SECURITY

Protect access, data, systems, and clinical boundaries by design.

Intelligent Radiology treats security as an operational control system spanning identity, authorization, encryption, auditability, software development, vendors, resilience, incident response, and evidence-based release decisions.

ENTERPRISE SECURITY BASELINE

Security controls must be visible in architecture and evidence.

The baseline applies according to system sensitivity and deployment scope. A stronger internal control may be required even where a specific law permits discretion.

Identity and MFA

  • Use verified identity and approved MFA for privileged and clinical access.
  • Manage sessions, recovery, offboarding, and high-risk account changes.

Least privilege

  • Grant only the permissions required for the authorized role and task.
  • Review administrative, clinical, vendor, and service-account access regularly.

Encryption and secrets

  • Protect sensitive data in transit and at rest using approved mechanisms.
  • Keep credentials and secrets out of public code and rotate compromised material promptly.

Auditability

  • Record security-relevant access, authentication, administrative changes, protected-data events, and critical workflow actions.
  • Preserve logs so authorized reviewers can reconstruct material events.

Secure development

  • Use review, testing, dependency management, vulnerability remediation, change control, and environment separation.
  • Do not move staging assumptions into production without explicit release review.

Risk analysis

  • Identify systems that create, receive, maintain, or transmit regulated or sensitive information.
  • Track risk treatment, residual risk, accountable owners, and required evidence.

Resilience and recovery

  • Maintain controlled backups, recovery procedures, downtime plans, integrity checks, and continuity processes.
  • Test restoration and escalation rather than relying only on written plans.

Incident response

  • Assign owners, preserve evidence, contain the event, assess notification duties, and coordinate clinical and operational response.
  • Use the shortest applicable legal, contractual, or customer notification window.

Vendor security

  • Review vendors and subprocessors before they receive sensitive access.
  • Require appropriate security evidence, access boundaries, incident duties, and termination controls.

Clinical safety boundary

  • Security controls do not create clinical authority.
  • Production clinical workflows remain gated by credentialing, licensure, privileging, governance, and explicit human responsibility.
Production gate: Security readiness requires current evidence. An unresolved applicable security requirement blocks PHI-enabled or clinical production release until it is closed or formally documented as not applicable.