Blogs | HealthlinkDimensions

HealthLink’s Delete Request File: Format and Security

Written by nlenyszyn | Aug 14, 2026, 2:00:32 PM

A look inside the file that carries clinician deletion requests to our customers: every column, both versions, and the protections around it.

We Said We'd Show Our Work

When we wrote about California’s Delete Act in July, we ended with an offer: ask us for the sample suppression file, and we’ll show our work. This post is that offer, kept in public. Below is exactly what the delete request file looks like, what each column means, what your team does with it, and how the data inside it is protected. Our first distribution cycle begins in September.

Quick recap for new readers: HealthLink is a registered data broker, and when a clinician exercises a verified deletion or opt-out right, through a state platform or directly with us, we remove the record from our database and notify the customers who licensed it. The file below is that notification, in a form your team can act on in minutes. The full background is in our guide to the Delete Act.

What the File Looks Like

The file is a comma-separated values (CSV) file with four columns, delivered on a regular cycle. There are two versions, and which one you receive depends on whether your company has executed our Data Protection Agreement (DPA).

Customers with a DPA receive the clear version:

record_ref

npi

email

first_listed

HLD-S-000114

1841207364

jsmith@exampleclinic.com

2026-09-10

HLD-S-000115

1710439828

 

2026-09-10

HLD-S-000116

 

k.osei@examplemed.net

2026-09-10

HLD-S-000117

1265883417

mchen.np@samplehealth.org

2026-10-22

HLD-S-000117

1265883417

m.chen@personalmail.example

2026-10-22

Customers without a Data Protection Agreement receive the same file with the email column hashed:

record_ref

npi

email_sha256

first_listed

HLD-S-000114

1841207364

17c5786c8829632c…7018092a5

2026-09-10

HLD-S-000115

1710439828

 

2026-09-10

HLD-S-000116

 

9ab90daf92f85dcf…3d7f81c0a

2026-09-10

HLD-S-000117

1265883417

40ba321bacfb1ced…9e3d7ec88

2026-10-22

HLD-S-000117

1265883417

e3c2973b41c24836…766a8407a

2026-10-22

All rows above are fabricated for illustration. No real clinician data appears in this post.

Notice the last two rows: when we hold more than one email address for the same clinician, the row repeats with the same reference ID and NPI, one row per address. Your matching should treat every row independently; suppressing the clinician once covers all of their rows.

Column by column: record_ref is a HealthLink-generated reference with no personal information in it, so your team and ours can discuss a specific row without ever exchanging identifiers. npi is the clinician’s National Provider Identifier, a publicly available identifier and the primary key for most HealthLink deliverables. email (or email_sha256) is the email address from our record, in the clear or as a hash depending on whether your company has an executed Data Protection Agreement. first_listed is the date the record first appeared in the file, so you can isolate what’s new each cycle.

What is a Hashed Email Address?

A hash is a one-way fingerprint of a piece of text. Run jsmith@exampleclinic.com through the standard SHA-256 function and it always produces the same 64-character string, beginning 17c5786c. The fingerprint cannot be reversed back into the address, but if you run your own email column through the same function, identical addresses produce identical fingerprints, and the matches reveal themselves. Your team never learns an address it didn’t already have; it only recognizes the ones it does. The file ships with the exact recipe (trim spaces, lowercase, SHA-256) and worked examples so your team can verify their process in minutes.

What Does My Team Do With the File?

Five things, and the first four are one-time setup. Match the file against your HealthLink-sourced data on whichever columns your files carry, NPI or email or both. Delete or permanently suppress the matches, and exclude them from any sale, sharing, or marketing use. Treat each file as complete: it supersedes the previous one, so a missed cycle heals itself on the next pull. Use first_listed to work only the new rows. And expect cycles with zero matches; the file covers our full customer base, so any single customer matching nothing in a given cycle is normal and means exactly what it looks like.

How the Data in the File is Protected?

The protections start inside the file. It carries no names, no phone numbers, no addresses, and no practice details, only the minimum match keys, and every value comes from HealthLink’s own records. Where no Data Protection Agreement is in place, the email column is hashed, unreadable by design. The NPI is a publicly available identifier maintained in a federal registry.

Delivery is handled through a secure document delivery platform rather than email attachments. Each recipient gets individually credentialed access through an expiring link, and every retrieval is logged: we know which organization accessed which file and when, and that record protects you as much as it protects us. If a link expires before your team gets to it, a fresh one is a request away.

Use is governed by contract. Every customer’s existing agreement with HealthLink makes the file confidential, and the Data Protection Agreement adds explicit deletion and use commitments on both sides. The file exists for one purpose: deletion and suppression. It is not a marketing asset, an enrichment source, or a dataset for any other use. Between the minimized contents, the credentialed delivery, and the purpose limitation, the file is designed so that the honoring of a privacy request never becomes a privacy risk of its own.

One File, Every State

The file includes verified deletion and opt-out requests from all states, not only California. A clinician’s residence can’t be reliably determined record by record, and in our view a privacy choice shouldn’t depend on a ZIP code. Processing the full file keeps your HealthLink-sourced data consistent everywhere you use it, and it is the same standard we apply to our own database.

If your company hasn’t executed the DPA yet, it takes about five minutes and moves you to the clear-text version of the file with automated feed access: Review and accept the DPA. Questions about the file or the process can go to your Client Success representative anytime.

Frequently Asked Questions

 

About HealthLink Dimensions

HealthLink Dimensions is the trusted HCP data partner for healthcare marketing agencies and the life sciences, hospital, health plan, and continuing medical education (CME) organizations they serve. Our four connected pillars, Profile, Enrich, Engage, and Pulse, deliver identity-resolved HCP data, clinically relevant audiences, monthly-verified activation, and closed-loop measurement. Every engagement is built on three commitments: Product Excellence, Superior Service, and Privacy & Compliance. Data to Insight. One Trusted Partner.