COMPLIANCE · PRIVACY · SECURITY

Compliance should be easy to understand.

We design the workflow around a simple principle: keep patient imaging protected, give the radiologist only the access needed to interpret it, and make every important action controlled and reviewable.

AWS-HOSTED DICOMVIEW-ONLY RADIOLOGIST ACCESSNO RADIOLOGIST DICOM DOWNLOADROLE-BASED ACCESS

WHERE THE DICOM FILE LIVES

The DICOM file stays in AWS-controlled storage.

Radiologists review the study through the authorized viewer. They do not need to take possession of the DICOM file to interpret it.

AWSDICOM STORAGE
🔒

Keep the image in the vault.

The clinical viewer is designed to present the study from AWS-hosted DICOM storage while keeping the underlying DICOM object in controlled cloud storage.

DICOM remains in AWS storage
Radiologist gets view access
DICOM download is disabled for radiologist users
No local DICOM export from the radiologist viewer
View the study. Interpret the study. Do not download the DICOM. The radiologist works in the controlled viewer; the DICOM file remains in AWS-hosted storage rather than being copied to the radiologist's local device.

THE WORKFLOW

Four steps. One protected imaging path.

The easiest way to understand the security model is to follow the image.

01

Study arrives

The DICOM study enters the approved Intelligent Radiology workflow.

02

Stored in AWS

The DICOM file is maintained in AWS-hosted controlled storage.

03

Radiologist views

An authorized radiologist receives view-only access through the clinical viewer.

04

Report returns

The interpretation can move through the workflow without downloading the DICOM to the radiologist's device.

RADIOLOGIST ACCESS

What the radiologist can do — and what the radiologist cannot do.

Can

Open an authorized study in the viewer
Use approved viewing and interpretation tools
Review the imaging needed for the assigned clinical work
Create or complete the interpretation workflow

Cannot

×Download the DICOM file from the radiologist viewer
×Export the underlying DICOM object to a local device
×Use the radiologist workflow to create a local DICOM archive
×Turn view access into unrestricted file possession

COMPLIANCE IN PLAIN LANGUAGE

The controls around the file matter as much as where the file is stored.

Our public compliance summary focuses on the practical questions customers and radiologists usually ask first.

ACCESS

Who can see it?

Access is role-based and limited to authorized users and approved workflow scope.

STORAGE

Where does it live?

DICOM imaging is maintained in AWS-hosted controlled storage for the radiology workflow.

DOWNLOAD

Can the radiologist take the file?

No. DICOM download and local DICOM export are disabled for radiologist users in the clinical viewer.

PRIVACY

How is patient information handled?

Patient information is handled through controlled clinical workflows rather than public marketing or ordinary communication channels.

AUDITABILITY

Can important actions be reviewed?

Security-relevant access and workflow events are designed to be logged and reviewable.

GOVERNANCE

Does one rule cover every use case?

No. Legal, contractual, licensing, privacy, security, and clinical requirements are evaluated for the actual deployment.

AROUND THE VIEW-ONLY MODEL

Security is layered around the workflow.

The storage model is one control. Identity, access, encryption, auditability, and operations remain essential around it.

IDENTITY

Verified access

Strong authentication and role-based authorization for protected workflows.

LEAST PRIVILEGE

Only what is needed

Users receive the access required for their role, not unrestricted data access.

ENCRYPTION

Protected storage and transport

Clinical data is protected through encrypted storage and secure transport controls.

LOGGING

Reviewable activity

Security-relevant access and critical workflow events are designed to be auditable.

PRIVACY

Clinical data stays clinical

PHI is kept out of public marketing, ordinary inquiry, and demonstration pathways.

CLINICAL

Qualified radiologists

Clinical authority, credentialing, licensing, and scope are deployment-specific requirements.

VENDORS

Contracted safeguards

BAAs, DPAs, security review, and other terms are applied when required by the deployment.

RELEASE

No unresolved critical gaps

Production clinical use requires the applicable privacy, security, contractual, and clinical controls to be addressed.

Need the detailed framework?

The previous compliance framework has been preserved as a standalone reference for regulatory detail, release-gate logic, and official-source links.

This page explains the operating model in plain language. It is not a certification, guarantee of regulatory status, or legal advice. Actual compliance depends on the customer, data, jurisdiction, contracts, clinical use, technical configuration, and evidence supporting the deployed workflow.