PRIVACY

Privacy should be easy to understand.

We separate public information, account and professional information, and clinical information so each can be handled for the right purpose, by the right people, in the right workflow.

PURPOSE-LIMITED USEROLE-BASED ACCESSPHI STAYS IN CLINICAL WORKFLOWSRETENTION & DELETION RULES

START WITH THE DATA

Not all information is the same.

Privacy becomes easier to manage when the information is classified before it is used.

PUBLIC / BUSINESS

Website and inquiry information

Ordinary website, marketing, and business-inquiry information belongs in public or business workflows—not in clinical workflows.

  • Business contact details
  • Organization and role
  • General service questions
  • No patient-specific PHI in public inquiry forms
ACCOUNT / PROFESSIONAL

User and professional information

Account, credentialing, professional, training, and operational information is handled according to the user's role and the purpose for which it is needed.

  • Identity and account information
  • Professional role information
  • Credentialing or qualification data where applicable
  • Operational activity relevant to the service
CLINICAL / PHI

Patient and imaging information

Patient information and DICOM imaging belong in approved clinical workflows with access limited to authorized users and purposes.

  • PHI stays out of public marketing workflows
  • DICOM imaging is maintained in AWS-hosted controlled storage
  • Radiologist users receive view-only DICOM access
  • Radiologist DICOM download/local export is disabled

CLINICAL PRIVACY MODEL

Keep clinical information inside the clinical workflow.

The radiologist should receive the information needed to do the assigned work without turning that access into unrestricted possession of the underlying DICOM file.

01

Classify

Identify the information as clinical, account, business, or another data class before use.

02

Authorize

Determine the purpose, role, and scope that justify access.

03

Use minimally

Give the user only the access needed for the approved task.

04

Retain or delete

Apply the approved legal, clinical, contractual, and operational lifecycle.

PRIVACY PRINCIPLES

Use what is needed. Protect what is sensitive. Keep the purpose clear.

PURPOSE

Use data for an authorized purpose

Information should be used for the clinical, operational, educational, contractual, or business purpose that authorized its collection or access.

MINIMUM NECESSARY

Limit access and reuse

Access should be scoped to the people, roles, systems, and tasks that require the information.

SEPARATION

Keep workflows distinct

Public, educational, testing, administrative, and clinical workflows should not be casually mixed.

VENDORS

Govern subprocessors

Contracts and security review should define permitted use, access, breach duties, return, and deletion when required.

RETENTION

Keep data only as long as needed

Retention and deletion should follow the approved legal, clinical, contractual, backup, and operational rules for the deployment.

INCIDENTS

Escalate suspected misuse

Suspected unauthorized access, use, or disclosure should be investigated, documented, and handled under the applicable incident and notification process.

YOUR PRIVACY QUESTIONS

What can you expect?

For customers and users

We aim to make the data path understandable: what information is collected, why it is needed, who is allowed to use it, and how long it remains.

Clear data purpose
Role-based access
Vendor and subprocessor governance where required
Retention and deletion rules

Privacy rights depend on the law and role

Access, correction, deletion, restriction, opt-out, appeal, or other rights vary by data type, jurisdiction, and the organization's legal role. Requests are handled through the applicable verified process.

Identity verification where required
Applicable-law review
Documented response workflow
Clinical-record duties remain separate where applicable

Need the detailed privacy framework?

The prior Privacy page is preserved as a standalone reference with the fuller data-lifecycle baseline, staging boundaries, vendor controls, tracking and secondary-use rules, retention, and incident-response detail.

This page is a plain-language privacy summary, not a certification, legal opinion, or substitute for deployment-specific analysis. The applicable privacy duties depend on the data, customer, jurisdiction, contractual role, clinical function, and technical configuration.