ENTERPRISE COMPLIANCE FRAMEWORK

No PHI moves until the obligations are clear.

Intelligent Radiology treats privacy, cybersecurity, clinical governance, and regulatory compliance as production requirements—not marketing labels. Every service and system must pass an evidence-based release gate before protected health information or production clinical workflows are enabled.

Important: this page does not self-certify legal compliance. A website cannot make an organization “100% compliant.” Our standard is stricter: 100% of the obligations that apply to a production use case must be mapped, assigned, evidenced, and closed—or formally documented as not applicable—before release.
MANDATORY AND CONDITIONAL OBLIGATIONS

The compliance scope changes with the data, the customer, the jurisdiction, and the clinical function.

The enterprise must determine its role for every workflow—covered entity, business associate, contractor, processor, service provider, software vendor, telemedicine entity, educational provider, or medical-device manufacturer—and apply the rules that attach to that role.

HIPAA / HITECH42 CFR Part 2California CMIACCPA / CPRACalOPPAFTC Health DataTeleradiologyFDA / QMSRGDPR / Cross-borderADA / Accessibility
FEDERAL HEALTH INFORMATION

HIPAA Privacy, Security & Breach Notification

When Intelligent Radiology is a covered entity or business associate, the Privacy, Security, Enforcement, and Breach Notification requirements apply to the protected health information in scope.

  • Minimum-necessary use and role-based access where applicable
  • Administrative, physical, and technical safeguards for ePHI
  • Formal risk analysis and risk management
  • Business Associate Agreements and subcontractor flow-down
  • Breach assessment, documentation, and notification
  • Six-year retention of required HIPAA compliance documentation
SENSITIVE SUD RECORDS

42 CFR Part 2

If the platform receives records from a federally assisted substance-use-disorder program, Part 2 requirements must be separately evaluated. The 2024 final rule is now in its compliance period as of February 16, 2026.

  • Part 2 consent and redisclosure controls
  • Restrictions on use in legal proceedings
  • Part 2 patient notice / NPP alignment where applicable
  • Breach requirements aligned with HITECH/HIPAA changes
CALIFORNIA

CMIA, CCPA/CPRA, CalOPPA & breach law

California medical-information and consumer-privacy rules can apply independently of HIPAA. HIPAA-regulated information exemptions do not automatically exempt every other data category or every business activity.

  • Confidentiality of Medical Information Act where applicable
  • CCPA/CPRA notices, rights, sensitive-PI controls, and opt-out obligations where applicable
  • Conspicuous website privacy policy under CalOPPA for covered commercial sites
  • California breach notices and Attorney General submission when thresholds are met
NON-HIPAA HEALTH DATA

FTC Act & Health Breach Notification Rule

Health data that falls outside HIPAA is not unregulated. Consumer health apps and personal-health-record products may fall under the FTC’s Health Breach Notification Rule and the FTC Act’s prohibitions on unfair or deceptive practices.

  • Accurate privacy/security representations
  • No undisclosed reuse or disclosure of health data
  • FTC/consumer/media breach notices where required
  • Clear, conspicuous privacy disclosures
CLINICAL & TELERADIOLOGY

Licensure, credentialing, privileging & final responsibility

Remote interpretation must be configured around state law, facility rules, Medicare Conditions of Participation where applicable, and the institution’s own medical-staff governance.

  • Radiologist licensure or recognized authority in the patient/facility state
  • Credentialing and privileging for the service being provided
  • Written telemedicine arrangements where required
  • Clear final-report responsibility and escalation
  • Quality review, complaints, adverse-event handling, and professional liability
AI & MEDICAL DEVICE

FDA regulatory assessment before diagnostic claims

Workflow automation and AI assistance must be evaluated for intended use. If a product is a medical device or finished-device software, FDA requirements apply. The FDA Quality Management System Regulation became effective February 2, 2026.

  • No unreviewed diagnostic-device claims
  • Intended-use and regulatory-classification review
  • QMSR / ISO 13485-aligned quality system when applicable
  • Verification, validation, change control, complaint handling, and postmarket obligations
INTERNATIONAL DATA

GDPR and cross-border processing where applicable

HIPAA is not a global privacy law. If GDPR or another jurisdiction’s privacy law applies, the enterprise must separately satisfy controller/processor duties, legal bases, rights, security, and international-transfer requirements.

  • Controller/processor role mapping and data-processing terms
  • Subprocessor authorization and due diligence
  • Standard Contractual Clauses or another lawful transfer mechanism when required
  • Data-subject rights, retention, security, and breach workflows
ACCESSIBILITY & CIVIL RIGHTS

Accessible digital health services

Public-facing healthcare services must be accessible to people with disabilities under applicable civil-rights laws. WCAG 2.1 AA is the enterprise technical target for web and mobile accessibility.

  • Keyboard, screen-reader, contrast, focus, labeling, captioning, and error accessibility
  • Accessible forms and authentication flows
  • Effective communication and reasonable modifications
  • Section 504 / HHS funding obligations where applicable
Current-rule note · September 17, 2026The current HIPAA Security Rule remains in force. HHS’s December 2024 / January 2025 cybersecurity changes are still a proposed rule, not final law. Intelligent Radiology nevertheless adopts stronger controls such as MFA, encryption, asset inventory, and regular control review as internal enterprise baselines; those controls are not represented here as already-finalized federal mandates.
IR ENTERPRISE SECURITY BASELINE

Security is enforced through architecture, identity, evidence, and operations.

The minimum enterprise baseline applies even when a particular regulation would permit a weaker implementation.

IDENTITY

MFA + least privilege

Role-based authorization, verified identity, strong session controls, immediate offboarding, and no shared clinical accounts.

ENCRYPTION

Data protected in transit and at rest

Modern transport security, encrypted storage, managed keys/secrets, and no credentials embedded in public code.

LOGGING

Auditability by design

Security-relevant access, administrative changes, PHI events, authentication, and critical workflow actions are logged and reviewable.

RISK

Formal risk analysis

All systems that create, receive, maintain, or transmit ePHI are included in documented risk analysis and remediation tracking.

RESILIENCE

Backup, recovery & downtime

Contingency planning, tested recovery, data integrity protections, service continuity, and defined downtime procedures.

SOFTWARE

Secure development lifecycle

Code review, dependency management, vulnerability remediation, environment separation, change control, testing, and production approvals.

VENDORS

Contract + security evidence

BAA/DPA/SCC as applicable, subprocessor controls, breach duties, data-return/deletion terms, and security due diligence before access.

WORKFORCE

Training + sanctions

Privacy/security training, role-specific clinical training, confidentiality commitments, incident reporting, and documented sanctions.

DATA

Minimize, retain, delete

Collect only what is needed, separate data classes, define retention schedules, and securely dispose of data when the lawful purpose ends.

PRIVACY BY DEFAULT

Personal information and health information require different handling rules.

The enterprise classifies information before deciding who may use it, where it may be stored, how long it may remain, and which privacy rights attach to it.

Patient / PHI workflows

  • No PHI in public marketing pages or demonstration environments
  • No direct patient uploads into unapproved staging or test systems
  • Minimum-necessary access and treatment-purpose exceptions handled correctly
  • Notice of Privacy Practices when Intelligent Radiology has a covered-entity duty to provide one
  • No advertising pixels or third-party trackers that can receive PHI from authenticated or health-data workflows

Personal / account information

  • Notice at collection and privacy policy where required
  • Purpose limitation and data minimization
  • Access, correction, deletion, opt-out, restriction, or appeal rights when the applicable law provides them
  • Separate handling for credentials, financial records, employment data, and sensitive personal information
  • Authenticated privacy-request workflow with identity verification
PRODUCTION RELEASE GATE

No clinical production release without evidence.

The following artifacts must exist and be current for the actual service being released. A control may be marked not applicable only with documented rationale.

DomainRequired evidenceRelease condition
Legal / role mappingCovered-entity / business-associate / contractor / processor / device role analysis; jurisdictions; service scopeApproved and current
HIPAA / privacyPolicies, NPP where applicable, minimum-necessary rules, individual-rights process, authorization/consent logicNo unresolved privacy gap
SecurityRisk analysis, remediation register, architecture, access controls, encryption, logging, vulnerability evidence, backupsResidual risk accepted by authorized owner
Contracts / vendorsBAA, DPA, SCC or equivalent; subprocessor inventory; security assessment; breach and deletion termsExecuted before regulated data access
ClinicalLicensure, credentialing, privileging, scope, final-report responsibility, escalation, QA, malpractice coverageVerified for facility and jurisdiction
AI / deviceIntended-use review, device determination, validation, human-oversight rules, change control, QMS evidence where applicableNo unsupported diagnostic claim
Incident / breachIncident-response plan, notification matrix, forensic preservation, regulator/customer contacts, tabletop exerciseTested and assigned
AccessibilityAutomated + manual accessibility testing, keyboard/screen-reader review, remediation logMaterial barriers resolved
Data lifecycleInventory, retention schedule, deletion/return workflow, backup retention, data residency and transfer controlsDocumented end-to-end
Training / workforcePrivacy, security, clinical and role-specific training; confidentiality; sanctions; offboarding processRequired workforce current
Privacy Policy / CalOPPA noticePublic policy for website and online-service personal information.
HIPAA Notice of Privacy PracticesRequired only when Intelligent Radiology has the covered-entity duty to provide it.
Notice at CollectionCalifornia notice at or before collection where CCPA/CPRA applies.
BAA + subcontractor BAA chainExecuted before a business associate or subcontractor creates, receives, maintains, or transmits ePHI.
Data Processing AgreementController/processor obligations, instructions, subprocessors, security, rights, and deletion.
Subprocessor registerCurrent list of vendors with data scope, location, contract status, and risk review.
Incident & breach response planHIPAA, FTC, California, customer, contractual, and international notification matrix.
Data retention & deletion policyLegal, clinical, contractual, backup, and secure-disposal schedules.
Security risk analysisAccurate, thorough, enterprise-wide assessment of risks to ePHI.
Accessibility evidenceWCAG 2.1 AA testing target, issue log, and effective-communication pathway.
BREACH & INCIDENT RESPONSE

Detection is only the beginning. Notification clocks matter.

HIPAA-regulated breach

An impermissible use or disclosure is presumed to be a breach unless the required risk assessment supports a low probability that PHI was compromised. Covered entities must meet individual, HHS, and media notice duties where applicable; business associates must notify the covered entity. The outer federal notification deadline for affected individuals is generally 60 days, but the rule also requires action without unreasonable delay.

California breach

California requires notice to affected residents when specified unencrypted personal information is acquired or reasonably believed acquired by an unauthorized person. If a single breach triggers notice to more than 500 California residents, a sample notice must be submitted to the California Attorney General.

FTC health-data breach

For non-HIPAA vendors of personal health records and related entities, the FTC Health Breach Notification Rule may require notice to consumers, the FTC, and in some cases the media.

Contractual escalation

Customer contracts, BAAs, DPAs, cyber-insurance terms, partner agreements, and international laws may impose shorter notice windows. The incident matrix must use the shortest applicable obligation.

OFFICIAL REGULATORY REFERENCES

Primary sources used for this framework.

Framework last reviewed against official sources: September 17, 2026. Laws, regulations, court orders, enforcement guidance, customer contracts, and state requirements can change; production legal review must use the current rule set for the actual deployment.