MFA and verified users
Approved authentication is used for privileged and clinical access according to the deployed workflow.
SECURITY
Keep the imaging in controlled AWS-hosted storage, give authorized users only the access they need, protect the path with layered controls, and make important activity reviewable.
THE CORE IMAGING CONTROL
The radiologist works through the authorized viewer. The radiologist does not need a local DICOM copy to interpret the study.
The radiologist workflow is designed around view access to the study while the underlying DICOM object remains in AWS-hosted controlled storage.
SECURITY LAYERS
Security depends on identity, permissions, encryption, logging, software controls, vendors, and resilience working together.
Approved authentication is used for privileged and clinical access according to the deployed workflow.
Access is limited to the role and task rather than granting broad possession of sensitive data.
Sensitive data is protected using approved encryption mechanisms in transit and at rest.
Security-relevant access, authentication, administrative changes, and critical workflow events are designed to be logged.
Review, testing, dependency management, vulnerability remediation, and change control are part of the production process.
Testing assumptions do not automatically become production permissions or data practices.
Controlled backups, recovery procedures, downtime planning, and integrity checks support continuity.
Vendors and subprocessors are reviewed for access, security duties, incident responsibilities, and termination controls where applicable.
RADIOLOGIST SECURITY BOUNDARY
OPERATING SECURITY
Operational controls determine how systems are monitored, recovered, changed, and investigated.
Systems handling regulated or sensitive information are included in documented risk analysis and remediation tracking.
Owners are assigned to contain events, preserve evidence, evaluate notification duties, and coordinate response.
Recovery procedures and downtime plans should be tested rather than assumed.
Role changes, termination, and high-risk account events require controlled access changes.
Security-sensitive changes should move through testing, review, and explicit production approval.
Licensure, credentialing, privileging, and clinical responsibility remain separate deployment requirements.
The prior Security page is preserved as a standalone reference with the fuller identity, MFA, least privilege, encryption, auditability, secure development, risk, resilience, incident-response, vendor, and clinical-boundary framework.
This page is a plain-language security summary, not a certification or guarantee that every deployment has identical controls. Actual security configuration and evidence depend on the service, customer, data, environment, contracts, clinical function, and production architecture.