HIPAA and GDPR compliance in teleradiology
How HIPAA and GDPR apply to teleradiology: AstraRad works as a business associate under a signed BAA, with encryption, access controls and audit logging.
A chest CT finishes at 11:52 p.m., and the study is on a subspecialist's worklist a minute later, mid-shift for the radiologist who will read it. Nothing in that hand-off is informal: it is what the HIPAA and GDPR obligations on a teleradiology provider look like in practice. A signed business associate agreement was on file before the first study ever moved, the transfer ran over TLS, the stored study sits encrypted at rest with AES-256, and the radiologist opened it under a named account whose every action lands in an append-only audit log. Studies from EU data subjects carry a data processing agreement alongside the BAA, and every document in that sequence is available on request during evaluation.
One clarification belongs at the top, because everything below it depends on the distinction. There is no such thing as HIPAA certification: HHS issues none, and no organization can hold a certificate saying it is compliant. What AstraRad can state, and evidence on request, is its role and its controls. AstraRad operates as a business associate under a signed BAA, processes EU imaging as a processor under a signed DPA, and builds its safeguards to the HIPAA Security Rule categories. It holds no SOC 2 report, no ISO 27001 certification, no HITRUST certification and no Joint Commission accreditation, and claims none of them. This page describes that posture and the documents behind it.
HIPAA compliance in teleradiology attaches through the business associate relationship
HIPAA compliance in teleradiology rests on the business associate relationship: your facility is the covered entity, and AstraRad, as the party interpreting your studies, is a business associate under the HIPAA rules with direct liability under the Security Rule and the applicable parts of the Privacy Rule. Your contract is one layer of protection; federal enforcement authority reaching us directly is the other.
That obligation lands in the three safeguard categories the Security Rule defines:
| Safeguard category | What AstraRad implements |
|---|---|
| Administrative | Signed BAAs with every client, workforce HIPAA training, documented policies, periodic risk analysis, sanctions for policy violations, minimum-necessary access assignments |
| Physical | Access-controlled hosting facilities, no PHI on removable media, workstation policies that apply to every radiologist on the panel, all physically located in the United States |
| Technical | TLS encryption in transit, AES-256 encryption at rest, unique user accounts, role-based access control, automatic session timeout, immutable audit logging |
The BAA is signed before onboarding starts and covers permitted uses, safeguard obligations, subcontractor flow-down, breach notification duties, and PHI return or destruction at contract end. If your legal team prefers your own template, we review and sign it during onboarding.
Your imaging is encrypted in transit, at rest, and in use
Your imaging is encrypted at every stage: TLS on every transfer in and out, AES-256 on every stored study, worklist entry, signed report, and backup, and authenticated individual sessions with automatic timeout while a radiologist reads. Studies reach us by direct DICOM transfer from your PACS or by upload through the portal; neither requires an integration project or a VPN appliance, and report delivery, whether HL7, FHIR, or portal download, uses the same encrypted transport. The control set behind those safeguards is designed against the ISO 27001 control catalogue. AstraRad is not ISO 27001 certified, holds no SOC 2 report and no HITRUST certification, and claims none; what it offers instead is the written safeguards summary mapped to the HIPAA Security Rule categories, and a completed security questionnaire in your own format.
Access control is where imaging programs get into trouble, and the failure is almost never dramatic. It looks like a shared workstation login in a reading room, a study copied to a local drive because the viewer was slow that night, a report faxed to a referring office and left sitting in a tray. Each of those is a person solving the problem in front of them, and the link between an action and a name quietly breaks. So access here is scoped to the minimum necessary and tied to individuals from the start. The subspecialist assigned to your study can open it. If the study is among the 1 in 20 routed for independent double-reading, the second reader can open it, and that physician's identity is recorded the same way. Operations staff supporting the read see what their role requires and no more.
Every view, edit, and delivery event is written to an append-only audit log. Each entry carries the account, the timestamp, and the action. That is what lets us produce a complete access history for a single accession number during an incident investigation or a client audit. Producing that history on request is the practical test of an access program.
The platform is DICOM conformant, so a study arrives with metadata, series structure, and prior linkage intact, and HL7 or FHIR delivery puts the signed report into your RIS or EHR through a standard, auditable interface. Email attachments and fax machines remain among the most common sources of PHI exposure in imaging, and a working interface removes the reason anyone would reach for either.
One boundary belongs in writing, because buyers raise it in every evaluation. Your patients' imaging is processed for two purposes and no others: to produce your report, and to run the quality program behind it. That program is the 1-in-20 independent double-read and the monthly discrepancy review, where major discrepancies, under 0.3% of signed reports, are closed with the reader who signed. PHI is never used for marketing, sold onward, or used to train any model; the restriction is written into the BAA, so it survives any change in our commercial plans.
No algorithm sits in the report path
AstraRad performs no AI pre-read. No algorithm triages a worklist, drafts a report, or contributes text to one, and no client PHI is used to train any model. Every finding, every measurement, and every impression on a signed report was written by the board-certified, fellowship-trained subspecialist whose name and credentials are on it.
That is a compliance fact before it is a capability claim, because it removes review items instead of adding them. There is no model to put in front of your review board, no model version to reconcile against a report signed a year ago, and no algorithmic output on the chart for a reviewer to weigh against the radiologist's impression. Routing is the only automated step, and it decides who reads a study, never what the report says: a study is assigned by modality, body part, and patient age to a subspecialist fellowship-trained for that work, and the interpretation is that physician's.
The training restriction is a contract term. A policy can be rewritten in an afternoon; a BAA clause cannot. PHI is never used to train any model, and the prohibition is written into the BAA alongside the other permitted-use limits, which is what makes it enforceable by you rather than revocable by us. What stands in place of an algorithm is the quality program described above: 1 signed report in 20 independently double-read by a second subspecialist who cannot see the first interpretation, major discrepancies under 0.3% of signed reports, and every one of them closed with the reader who signed. The measurement method behind both figures is published on the SLA page.
How does GDPR apply to teleradiology?
When imaging originates from EU data subjects, GDPR applies to the teleradiology relationship on top of the HIPAA obligations: your organization is the controller and AstraRad is the processor. Three things are in place before a radiologist opens the study:
- A data processing agreement (DPA) covering processing scope, security measures, sub-processor terms, and deletion obligations, signed alongside the BAA.
- A lawful basis inherited from you as controller, typically the provision of care; we process only on your documented instructions.
- Cross-border transfer safeguards documented for data moving between the EU and the US, using the recognized transfer mechanisms current at contracting.
Operationally, a GDPR-scope study is handled like every other study: same encryption, same role-based access, same audit log. Data subject rights requests, access or erasure, route through you as the controller, and we support fulfillment inside the DPA's timelines.
Reading continues when the day goes badly
Two commitments govern the bad days: you hear about incidents on a contractual clock, and the reading function keeps running.
Breach notification. If a breach of unsecured PHI occurs, we notify affected clients without unreasonable delay. The clock is the one written into the BAA. The notice carries the level of detail HIPAA's Breach Notification Rule requires: what happened, which data was involved, what has been done to contain it, and what changes to prevent recurrence. Your own covered-entity notification duties then run on complete information.
Professional liability coverage. AstraRad carries professional liability insurance covering the interpretations its radiologists sign, and every radiologist on the panel is covered for the reading they do for AstraRad. A certificate of insurance is issued to your organization on request during evaluation or contracting, naming the carrier, the policy form and the limits, so your risk office reviews the actual terms rather than a summary of them. Limits and policy form belong in the contract, which is why no figure appears on this page.
Continuity of reads. Coverage runs 24/7/365 on scheduled shifts with 240 board-certified, fellowship-trained subspecialists on panel, all physically located in the United States; 99.4% of signed reports landed inside their contracted tier over the trailing 12 months, and the median STAT turnaround was 30 minutes. Shift coverage spread across US regions is itself a continuity control: a hurricane that closes one region does not close the reading function, because radiologists on shift elsewhere in the country hold licensure in the state where your patients are located. Panel headroom covers 25,000 additional studies per month, which is why an 8,000-study backlog clears in under 30 days for a facility onboarding mid-crisis.
Measured reliability. The tiers are contractual: STAT under 1 hour, Urgent under 4 hours, Routine under 24 hours, each measured from last-image arrival to radiologist signature and reported on the trailing twelve months. The SLA page carries the measurement methodology.
What compliance documentation can buyers review?
Every document named on this page is available during evaluation or a formal RFP:
- Standard BAA and DPA templates, or redlines of yours
- A written safeguards summary mapped to the HIPAA Security Rule categories
- Our breach notification procedure and escalation contacts
- Business continuity and coverage overview
- A current certificate of insurance for professional liability, issued to your organization
- Current SLA performance data and the quality program description, including double-read methodology
- Completed security questionnaires in your format
Documentation requests move on the same clock as pricing: reach us through the contact page and the package arrives with your rate card within one business day. Per-report pricing with no minimums, subscriptions, or platform fees is set out on the pricing page.
Who may read your studies belongs to the same program: every study goes to a radiologist licensed in the state where your patients are located, matched by subspecialty, from a panel holding active licenses in all 50 US states, with primary sources on the licensing hub. One honest limit: AstraRad delivers final signed reports only, so a program built around overnight preliminary reads with morning overreads by your own staff, or one that needs a radiologist physically on site for procedures, is a wrong fit for us. If you are still assembling a shortlist, the compliance questions in our guide to choosing a teleradiology company apply to every vendor you talk to, this one included. The privacy policy and terms of service are published in full.
HIPAA compliance in teleradiology lives in unglamorous places. It is the account deactivated the day a radiologist rolls off your facility, the log entry nobody needs until an auditor asks for it by accession number, the BAA countersigned before the first study moved. A program is only ever as good as the record it can produce a year later.
Frequently asked questions
Is teleradiology HIPAA compliant?
Teleradiology is HIPAA compliant when the reading service operates as a business associate under a signed BAA and implements the administrative, physical, and technical safeguards the Security Rule requires. AstraRad signs a BAA with every client before the first study moves, encrypts all imaging data in transit and at rest, and restricts PHI access to the radiologists and staff involved in each read.
Do you sign business associate agreements?
Yes. A signed business associate agreement is a precondition of service for every AstraRad client, from a single imaging center to a hospital network. Our standard BAA covers permitted uses, safeguard obligations, subcontractor flow-down, breach notification timelines, and data return or destruction at termination. We will also review and sign a client's own BAA template during vendor onboarding.
How is imaging data encrypted in transit and at rest?
Studies travel from your PACS or the portal upload over TLS-encrypted channels, and all stored imaging data and reports are encrypted at rest with AES-256. Encryption applies at every stage: transmission, worklist storage, radiologist review, and report delivery over HL7 or FHIR. There is no unencrypted path through the platform.
How does GDPR apply to teleradiology?
When imaging originates from EU data subjects, the reading service acts as a processor under GDPR and needs a data processing agreement, a lawful basis inherited from the controller, and documented safeguards for any cross-border transfer. AstraRad supports DPAs alongside the BAA, applies the same encryption and access controls to all studies, and honors data subject rights requests routed through the client.
What compliance documentation can you share during an RFP?
We provide our standard BAA and DPA templates, a written summary of administrative, physical, and technical safeguards, our breach notification procedure, business continuity overview, and current SLA performance data. Security questionnaires such as a client's own vendor risk assessment are completed during evaluation. Request the package through our contact page and it ships with the rate card within one business day.
Who can see my patients' imaging data?
Access is role-based and limited to the minimum necessary: the subspecialist assigned to the study, the second reader if the study is selected for our 1-in-20 independent double-read program, and the operations staff supporting that workflow. Every access event is written to an audit log tied to a named individual account. No PHI is used for marketing, resale, or model training.
Do you run AI on our studies, and is our PHI used to train models?
No to both. AstraRad performs no AI pre-read: no algorithm triages a worklist, drafts a report, or contributes text to one, and every report is read and signed by a board-certified subspecialist. No client PHI is used to train any model, and that restriction is written into the BAA rather than left to policy, so there is no model for your review board to assess and no model output on the chart.
Put a radiologist's name on your next read.
Tell us your modalities and monthly volume. A complete per-report rate card, with turnaround tiers and SLA terms in writing, lands in your inbox within one business day.