VISFO HCP identity resolution

Resolving clinician identity from limited input data.

This workspace sets out what can and cannot be established about a set of healthcare professionals when the only inputs are a first name, a surname, a country and the fact that the individual practises medicine. Where the evidence supports one person, the record is resolved. Where several clinicians share a name in the same region, the record is marked unresolved rather than assigned a best guess.

The candidate records, evidence, scores and identifier requirements are personal data. They are not published here, and are available to named accounts after sign in, subject to the role assigned to that account.

3 fields

Inputs used

First name, surname and country, plus the statement that the person practises medicine.

5

Evidence classes

Regulatory, scholarly, institutional, directory and social, each weighted separately.

Deterministic

Scoring

The same inputs produce the same score, and every score cites the sources behind it.

Per decision

Audit trail

Every confirmation, rejection and identifier tick is stored with the account that made it.

All candidate data, methodology detail and governance documentation sit behind authentication. Accounts are created by an administrator.

What the workspace contains

A provided list of clinician names with the candidate records matched to each one, the evidence behind every match, a confidence score, and the identifiers still required before enrichment can proceed.

How matches are assessed

Evidence is grouped into regulatory, scholarly, institutional, directory and social classes, weighted, and reduced where several people share a name in the same region. Scores are deterministic and reproducible.

Where certainty stops

A first name, surname and country cannot identify a person uniquely. Where a name returns several plausible clinicians, the record is marked unresolved rather than assigned a best guess.

What unlocks further work

Confirmed identity plus identifiers such as NPI, ORCID, institutional email or registration number. Publication disambiguation, co-author network analysis, geolocation resolution and registry matching follow from those inputs.

Privacy and security

This page is maintained by VISFO to answer common privacy and security questions about the workspace. It describes the controls in place today and is not an independent certification of them.

What is collected
Names and countries supplied by the client, plus attributes drawn from open sources: registry entries, publication records, institutional pages, professional directories and public professional profiles. No special category health data about the clinicians is collected, and no patient data is processed at any point.
What stays private
Candidate records, evidence trails, confidence scores, identifier checklists, resolution decisions and exports are never published on this site and are not indexed. This public page carries no candidate data of any kind. Client supplied lists are treated as confidential to the engagement.
Access controls behind login
Accounts are created by an administrator, not by public sign-up. Access is role based: viewers can read candidate records, admins and super admins can also record decisions and export data, and a signed-in account with no assigned role sees no candidate data at all. The same rules are enforced in the database with row level security, so they cannot be bypassed from the browser.
Governance and retention
Processing is documented against UK and EU GDPR with lawful basis recorded per source, HIPAA scope is controlled, and every decision is attributable to a named account. Data is held for the duration of the engagement and deleted or returned on request. The application is hosted on Google Cloud Platform and operated under its published certifications.