Privacy Policy

How AstraRad collects, uses, protects, and retains personal data and protected health information across our teleradiology platform and website.

Updated Fri Jul 31 2026 02:00:00 GMT+0200 (Central European Summer Time)privacylegalphihipaadata-protection

AstraRad collects three categories of data: website visitor data (analytics, contact form submissions), platform account data for authorized users at client facilities (name, credentials, activity logs), and protected health information (PHI) contained in the imaging studies we interpret as a HIPAA business associate. We use this data only to deliver teleradiology services, never sell it, and protect PHI under signed Business Associate Agreements with every client. This page is the full policy; questions go through our contact page.

Effective date: July 31, 2026.

Plain-language summary

Before the full policy, here is what it says in brief.

Question Answer
What we collect Website analytics and form data; platform user accounts; PHI in imaging studies
Why we collect it To operate the website, run the reading platform, and produce diagnostic reports
Who we share with Client facilities, our credentialed radiologists, and vetted service providers under contract. No one else, and never for sale
How long we keep it PHI per client agreement and law; account data for the life of the account; analytics for a limited operational period
Your rights HIPAA rights through your facility; state privacy law and GDPR rights where applicable
How to reach us Through the contact page

Data we collect

Website visitors

When you visit astrarad.com we collect standard technical data: IP address, browser type, pages viewed, and referring URL. If you request a rate card or submit the contact form, we collect the information you provide, typically your name, work email, organization, and message. We do not collect PHI through the public website, and you should not submit patient information through it.

Platform users at client facilities

Authorized users at client facilities (radiology administrators, technologists, referring physicians) receive platform accounts. For these accounts we collect name, work email, role, facility affiliation, login credentials, and activity logs. Activity logs record actions such as study uploads, report downloads, and priority changes, and are kept for security auditing and for SLA compliance verification.

Protected health information

When a client facility transmits an imaging study, by DICOM from PACS or by portal upload, that study contains PHI: patient name, date of birth, identifiers, clinical history, and the images themselves. AstraRad processes this PHI solely as a business associate of the client facility under HIPAA. A signed Business Associate Agreement (BAA) is in place before any study is transmitted.

How we use data

We use data only for the purposes below.

  • Delivering interpretation services. PHI is used to assign studies to appropriately subspecialized, board-certified radiologists, produce signed reports, and return results by HL7, FHIR, or portal delivery.
  • Quality assurance. A sample of reports (1 in 20) is independently double-read. QA reviewers access PHI only as needed for that review.
  • Operating and securing the platform. Account data and activity logs support authentication, access control, audit trails, and incident investigation.
  • Billing. Per-report billing uses study metadata (study type, priority tier, facility). Invoices do not require patient-identifiable detail beyond what the client agreement specifies.
  • Responding to inquiries. Contact form data is used to answer your request, such as sending a rate card within one business day.
  • Legal obligations. We use and disclose data where required by law, including breach notification under HIPAA.

We do not use PHI for marketing. We do not sell personal data or PHI. We do not use patient data to train commercial machine learning products outside the scope permitted by the applicable BAA.

Who we share data with

  • Client facilities. Reports and study data flow back to the facility that ordered the read.
  • Our radiologists. The 240 board-certified, fellowship-trained subspecialists on our panel access PHI only for studies assigned to them, under confidentiality obligations and role-based access controls.
  • Service providers. Hosting, secure transmission, and support vendors that handle PHI do so under subcontractor BAAs, as HIPAA requires.
  • Legal and safety. We disclose data when required by valid legal process, or to report threats to health and safety as permitted by law.

We do not share data with advertisers, data brokers, or any party not listed above.

Data retention

Data type Retention
Imaging studies and signed reports Per the client agreement and applicable medical record retention law; then securely deleted or returned per the BAA
Platform account data and audit logs Life of the account plus the audit period specified in the client agreement
Contact form submissions As long as needed to handle the inquiry and maintain business records
Website analytics A limited operational period; not linked to PHI or platform accounts

When retention ends, data is destroyed using methods consistent with HHS media sanitization guidance.

Security

AstraRad is HIPAA and GDPR compliant, DICOM conformant, and delivers results over HL7 and FHIR interfaces. Safeguards include encryption of PHI in transit and at rest, role-based access limited to assigned studies, audit logging of PHI access, workforce training, and breach response procedures aligned with the HIPAA Breach Notification Rule administered by HHS Office for Civil Rights. Details of our compliance program are on the compliance page.

Your rights

HIPAA rights

Under HIPAA, patients hold rights of access, amendment, and accounting of disclosures against the covered entity, the facility that ordered the study. If you are a patient, direct your request to that facility; AstraRad supports the facility's response under the BAA. You may also contact us through the contact page and we will route the request.

State privacy rights

Residents of states with comprehensive privacy laws (such as California, Colorado, Virginia, and Texas) may have rights to access, correct, or delete personal data we hold outside of PHI, which is generally exempt from those laws when covered by HIPAA. Submit requests through the contact page; we respond within the timelines the applicable law sets and do not discriminate against you for exercising rights.

GDPR rights

Where GDPR applies, AstraRad acts as a processor for imaging data and as a controller for its own website and business contact data. Data subjects may exercise access, rectification, erasure, restriction, portability, and objection rights. For imaging data, route requests through the controller (the client facility); for website and contact data, reach us directly. Cross-border transfers rely on approved transfer mechanisms.

Cookies and analytics

The website uses essential cookies for basic function and limited analytics cookies to measure page performance. We do not use advertising cookies or cross-site tracking. Analytics data is aggregated and is never joined to platform accounts or PHI.

Children

Our website and platform are directed at healthcare organizations, not children. We do not knowingly collect personal data from children through the website. Pediatric imaging studies transmitted by client facilities are PHI handled under the BAA framework described above.

Changes to this policy

We may update this policy as our services or the law change. Material changes will be posted here with a new effective date, and client facilities will be notified where the change affects PHI handling. Continued use of the website or platform after an update constitutes acceptance, subject to the terms of any executed BAA, which controls over this policy for PHI.

Governing law

This policy is governed by the laws of the State of Delaware, without regard to conflict of law principles, except where HIPAA, GDPR, or a mandatory state privacy law applies to the data in question. Our service commitments and limitations are set out in the terms of service.

Contact

For privacy questions, rights requests, or to report a concern, use the contact page and identify your inquiry as a privacy matter. Facilities with an executed BAA should also use the notice provisions in that agreement for breach-related communications.

Questions, answered

Frequently asked questions

Does AstraRad sign a Business Associate Agreement (BAA)?

Yes. AstraRad executes a BAA with every client facility before any protected health information is transmitted. The BAA governs permitted uses of PHI, breach notification obligations, and subcontractor requirements, and it operates alongside this privacy policy.

Does AstraRad sell personal data or PHI?

No. AstraRad does not sell personal data or protected health information to anyone, for any purpose. PHI is used only to perform interpretation services under our contracts and BAAs with client facilities.

How long does AstraRad retain imaging studies and reports?

Studies and signed reports are retained for the period required by the client agreement and applicable law, then securely deleted or returned per the BAA. Website analytics data is retained for a shorter operational period and is not linked to PHI.

Is AstraRad GDPR compliant?

Yes. AstraRad is HIPAA and GDPR compliant. Where GDPR applies, we act as a processor for imaging data, honor data subject rights requests routed through the controller, and use approved transfer mechanisms for any cross-border data flows.

How do patients exercise their HIPAA rights over records AstraRad holds?

Patients should direct access, amendment, and accounting requests to the facility that ordered the study, which is the covered entity holding the designated record set. AstraRad supports those requests through the facility under the BAA, and patients may also reach us through our contact page.

How do I report a privacy concern or suspected breach?

Submit details through our contact page and mark the inquiry as a privacy matter. We acknowledge privacy inquiries promptly, and suspected breaches involving PHI follow the notification timelines in the applicable BAA and HIPAA's Breach Notification Rule.

Put a radiologist's name on your next read.

Tell us your modalities and monthly volume. A complete per-report rate card, with turnaround tiers and SLA terms in writing, lands in your inbox within one business day.