Skip to main content
Category: Regulatory Framework

National Provider Identifier (NPI)

Also known as: NPI, National Provider Identifier Standard, NPI number
Simply put

The National Provider Identifier (NPI) is a unique 10-digit identification number assigned to healthcare providers in the United States. It is used by health plans and other parties to identify providers in standard healthcare transactions, and active NPI records are searchable through a free public directory. Providers apply for an NPI through the government's enrollment system administered by CMS.

Formal definition

The NPI is a unique, intelligence-free numeric identifier consisting of 10 digits assigned to covered health care providers under HIPAA Administrative Simplification standards, administered by CMS. "Intelligence-free" means the number does not encode information about the provider (such as specialty or location). Providers apply for and manage NPI records through the National Plan and Provider Enumeration System (NPPES), and active records are publicly available via the NPI Registry public search. The NPI is intended for use by health plans and other entities to identify providers in standard electronic transactions. This entry addresses the NPI as an identifier standard only; it does not by itself establish an entity's status as a covered entity or business associate, and it is distinct from the Privacy, Security, and Breach Notification Rules. Readers should verify current application procedures, eligibility categories, and applicable requirements against current CMS guidance, as specific procedural and regulatory details may change over time.

Why it matters

The National Provider Identifier is a foundational element of HIPAA's Administrative Simplification standards, which aim to streamline and standardize electronic healthcare transactions. Before a single standard identifier existed, providers were identified using a patchwork of different numbers assigned by different health plans, which complicated claims processing, coordination, and data exchange. The NPI provides a single, consistent way for health plans and other entities to identify a healthcare provider across standard transactions, reducing ambiguity and administrative friction.

Who it's relevant to

Healthcare Providers
Individual and organizational healthcare providers apply for and manage their NPI records through NPPES. Providers should understand that their active NPI record is publicly searchable and should keep the information they submit accurate and current, verifying application and update procedures against current CMS guidance.
Health Plans and Payers
Health plans use the NPI to identify providers in standard electronic transactions such as claims. The identifier gives payers a consistent way to reference providers across systems, and the public NPI Registry can support verification of active records.
Compliance and Administrative Simplification Officers
Those responsible for HIPAA Administrative Simplification should treat the NPI as a standard identifier requirement distinct from the Privacy, Security, and Breach Notification Rules. Using an NPI does not establish covered entity or business associate status or satisfy those rules; those obligations are assessed separately and may be affected by state law or the HITECH Act.
Billing, Credentialing, and Revenue Cycle Staff
Staff who prepare claims, credential providers, or manage provider directories rely on accurate NPI data for correct provider identification in transactions. They can use the free NPI Registry to confirm active NPI records, while confirming current procedural requirements against current CMS and NPPES guidance.

Inside NPI

Unique Identifier
The NPI is a single, unique identification number assigned to healthcare providers for use in standard transactions. It is intended to identify the provider consistently across the healthcare system.
Standard Transaction Use
The NPI is used in the standard electronic transactions governed by the HIPAA Administrative Simplification provisions, such as claims, eligibility inquiries, and remittance advice.
Provider Scope
NPIs generally apply to healthcare providers, which may include both individuals (such as physicians and nurses) and organizations (such as hospitals and group practices), depending on the entity type. Readers should verify current enumeration criteria against applicable regulatory guidance.
Non-Intelligent Numbering
The NPI is typically designed as a non-intelligent identifier, meaning the number itself does not encode information about the provider such as specialty or location.
Administrative Simplification Context
The NPI arises from the HIPAA Administrative Simplification framework, which addresses standardized identifiers and transactions, and is administered under authority delegated within HHS. Specific administering entities and requirements should be confirmed against current regulation.

Common questions

Answers to the questions practitioners most commonly ask about NPI.

Does having an NPI mean a provider is HIPAA compliant?
No. The NPI is a standard identifier used in HIPAA standard electronic transactions, but obtaining and using one does not by itself establish compliance with the Privacy Rule, the Security Rule, or any other HIPAA requirement. NPI use addresses the identification standards tied to HIPAA's administrative simplification provisions, not the broader safeguard, notice, and administrative obligations that apply to covered entities and business associates. Compliance depends on meeting each applicable rule, which readers should assess independently.
Is the NPI a confidential or protected identifier that must be safeguarded like PHI?
Generally, the NPI is intended to be a public identifier used to route and identify providers in standard transactions rather than a secret or sensitive data element on its own. It is not treated the same way as protected health information simply by virtue of being an identifier. However, when an NPI appears alongside other data in a way that relates to an individual's health information, the surrounding record may still be PHI subject to the Privacy and Security Rules. Readers should evaluate the full context of the data rather than the NPI in isolation.
Who is required to obtain and use an NPI?
In general terms, health care providers who are HIPAA covered entities, and typically those who transmit health information electronically in connection with standard transactions, are expected to obtain and use an NPI. Requirements can extend to certain providers under specific programs and payer rules. Because eligibility and mandatory-use scenarios can vary, readers should confirm applicability against the current regulatory text and any relevant payer or program guidance.
How should an NPI be used within HIPAA standard transactions?
The NPI is generally used to identify the relevant provider or organization in HIPAA standard electronic transactions, such as claims and related exchanges. Proper use typically involves placing the correct NPI in the appropriate data fields as defined by the applicable transaction standards. Because transaction formatting requirements and field-level expectations are governed by the relevant standards and payer instructions, readers should verify specific usage against current transaction implementation guides.
What is the difference between a Type 1 and Type 2 NPI, and which should be requested?
In general, NPIs are issued in two categories: one associated with individual providers and one associated with organizational providers. Which type is appropriate depends on whether the enumeration is for an individual practitioner or an organization, and some entities may need both depending on how they bill and organize their practice. Readers should confirm the correct type and any subpart considerations against current enumeration guidance before applying.
What should an organization do if provider information tied to an NPI changes?
As a general practice, organizations should keep the information associated with their NPIs current, updating relevant details when changes occur to the provider or organization. Maintaining accurate NPI records helps support correct identification in standard transactions and interactions with payers. Because update procedures, timeframes, and required data elements are set by the applicable enumeration process, readers should follow the current official update instructions rather than relying on assumptions.

Common misconceptions

The NPI is a privacy or security safeguard that protects health information.
The NPI is a standardized identifier used primarily in administrative and transaction standardization, not a safeguard under the HIPAA Security Rule. Protection of ePHI is governed separately by the Security Rule's administrative, physical, and technical safeguards, and protection of PHI in all forms by the Privacy Rule.
Every vendor or entity that handles healthcare data must obtain and use an NPI.
The NPI generally applies to healthcare providers in the context of standard transactions. It does not by itself define the covered entity or business associate relationships through which HIPAA obligations attach, and not all entities touching data are providers requiring an NPI. Verify applicability against current regulatory text.
Holding an NPI demonstrates HIPAA compliance.
An NPI is an identifier for transaction standardization and does not by itself establish compliance with the Privacy Rule, Security Rule, or Breach Notification Rule. Compliance is determined by meeting the applicable requirements of those rules, which HHS OCR enforces.

Best practices

Use the NPI in the standard electronic transactions where it is required, and confirm current transaction and enumeration requirements against the applicable regulatory text.
Treat the NPI as a non-intelligent identifier and avoid assuming it encodes specialty, location, or other provider attributes.
Verify the correct entity type (individual versus organizational provider) when obtaining or using an NPI, consulting current enumeration criteria.
Do not rely on possession of an NPI as evidence of HIPAA compliance; maintain separate documented compliance with the Privacy, Security, and Breach Notification Rules.
Keep NPI-related administrative processes distinct from your Security Rule safeguards, which separately govern the protection of ePHI.
Confirm any specific administering authority, applicability details, or current requirements against the current regulation and, where relevant, note that state law or HITECH provisions may impose additional requirements.