AstraRad collects three categories of data: website visitor data (analytics, contact form submissions), platform account data for authorized users at client facilities (name, credentials, activity logs), and protected health information (PHI) contained in the imaging studies we interpret as a HIPAA business associate. We use this data only to deliver teleradiology services, never sell it, and protect PHI under signed Business Associate Agreements with every client. This page is the full policy; questions go through our contact page.
Effective date: July 31, 2026.
Plain-language summary
Before the full policy, here is what it says in brief.
| Question | Answer |
|---|---|
| What we collect | Website analytics and form data; platform user accounts; PHI in imaging studies |
| Why we collect it | To operate the website, run the reading platform, and produce diagnostic reports |
| Who we share with | Client facilities, our credentialed radiologists, and vetted service providers under contract. No one else, and never for sale |
| How long we keep it | PHI per client agreement and law; account data for the life of the account; analytics for a limited operational period |
| Your rights | HIPAA rights through your facility; state privacy law and GDPR rights where applicable |
| How to reach us | Through the contact page |
Data we collect
Website visitors
When you visit astrarad.com we collect standard technical data: IP address, browser type, pages viewed, and referring URL. If you request a rate card or submit the contact form, we collect the information you provide, typically your name, work email, organization, and message. We do not collect PHI through the public website, and you should not submit patient information through it.
Platform users at client facilities
Authorized users at client facilities (radiology administrators, technologists, referring physicians) receive platform accounts. For these accounts we collect name, work email, role, facility affiliation, login credentials, and activity logs. Activity logs record actions such as study uploads, report downloads, and priority changes, and are kept for security auditing and for SLA compliance verification.
Protected health information
When a client facility transmits an imaging study, by DICOM from PACS or by portal upload, that study contains PHI: patient name, date of birth, identifiers, clinical history, and the images themselves. AstraRad processes this PHI solely as a business associate of the client facility under HIPAA. A signed Business Associate Agreement (BAA) is in place before any study is transmitted.
How we use data
We use data only for the purposes below.
- Delivering interpretation services. PHI is used to assign studies to appropriately subspecialized, board-certified radiologists, produce signed reports, and return results by HL7, FHIR, or portal delivery.
- Quality assurance. A sample of reports (1 in 20) is independently double-read. QA reviewers access PHI only as needed for that review.
- Operating and securing the platform. Account data and activity logs support authentication, access control, audit trails, and incident investigation.
- Billing. Per-report billing uses study metadata (study type, priority tier, facility). Invoices do not require patient-identifiable detail beyond what the client agreement specifies.
- Responding to inquiries. Contact form data is used to answer your request, such as sending a rate card within one business day.
- Legal obligations. We use and disclose data where required by law, including breach notification under HIPAA.
We do not use PHI for marketing. We do not sell personal data or PHI. We do not use patient data to train commercial machine learning products outside the scope permitted by the applicable BAA.
Who we share data with
- Client facilities. Reports and study data flow back to the facility that ordered the read.
- Our radiologists. The 240 board-certified, fellowship-trained subspecialists on our panel access PHI only for studies assigned to them, under confidentiality obligations and role-based access controls.
- Service providers. Hosting, secure transmission, and support vendors that handle PHI do so under subcontractor BAAs, as HIPAA requires.
- Legal and safety. We disclose data when required by valid legal process, or to report threats to health and safety as permitted by law.
We do not share data with advertisers, data brokers, or any party not listed above.
Data retention
| Data type | Retention |
|---|---|
| Imaging studies and signed reports | Per the client agreement and applicable medical record retention law; then securely deleted or returned per the BAA |
| Platform account data and audit logs | Life of the account plus the audit period specified in the client agreement |
| Contact form submissions | As long as needed to handle the inquiry and maintain business records |
| Website analytics | A limited operational period; not linked to PHI or platform accounts |
When retention ends, data is destroyed using methods consistent with HHS media sanitization guidance.
Security
AstraRad is HIPAA and GDPR compliant, DICOM conformant, and delivers results over HL7 and FHIR interfaces. Safeguards include encryption of PHI in transit and at rest, role-based access limited to assigned studies, audit logging of PHI access, workforce training, and breach response procedures aligned with the HIPAA Breach Notification Rule administered by HHS Office for Civil Rights. Details of our compliance program are on the compliance page.
Your rights
HIPAA rights
Under HIPAA, patients hold rights of access, amendment, and accounting of disclosures against the covered entity, the facility that ordered the study. If you are a patient, direct your request to that facility; AstraRad supports the facility's response under the BAA. You may also contact us through the contact page and we will route the request.
State privacy rights
Residents of states with comprehensive privacy laws (such as California, Colorado, Virginia, and Texas) may have rights to access, correct, or delete personal data we hold outside of PHI, which is generally exempt from those laws when covered by HIPAA. Submit requests through the contact page; we respond within the timelines the applicable law sets and do not discriminate against you for exercising rights.
GDPR rights
Where GDPR applies, AstraRad acts as a processor for imaging data and as a controller for its own website and business contact data. Data subjects may exercise access, rectification, erasure, restriction, portability, and objection rights. For imaging data, route requests through the controller (the client facility); for website and contact data, reach us directly. Cross-border transfers rely on approved transfer mechanisms.
Cookies and analytics
The website uses essential cookies for basic function and limited analytics cookies to measure page performance. We do not use advertising cookies or cross-site tracking. Analytics data is aggregated and is never joined to platform accounts or PHI.
Children
Our website and platform are directed at healthcare organizations, not children. We do not knowingly collect personal data from children through the website. Pediatric imaging studies transmitted by client facilities are PHI handled under the BAA framework described above.
Changes to this policy
We may update this policy as our services or the law change. Material changes will be posted here with a new effective date, and client facilities will be notified where the change affects PHI handling. Continued use of the website or platform after an update constitutes acceptance, subject to the terms of any executed BAA, which controls over this policy for PHI.
Governing law
This policy is governed by the laws of the State of Delaware, without regard to conflict of law principles, except where HIPAA, GDPR, or a mandatory state privacy law applies to the data in question. Our service commitments and limitations are set out in the terms of service.
Contact
For privacy questions, rights requests, or to report a concern, use the contact page and identify your inquiry as a privacy matter. Facilities with an executed BAA should also use the notice provisions in that agreement for breach-related communications.