HIPAA & GDPR Compliant Teleradiology

How AstraRad protects imaging data: HIPAA safeguards, BAAs, encryption in transit and at rest, access controls, audit logging, and GDPR readiness.

Updated 31 July 2026compliancehipaagdprsecurityteleradiology

AstraRad is a HIPAA business associate to every client we serve. A signed business associate agreement is in place before the first study moves, all imaging data is encrypted in transit with TLS and at rest with AES-256, access is role-based and logged per user, and EU-origin data is handled under GDPR-aligned data processing agreements. That is the whole architecture in one sentence, and every part of it is documented and available for your vendor review.

Most teleradiology companies treat compliance as legal boilerplate: a paragraph in the terms of service, or a press release from years ago. We treat it as part of the product. Imaging center directors and hospital compliance officers evaluate us the same way they evaluate turnaround, so this page lays out the program the way an RFP would ask for it.

How AstraRad meets HIPAA requirements

HIPAA applies to teleradiology through the business associate relationship. Your facility is the covered entity; AstraRad, as the party reading your studies, is a business associate under the HIPAA rules and is directly obligated to follow the Security Rule and the applicable parts of the Privacy Rule.

We implement that obligation across the three safeguard categories the Security Rule defines:

Safeguard category What AstraRad implements
Administrative Signed BAAs with every client, workforce HIPAA training, documented policies, periodic risk analysis, sanctions for policy violations, minimum-necessary access assignments
Physical Access-controlled hosting facilities, no PHI on removable media, workstation policies for our 240 subspecialists reading across 12 time zones
Technical TLS encryption in transit, AES-256 encryption at rest, unique user accounts, role-based access control, automatic session timeout, immutable audit logging

The BAA is not optional and not negotiated after go-live. It covers permitted uses and disclosures, safeguard obligations, flow-down terms for any subcontractor, breach notification duties, and return or destruction of PHI at contract end. If your legal team prefers your own BAA template, we review and sign it during onboarding.

Encryption, access control, and audit logging

Studies reach us one of two ways: direct DICOM transfer from your PACS or portal upload. There is no integration project and no VPN appliance to install, and both paths are encrypted end to end.

The data path looks like this:

  1. In transit. DICOM transfers and portal uploads run over TLS-encrypted channels. Report delivery back to you, whether HL7, FHIR, or portal download, uses the same encrypted transport.
  2. At rest. Every stored study, worklist entry, and signed report is encrypted with AES-256. Backups inherit the same encryption.
  3. In use. Radiologists read through authenticated sessions tied to individual accounts. No shared logins, no exported local copies as a workflow.

Access control follows the minimum-necessary principle. The subspecialist assigned to your study can see it. If the study is among the 1 in 20 we route for independent double-reading, the second reader can see it. Operations staff supporting that read can see what their role requires. Nobody else.

Every access, view, edit, and delivery event is written to an audit log with the user identity, timestamp, and action. Audit records are append-only, and we can produce access histories for a specific study during an incident investigation or a client audit.

The platform is DICOM conformant, so studies arrive with their metadata, series structure, and prior linkage intact rather than passing through lossy conversion steps that create their own integrity risk. Report delivery over HL7 or FHIR means results land in your RIS or EHR through standard, auditable interfaces instead of ad hoc email or fax workflows, which remain one of the most common sources of PHI exposure in imaging operations.

One thing we do not do: use your patients' imaging for marketing, resale, or training commercial AI models. PHI is processed to produce your report and to run the quality program that keeps our major discrepancy rate under 0.3 percent. That is the entire scope.

How does GDPR apply to teleradiology?

If any of your imaging originates from EU data subjects, GDPR sits alongside HIPAA rather than replacing it. Under GDPR, your organization is the controller and AstraRad is a processor, which means three things must be true before we read the study:

  • A data processing agreement (DPA) is in place, covering processing scope, security measures, sub-processor terms, and deletion obligations. We sign DPAs alongside the BAA for clients with EU-origin data.
  • A lawful basis exists for the processing. As a processor we inherit yours, typically the provision of care, and we process only on your documented instructions.
  • Cross-border transfer safeguards are documented for data moving between the EU and the US, using the recognized transfer mechanisms current at the time of contracting.

Operationally, GDPR-scope studies get the same treatment as everything else: the same encryption, the same role-based access, the same audit logging. Data subject rights requests, such as access or erasure, route through you as the controller, and we support fulfillment within the DPA's committed timelines.

Breach response, uptime, and business continuity

A compliance program is only as credible as its behavior on a bad day. Three commitments matter here.

Breach notification. If a breach of unsecured PHI occurs, we notify affected clients without unreasonable delay and within the timelines in the BAA, with the detail HIPAA's Breach Notification Rule requires: what happened, what data was involved, what we have done to contain it, and what we are doing to prevent recurrence. You fulfill your covered-entity notification duties with complete information, not fragments.

Continuity of reads. Coverage is 24/7/365 across 12 time zones with 240 board-certified, fellowship-trained subspecialists on panel. Distributed reading is itself a continuity control: no single site, storm, or regional outage takes down the reading function. We hold headroom for 25,000 additional studies per month, which is also why an 8,000-study backlog clears in under 30 days when a client onboards mid-crisis.

Measured reliability. Our service levels are published, not aspirational: STAT under 1 hour, Urgent under 4 hours, Routine under 24 hours, with 99.4 percent SLA compliance over the trailing 12 months and a 28-minute median STAT turnaround. The full methodology lives on our SLA page.

What compliance documentation can buyers review?

Vendor review should not require a subpoena. During evaluation or an RFP, we provide:

  • Standard BAA and DPA templates, or redlines of yours
  • A written safeguards summary mapped to the HIPAA Security Rule categories
  • Our breach notification procedure and escalation contacts
  • Business continuity and coverage overview
  • Current SLA performance data and quality program description, including the double-read methodology
  • Completed security questionnaires in your format

We respond to documentation requests on the same clock as pricing: reach us through the contact page and the package arrives with your rate card within one business day. Pricing itself is per report with no minimums, no subscriptions, and no platform fees; the details are on the pricing page.

Compliance also extends to who is allowed to read your studies in the first place. Our model is simple: radiologists licensed in the state where your patients are located, matched by subspecialty. State-by-state specifics, with primary sources, are on the licensing hub.

If you are earlier in the process and building a shortlist, our guide to choosing a teleradiology company includes the compliance questions worth asking every vendor, including us. The legal texts behind this page, our privacy policy and terms of service, are published in full. Send one study a month or ten thousand: the safeguards are identical.

Questions, answered

Frequently asked questions

Is teleradiology HIPAA compliant?

Teleradiology is HIPAA compliant when the reading service operates as a business associate under a signed BAA and implements the administrative, physical, and technical safeguards the Security Rule requires. AstraRad signs a BAA with every client before the first study moves, encrypts all imaging data in transit and at rest, and restricts PHI access to the radiologists and staff involved in each read.

Do you sign business associate agreements?

Yes. A signed business associate agreement is a precondition of service for every AstraRad client, from a single-site imaging center to a hospital network. Our standard BAA covers permitted uses, safeguard obligations, subcontractor flow-down, breach notification timelines, and data return or destruction at termination. We will also review and sign a client's own BAA template during vendor onboarding.

How is imaging data encrypted in transit and at rest?

Studies travel from your PACS or the portal upload over TLS-encrypted channels, and all stored imaging data and reports are encrypted at rest with AES-256. Encryption applies at every stage: transmission, worklist storage, radiologist review, and report delivery over HL7 or FHIR. There is no unencrypted path through the platform.

How does GDPR apply to teleradiology?

When imaging originates from EU data subjects, the reading service acts as a processor under GDPR and needs a data processing agreement, a lawful basis inherited from the controller, and documented safeguards for any cross-border transfer. AstraRad supports DPAs alongside the BAA, applies the same encryption and access controls to all studies, and honors data subject rights requests routed through the client.

What compliance documentation can you share during an RFP?

We provide our standard BAA and DPA templates, a written summary of administrative, physical, and technical safeguards, our breach notification procedure, business continuity overview, and current SLA performance data. Security questionnaires such as a client's own vendor risk assessment are completed during evaluation. Request the package through our contact page and it ships with the rate card within one business day.

Who can see my patients' imaging data?

Access is role-based and limited to the minimum necessary: the subspecialist assigned to the study, the second reader if the study is selected for our 1-in-20 independent double-read program, and the operations staff supporting that workflow. Every access event is written to an audit log tied to a named individual account. No PHI is used for marketing, resale, or model training.

Put a radiologist's name on your next read.

Tell us your modalities and monthly volume. A complete per-report rate card, with turnaround tiers and SLA terms in writing, lands in your inbox within one business day.