO. Contact us for more details.
Yes! Please email us here for our Pentest Rules of Engagement. We respond to all inquiries within 3 business days or less.
Email us here. We respond to all inquiries within 3 business days or less.
We make money from Premium and Enterprise customers who choose to upgrade and unlock the full potential of Gigasheet. You can learn more about our pricing and plans here. We do not sell or share user data with any other companies or individuals except in cases where you ask us to do so, or in cases where we are legally required to do so. Our Privacy Policy explicitly details these situations.
Gigasheet is currently SOC 2 (System and Organization Controls 2) Type 2 compliant and under continuous monitoring. Gigasheet utilizes enterprise-grade best practices to protect our customers’ data, and works with independent experts to verify its security, privacy, and compliance controls, and has achieved SOC 2 Type 2 report against stringent standards. We work with an independent auditor to maintain a SOC 2 report, which objectively certifies our controls to ensure the continuous security of our customers' data.
About the information we display
Gigasheet makes publicly available healthcare information easier to find, understand, and analyze. We may combine information from public source files with benchmarks and market comparisons calculated by Gigasheet.
Depending on the page, the information may include:
Provider information from NPPES
The National Plan and Provider Enumeration System, or NPPES, is maintained by the Centers for Medicare & Medicaid Services. It contains information associated with National Provider Identifiers, including provider names, practice locations, taxonomy codes, and other professional information.
CMS makes FOIA-disclosable NPPES information publicly available through the NPI Registry and downloadable data files. CMS states that this information is reported by the provider, someone acting on the provider’s behalf, or an authorized official.
Payer pricing from Transparency in Coverage files
Federal Transparency in Coverage rules require applicable health plans and health insurance issuers to publish machine-readable files containing in-network rates and certain out-of-network pricing information. These files must be publicly accessible to any person, free of charge and without conditions such as registration or submission of personal information.
Hospital pricing from Hospital Price Transparency files
Federal Hospital Price Transparency requirements generally require hospitals to publish a comprehensive machine-readable file containing standard charges for their items and services, including payer-specific negotiated charges and discounted cash prices.
Analytics calculated by Gigasheet
Gigasheet normalizes and organizes the published source data and may enrich it with provider, geographic, reimbursement, and other healthcare information. Gigasheet also calculates benchmarks, market comparisons, and other analytical results using the published data.
Gigasheet does not create the underlying NPPES, payer, or hospital source records. Providers generally do not submit these records directly to Gigasheet.
Important limitations
Healthcare source data can be incomplete, outdated, incorrectly reported, or difficult to interpret. The presence of a provider’s name, NPI, or other identifier in a payer file does not necessarily establish that the provider:
Displayed rates are not patient-specific estimates and may not reflect deductibles, coinsurance, copayments, benefit limitations, medical-necessity requirements, or the amount a patient will ultimately owe.
Benchmarks and market-position labels are statistical comparisons of published rates. They are not assessments of a provider’s credentials, clinical quality, patient outcomes, professional performance, or value of care.
Gigasheet does not verify professional licensing or credentials, endorse any provider or payer, or make decisions concerning eligibility, employment, credit, insurance, or access to healthcare.
Request a review
You may request that Gigasheet review information displayed on a provider page. Please provide:
Requests may involve inaccurate or outdated information, incorrect provider attribution, residential addresses, personal telephone numbers, safety concerns, or other privacy concerns.
We may request reasonable verification that you are the provider or are authorized to act on the provider’s behalf. Request a review here.
How we handle requests
Gigasheet will review the original public source data and its processing of that data. Depending on the circumstances, we may correct, annotate, or suppress information, or direct the requester to update the underlying source record.
The applicable federal public-access requirements do not condition access to the source data on obtaining separate consent from each provider. Accordingly, subject to applicable law, lack of provider consent alone is generally not a basis for removing accurate professional or pricing information derived from these public sources.
However, Gigasheet will review requests involving personal contact information, safety concerns, inaccurate or outdated information, incorrect attribution, or other circumstances that may warrant correction or suppression.
Correcting an NPPES record
If a provider name, address, taxonomy, telephone number, or other NPPES field is incorrect, the underlying record should also be updated through the NPPES portal. CMS directs providers or their authorized representatives to correct inaccurate NPPES information directly.
Once CMS publishes an updated record, Gigasheet will incorporate the revised information through its normal data-refresh process.
A correction or suppression made by Gigasheet will not alter information contained in NPPES, a payer’s machine-readable file, a hospital’s machine-readable file, or other services using those sources.



