Study arrives
The DICOM study enters the approved Intelligent Radiology workflow.
COMPLIANCE · PRIVACY · SECURITY
We design the workflow around a simple principle: keep patient imaging protected, give the radiologist only the access needed to interpret it, and make every important action controlled and reviewable.
WHERE THE DICOM FILE LIVES
Radiologists review the study through the authorized viewer. They do not need to take possession of the DICOM file to interpret it.
The clinical viewer is designed to present the study from AWS-hosted DICOM storage while keeping the underlying DICOM object in controlled cloud storage.
THE WORKFLOW
The easiest way to understand the security model is to follow the image.
The DICOM study enters the approved Intelligent Radiology workflow.
The DICOM file is maintained in AWS-hosted controlled storage.
An authorized radiologist receives view-only access through the clinical viewer.
The interpretation can move through the workflow without downloading the DICOM to the radiologist's device.
COMPLIANCE IN PLAIN LANGUAGE
Our public compliance summary focuses on the practical questions customers and radiologists usually ask first.
Access is role-based and limited to authorized users and approved workflow scope.
DICOM imaging is maintained in AWS-hosted controlled storage for the radiology workflow.
No. DICOM download and local DICOM export are disabled for radiologist users in the clinical viewer.
Patient information is handled through controlled clinical workflows rather than public marketing or ordinary communication channels.
Security-relevant access and workflow events are designed to be logged and reviewable.
No. Legal, contractual, licensing, privacy, security, and clinical requirements are evaluated for the actual deployment.
AROUND THE VIEW-ONLY MODEL
The storage model is one control. Identity, access, encryption, auditability, and operations remain essential around it.
Strong authentication and role-based authorization for protected workflows.
Users receive the access required for their role, not unrestricted data access.
Clinical data is protected through encrypted storage and secure transport controls.
Security-relevant access and critical workflow events are designed to be auditable.
PHI is kept out of public marketing, ordinary inquiry, and demonstration pathways.
Clinical authority, credentialing, licensing, and scope are deployment-specific requirements.
BAAs, DPAs, security review, and other terms are applied when required by the deployment.
Production clinical use requires the applicable privacy, security, contractual, and clinical controls to be addressed.
The previous compliance framework has been preserved as a standalone reference for regulatory detail, release-gate logic, and official-source links.
This page explains the operating model in plain language. It is not a certification, guarantee of regulatory status, or legal advice. Actual compliance depends on the customer, data, jurisdiction, contracts, clinical use, technical configuration, and evidence supporting the deployed workflow.