AstraRad is a HIPAA business associate to every client we serve. A signed business associate agreement is in place before the first study moves, all imaging data is encrypted in transit with TLS and at rest with AES-256, access is role-based and logged per user, and EU-origin data is handled under GDPR-aligned data processing agreements. That is the whole architecture in one sentence, and every part of it is documented and available for your vendor review.
Most teleradiology companies treat compliance as legal boilerplate: a paragraph in the terms of service, or a press release from years ago. We treat it as part of the product. Imaging center directors and hospital compliance officers evaluate us the same way they evaluate turnaround, so this page lays out the program the way an RFP would ask for it.
How AstraRad meets HIPAA requirements
HIPAA applies to teleradiology through the business associate relationship. Your facility is the covered entity; AstraRad, as the party reading your studies, is a business associate under the HIPAA rules and is directly obligated to follow the Security Rule and the applicable parts of the Privacy Rule.
We implement that obligation across the three safeguard categories the Security Rule defines:
| Safeguard category | What AstraRad implements |
|---|---|
| Administrative | Signed BAAs with every client, workforce HIPAA training, documented policies, periodic risk analysis, sanctions for policy violations, minimum-necessary access assignments |
| Physical | Access-controlled hosting facilities, no PHI on removable media, workstation policies for our 240 subspecialists reading across 12 time zones |
| Technical | TLS encryption in transit, AES-256 encryption at rest, unique user accounts, role-based access control, automatic session timeout, immutable audit logging |
The BAA is not optional and not negotiated after go-live. It covers permitted uses and disclosures, safeguard obligations, flow-down terms for any subcontractor, breach notification duties, and return or destruction of PHI at contract end. If your legal team prefers your own BAA template, we review and sign it during onboarding.
Encryption, access control, and audit logging
Studies reach us one of two ways: direct DICOM transfer from your PACS or portal upload. There is no integration project and no VPN appliance to install, and both paths are encrypted end to end.
The data path looks like this:
- In transit. DICOM transfers and portal uploads run over TLS-encrypted channels. Report delivery back to you, whether HL7, FHIR, or portal download, uses the same encrypted transport.
- At rest. Every stored study, worklist entry, and signed report is encrypted with AES-256. Backups inherit the same encryption.
- In use. Radiologists read through authenticated sessions tied to individual accounts. No shared logins, no exported local copies as a workflow.
Access control follows the minimum-necessary principle. The subspecialist assigned to your study can see it. If the study is among the 1 in 20 we route for independent double-reading, the second reader can see it. Operations staff supporting that read can see what their role requires. Nobody else.
Every access, view, edit, and delivery event is written to an audit log with the user identity, timestamp, and action. Audit records are append-only, and we can produce access histories for a specific study during an incident investigation or a client audit.
The platform is DICOM conformant, so studies arrive with their metadata, series structure, and prior linkage intact rather than passing through lossy conversion steps that create their own integrity risk. Report delivery over HL7 or FHIR means results land in your RIS or EHR through standard, auditable interfaces instead of ad hoc email or fax workflows, which remain one of the most common sources of PHI exposure in imaging operations.
One thing we do not do: use your patients' imaging for marketing, resale, or training commercial AI models. PHI is processed to produce your report and to run the quality program that keeps our major discrepancy rate under 0.3 percent. That is the entire scope.
How does GDPR apply to teleradiology?
If any of your imaging originates from EU data subjects, GDPR sits alongside HIPAA rather than replacing it. Under GDPR, your organization is the controller and AstraRad is a processor, which means three things must be true before we read the study:
- A data processing agreement (DPA) is in place, covering processing scope, security measures, sub-processor terms, and deletion obligations. We sign DPAs alongside the BAA for clients with EU-origin data.
- A lawful basis exists for the processing. As a processor we inherit yours, typically the provision of care, and we process only on your documented instructions.
- Cross-border transfer safeguards are documented for data moving between the EU and the US, using the recognized transfer mechanisms current at the time of contracting.
Operationally, GDPR-scope studies get the same treatment as everything else: the same encryption, the same role-based access, the same audit logging. Data subject rights requests, such as access or erasure, route through you as the controller, and we support fulfillment within the DPA's committed timelines.
Breach response, uptime, and business continuity
A compliance program is only as credible as its behavior on a bad day. Three commitments matter here.
Breach notification. If a breach of unsecured PHI occurs, we notify affected clients without unreasonable delay and within the timelines in the BAA, with the detail HIPAA's Breach Notification Rule requires: what happened, what data was involved, what we have done to contain it, and what we are doing to prevent recurrence. You fulfill your covered-entity notification duties with complete information, not fragments.
Continuity of reads. Coverage is 24/7/365 across 12 time zones with 240 board-certified, fellowship-trained subspecialists on panel. Distributed reading is itself a continuity control: no single site, storm, or regional outage takes down the reading function. We hold headroom for 25,000 additional studies per month, which is also why an 8,000-study backlog clears in under 30 days when a client onboards mid-crisis.
Measured reliability. Our service levels are published, not aspirational: STAT under 1 hour, Urgent under 4 hours, Routine under 24 hours, with 99.4 percent SLA compliance over the trailing 12 months and a 28-minute median STAT turnaround. The full methodology lives on our SLA page.
What compliance documentation can buyers review?
Vendor review should not require a subpoena. During evaluation or an RFP, we provide:
- Standard BAA and DPA templates, or redlines of yours
- A written safeguards summary mapped to the HIPAA Security Rule categories
- Our breach notification procedure and escalation contacts
- Business continuity and coverage overview
- Current SLA performance data and quality program description, including the double-read methodology
- Completed security questionnaires in your format
We respond to documentation requests on the same clock as pricing: reach us through the contact page and the package arrives with your rate card within one business day. Pricing itself is per report with no minimums, no subscriptions, and no platform fees; the details are on the pricing page.
Compliance also extends to who is allowed to read your studies in the first place. Our model is simple: radiologists licensed in the state where your patients are located, matched by subspecialty. State-by-state specifics, with primary sources, are on the licensing hub.
If you are earlier in the process and building a shortlist, our guide to choosing a teleradiology company includes the compliance questions worth asking every vendor, including us. The legal texts behind this page, our privacy policy and terms of service, are published in full. Send one study a month or ten thousand: the safeguards are identical.