SECURITY

Security should be easy to understand.

Keep the imaging in controlled AWS-hosted storage, give authorized users only the access they need, protect the path with layered controls, and make important activity reviewable.

AWS-HOSTED DICOMVIEW-ONLY RADIOLOGIST ACCESSMFA & LEAST PRIVILEGEENCRYPTION & AUDITABILITY

THE CORE IMAGING CONTROL

The DICOM file stays in AWS-controlled storage.

The radiologist works through the authorized viewer. The radiologist does not need a local DICOM copy to interpret the study.

AWSDICOM STORAGE

View, do not take possession.

The radiologist workflow is designed around view access to the study while the underlying DICOM object remains in AWS-hosted controlled storage.

DICOM remains in AWS storage
Radiologist users receive view-only access
DICOM download is disabled for radiologist users
No local DICOM export from the radiologist viewer

SECURITY LAYERS

The vault is one layer. The workflow is protected by several more.

Security depends on identity, permissions, encryption, logging, software controls, vendors, and resilience working together.

IDENTITY

MFA and verified users

Approved authentication is used for privileged and clinical access according to the deployed workflow.

LEAST PRIVILEGE

Only the permissions needed

Access is limited to the role and task rather than granting broad possession of sensitive data.

ENCRYPTION

Protect storage and transport

Sensitive data is protected using approved encryption mechanisms in transit and at rest.

AUDITABILITY

Important actions are reviewable

Security-relevant access, authentication, administrative changes, and critical workflow events are designed to be logged.

SOFTWARE

Secure development

Review, testing, dependency management, vulnerability remediation, and change control are part of the production process.

ENVIRONMENTS

Keep staging and production distinct

Testing assumptions do not automatically become production permissions or data practices.

RESILIENCE

Backup and recovery

Controlled backups, recovery procedures, downtime planning, and integrity checks support continuity.

VENDORS

Third parties are governed

Vendors and subprocessors are reviewed for access, security duties, incident responsibilities, and termination controls where applicable.

RADIOLOGIST SECURITY BOUNDARY

View access is not file possession.

Radiologist can

Open an assigned study in the authorized viewer
Use approved viewing and interpretation tools
Access the clinical information required for the assigned work
Complete the approved interpretation workflow

Radiologist cannot

×Download the DICOM file from the radiologist viewer
×Export the underlying DICOM object to a local device
×Create an unrestricted local DICOM archive through the viewer
×Turn clinical view access into unrestricted data access

OPERATING SECURITY

Security continues after sign-in.

Operational controls determine how systems are monitored, recovered, changed, and investigated.

RISK

Risk analysis

Systems handling regulated or sensitive information are included in documented risk analysis and remediation tracking.

INCIDENTS

Incident response

Owners are assigned to contain events, preserve evidence, evaluate notification duties, and coordinate response.

RECOVERY

Restoration and continuity

Recovery procedures and downtime plans should be tested rather than assumed.

OFFBOARDING

Remove access promptly

Role changes, termination, and high-risk account events require controlled access changes.

CHANGE CONTROL

Production changes are reviewed

Security-sensitive changes should move through testing, review, and explicit production approval.

CLINICAL BOUNDARY

Security does not create clinical authority

Licensure, credentialing, privileging, and clinical responsibility remain separate deployment requirements.

Need the detailed security baseline?

The prior Security page is preserved as a standalone reference with the fuller identity, MFA, least privilege, encryption, auditability, secure development, risk, resilience, incident-response, vendor, and clinical-boundary framework.

This page is a plain-language security summary, not a certification or guarantee that every deployment has identical controls. Actual security configuration and evidence depend on the service, customer, data, environment, contracts, clinical function, and production architecture.