Industry

HIPAA compliance for radiology & imaging

PACS, DICOM, and teleradiology reading across organisations — imaging metadata is ePHI and it travels.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

PACS, DICOM, and teleradiology reading across organisations — imaging metadata is ePHI and it travels.

What usually goes wrong

  • PACS and VNA access control and audit logging
  • DICOM metadata leaking identifiers into research and AI pipelines
  • Teleradiology readers working from home networks
  • Long retention periods on large image stores

What SuperHIPAA does about it

  • PACS and VNA control review with audit log validation
  • De-identification procedure for research and AI use
  • Remote reader workstation and network policy
  • Retention and archival safeguard documentation

Your obligations in one paragraph

As a covered entity, you must conduct an accurate and thorough risk analysis, implement the required Security Rule specifications (and either implement or document a rationale for each addressable one), maintain policies and procedures, train your workforce, execute business associate agreements with everyone who touches ePHI on your behalf, and be able to detect, assess, and report breaches. All of it must be evidenced. None of it is a one-time project.

Where most radiology & imaging actually stand

The pattern we see in this vertical: policies exist, training happens sporadically, BAAs are partially in place, and the risk analysis is either missing or several years stale. That last one is the finding that turns an incident into a penalty, because it is the first document OCR requests.

Getting started

  1. Free readiness assessment — scored report, no call required
  2. Gap assessment — if the score shows real exposure
  3. Implementation — we fix it with you, or hand your team the plan
  4. Platform — keeps it true after we leave

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.

Questions

Are radiology & imaging covered entities or business associates?

Typically **Covered Entity**. It matters because it changes which obligations are yours directly and which flow through a BAA. The readiness assessment determines your scope in the first three questions.

How long does it take to get compliant?

For an organisation starting from near zero, 8–12 weeks to a defensible position: risk analysis complete, required safeguards implemented, policies live, workforce trained. Anyone promising two weeks is selling you a certificate.

What does it cost?

Platform starts at a published monthly price — see pricing. Services are fixed-fee. There is no 'contact us for a quote' wall on this site.

Do you replace our IT provider?

No. We tell your IT provider exactly what to configure and then verify they did it.

Is our PACS in scope for the risk analysis?

Centrally. PACS and VNA systems hold enormous ePHI volumes, so access controls, audit logging under §164.312(b), encryption decisions, and every DICOM transfer path belong in the risk analysis — not just the RIS and billing systems.

Do teleradiology reads require a BAA?

An independent radiology group interpreting studies is generally providing treatment, which does not require a BAA — but the platform vendor moving your images on your behalf is a business associate and does. We map who does what before assuming either way.

Are image CDs and USB drives for patients a risk?

Giving patients their own images is their right under §164.524. The risk is unencrypted media used for anything else — §164.310(d) media controls cover creation, tracking, reuse, and disposal, and we put that workflow in policy.

Some modalities run operating systems that cannot be patched. Now what?

That is common and the rule accounts for it: documented compensating controls — network segmentation, restricted access, monitoring — with the reasoning recorded in the risk analysis. What is not defensible is an unpatched scanner nobody has assessed.

Can we contribute imaging data to AI model development?

Only after genuine de-identification, and imaging fails it in ways tabular data does not: DICOM header fields, burned-in annotations on ultrasound and secondary captures, and reconstructable facial features from head CT and MRI. Stripping headers alone is not de-identification — validate the pixels too, and document the method.

We are moving from on-prem PACS to a cloud vendor. What does HIPAA require?

A BAA with the PACS vendor before any study migrates, encrypted transfer for the archive move, and a documented plan for the old hardware — decommissioned PACS servers and modality disks full of studies are a classic §164.310(d) failure. Update the risk analysis to reflect the new architecture rather than the one it was written for.

Can radiologists use interesting cases in teaching files and conference talks?

Only de-identified — and an unusual case can be identifiable from the finding itself in a small community, so scrubbing the name is not always enough. Header data, burned-in text, and clinical narrative all need cleaning, and a standing teaching-file procedure beats ad hoc judgment on the eve of a conference.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo