Privacy policy: how AstraRad handles PHI and imaging data

AstraRad never sells personal data or PHI. This privacy policy covers website, account, and imaging data handled as a HIPAA business associate under BAAs.

Published 8 April 2026Updated 13 August 2026

AstraRad holds three categories of data, uses all of it for one line of work, and sells none of it. The categories are website visitor data from astrarad.com, platform account data for authorized users at client facilities, and protected health information (PHI) inside the studies we interpret as a HIPAA business associate. How each category is handled depends on how it arrived. The PHI is why this privacy policy exists. A scanner finishes its last study of the evening and the images leave the facility for a radiologist who has never walked its halls; traveling with them are a patient's name, date of birth, identifiers, and whatever clinical history the ordering physician typed into the requisition. That data supports producing final signed reports, running the platform that carries them, and billing per report. A Business Associate Agreement is executed with every client facility before a single study moves.

Effective date: July 31, 2026. Last updated: August 13, 2026.

Read the short version first

AstraRad collects website, account, and study data, uses it only to run the platform and produce final signed reports, and sells none of it.

Question Answer
What we collect Website analytics and form data; platform user accounts; PHI inside imaging studies
Why we collect it To operate the website, run the reading platform, and produce final signed reports
Who we share with Client facilities, our subspecialist panel, and vetted service providers under contract; never a sale
How long we keep it PHI per client agreement and law; account data for the life of the account; analytics for a limited operational period
Your rights HIPAA rights through your facility; state privacy and GDPR rights where applicable, subject to the limits stated below
How to reach us The contact form, with the inquiry marked as a privacy matter

Three categories of data reach us

Website visitors, platform users, and transmitted imaging studies each bring their own kind of data and their own rules.

Website visitors

Visiting astrarad.com produces standard technical data: IP address, browser type, pages viewed, and referring URL. Request a rate card or submit the contact form and we also hold what you typed, usually a name, work email, organization, and message. The public website carries business inquiries only: keep patient information out of it, because PHI belongs on the DICOM or portal path described below.

Platform users at client facilities

Radiology administrators, technologists, and referring physicians receive platform accounts. Those accounts carry a name, work email, role, facility affiliation, login credentials, and an activity log. The log records study uploads, report downloads, and priority changes, so security auditing and compliance verification rest on records instead of assertion.

Protected health information

When a client facility transmits a study, by DICOM from its PACS or by upload through the portal, the file carries PHI: patient name, date of birth, identifiers, clinical history, and the images themselves. AstraRad holds that PHI as a business associate of the facility. The distinction decides almost everything else on this page. The facility ordered the study, the facility holds the designated record set, and the facility remains the covered entity a patient turns to for access or amendment. Our authority over that study is borrowed, and it is bounded by the Business Associate Agreement signed before the first transmission. The agreement fixes what the PHI may be used for, which is interpreting the study and returning a final signed report. It fixes who may open the study, which is the subspecialist it was assigned to and the reviewers working inside the quality program. It fixes what happens at the end, which is return to the facility or destruction on the schedule the facility set. Each of those boundaries is enforced in the platform through role-based access and written into the audit log, so a facility auditing us afterward can see which radiologist opened which study and at what hour. Nothing on this page loosens those terms; where the two documents disagree about PHI, the BAA wins.

Where the data goes once it arrives

Every use of arriving data serves final signed reports and the platform that delivers and bills them, nothing else.

  • Producing the final signed report. Each study is routed to a board-certified, fellowship-trained subspecialist licensed in the state where the patient is located, and the signed report returns by HL7, FHIR, or portal.
  • Quality review. One signed report in twenty is pulled for an independent double-read by a second subspecialist, who sees the PHI required to re-read that study and nothing beyond it.
  • Running the platform. Account data and activity logs drive authentication, access control, audit trails, and incident investigation.
  • Billing per report. Invoices are assembled from study metadata: study type, priority tier, facility. Patient-identifiable detail appears only where the client agreement calls for it.
  • Answering what you send. Contact form data is used only to reply to your message.
  • Legal obligations. Data is used and disclosed where the law requires it, including breach notification under HIPAA.

PHI never enters a marketing list, never gets sold or licensed, and is never used to build commercial machine learning products outside what the applicable BAA permits.

Four groups receive data

Only client facilities, our subspecialist panel, contracted service providers, and legal recipients receive data.

  • Client facilities. The final signed report and study data return to the ordering facility.
  • The subspecialists on our panel. A radiologist opens only the studies assigned to them, under confidentiality obligations enforced by role-based access controls.
  • Service providers. Hosting, secure transmission, and support vendors that handle PHI operate under subcontractor BAAs, as HIPAA requires.
  • Legal and safety recipients. Data is disclosed under valid legal process, or to report threats to health and safety where the law permits it.

Advertisers and data brokers receive nothing. If your organization's policy bars PHI from leaving its own network under any business associate arrangement, teleradiology is the wrong fit, and that includes AstraRad.

Each data type has a retention clock

Imaging studies and final signed reports are kept as long as the client agreement and medical record retention law require; every other data type is held shorter. Platform account data and audit logs live for the life of the account plus the audit period the client agreement specifies. Contact form submissions last as long as the inquiry stays open, plus ordinary business record keeping. Website analytics has a short operational life and is never joined to PHI or platform accounts. When a clock runs out, data is destroyed per HHS media sanitization guidance or returned to the facility, whichever the BAA specifies.

We encrypt PHI in transit and at rest

PHI is encrypted in transit and at rest. AstraRad operates as a HIPAA business associate under a signed BAA, builds its safeguards to the HIPAA Security Rule categories, is DICOM conformant, and delivers results over HL7 and FHIR interfaces. Beyond encryption, the safeguards that matter day to day are ordinary and enforced: access scoped by role to assigned studies, audit logging of every PHI access, workforce training, and a breach response procedure aligned with the HIPAA Breach Notification Rule administered by the HHS Office for Civil Rights. Our full compliance program is documented on the compliance page.

Rights you can exercise

HIPAA rights run through the facility that ordered your study; state privacy and GDPR rights, where they apply, come to us directly.

HIPAA rights

HIPAA's rights of access, amendment, and accounting of disclosures run against the covered entity: the facility that ordered the study. Send your request there. AstraRad supports the facility's response under the BAA, and a request that arrives through our contact page will be routed to the facility holding your record.

State privacy rights

Residents of states with comprehensive privacy laws may hold rights to access, correct, or delete personal data we keep outside of PHI, which is generally exempt from those laws when HIPAA already covers it. Submit requests through the contact page; we answer inside the timelines the law sets, and exercising a right costs you nothing in service or price.

GDPR rights

Where GDPR applies, AstraRad acts as a processor for client imaging under a signed data processing agreement, and as a controller for its own website and business contact data. For imaging that means we act on the controlling facility's documented instructions and support its response; we make no compliance claim of our own. Route imaging requests through the controller, which is the client facility.

For website and business contact data, use the contact form and mark the inquiry as a privacy matter. Access, rectification, erasure, restriction, portability, and objection requests are handled case by case, and you'll be told what we hold and what we can remove. One limit belongs here plainly: astrarad.com carries no consent management platform yet, so analytics runs for every visitor and the site offers no on-page consent switch to withdraw. Until that tooling ships, the browser-level opt-outs described under cookies are the working control, and a request through the contact form is how you reach us. Cross-border transfers rely on approved transfer mechanisms.

AstraRad has not appointed an Article 27 representative in the EU or the UK, because it offers its service to healthcare organizations rather than to data subjects directly. If that changes, the appointment and its address will be published on this page.

Cookies stay limited to function, analytics, and ad measurement

The website sets essential cookies so pages work, plus cookies for four third-party tools. Google Analytics 4 measures page performance and where traffic came from. Microsoft Clarity records aggregate interaction data such as scroll depth and clicks. Leadfeeder, operated by Dealfront, resolves the visitor IP address to an organization so we can see which companies visit; it identifies companies, not individuals, and we do not use it to build a profile of a named person. The OpenAI pixel measures advertising: it sets first-party cookies holding a click identifier for 30 days, a browser reference, and a consent flag, and it reports which actions on this site followed a click on an OpenAI ad.

One line of the previous version of this section is no longer true and is worth stating plainly rather than quietly deleting: advertising measurement is now in use on this site. Advertising and remarketing features remain switched off in Google Analytics 4, Clarity, and Leadfeeder, and the OpenAI pixel is used to count conversions rather than to build remarketing audiences.

Two things about that pixel are worth spelling out, because they are the parts a reader cannot check for themselves. It runs with automatic matching enabled, which OpenAI controls from its own servers rather than us: when you submit a form on this site, the pixel reads the email address you typed, hashes it with SHA-256 in your browser, and sends the hash rather than the address. It is used to match a conversion to an ad click. It is one-way, we send nothing else about you with it, and no name, phone number, or message text is included. Second, the pixel is deliberately not loaded on the signed-in areas of this site at all, so nothing in the portal, the reading worklist, or our internal tools is measured by it. None of this data is joined to a platform account or to PHI, and no PHI ever reaches it: patient data travels by DICOM and the portal, never through a website form.

All four run for every visitor, because the site does not yet present a consent banner. Three opt-outs work today: install Google's Analytics opt-out browser add-on, block analytics cookies in your browser settings, or run any tracker-blocking extension. None of the four changes what the site shows you. When consent tooling is in place, this section changes and the effective date at the top of the page moves with it.

Pediatric studies follow the BAA framework

A child's study transmitted by a client facility is PHI, handled under the same BAA framework, role-based access, and audit logging as every other study on the platform. The website itself is built for healthcare organizations, and we do not knowingly collect personal data from children through it.

We post privacy policy changes here with a new effective date

Material revisions to this privacy policy appear on this page under a new effective date, and client facilities are notified directly where a change affects PHI handling. Continued use after an update constitutes acceptance; an executed BAA still controls for anything involving PHI.

Delaware law governs this privacy policy

This privacy policy is governed by Delaware law, without regard to conflict of law principles, except where HIPAA, GDPR, or a mandatory state privacy law reaches the data in question. Service commitments and limitations live in the terms of service.

Reach us about a privacy matter

Use the contact page for privacy questions, rights requests, and reports of a suspected problem, and label the inquiry as a privacy matter. Suspected security problems go through the same form, labelled as a security report. A facility with an executed BAA should also use that agreement's notice provisions for anything breach related, because those provisions carry the deadlines. The BAA is the contract. This privacy policy is the explanation.

Questions, answered

Frequently asked questions

Does AstraRad sign a Business Associate Agreement (BAA)?

Yes. Every client facility signs a BAA before the first study is transmitted. The agreement sets the permitted uses of PHI, the breach notification duties on both sides, the subcontractor terms passed down to vendors that touch PHI, and the return or destruction schedule at the end of the relationship. Where the BAA and this policy differ on PHI, the BAA controls.

Does AstraRad sell personal data or PHI?

No. Personal data and PHI are never sold, licensed, or brokered. PHI is used to interpret studies, produce final signed reports, and support the quality review that samples signed reports, all under the client agreement and BAA. Advertisers and data brokers receive nothing at all.

How long does AstraRad retain imaging studies and reports?

Studies and final signed reports are held for the period the client agreement and applicable medical record retention law require, then returned to the facility or destroyed on the schedule in the BAA. Website analytics data has a much shorter operational life and is never joined to PHI or to platform accounts.

How does GDPR compliance work when AstraRad handles EU imaging?

For client imaging AstraRad is a processor, not a controller, so it does not claim GDPR compliance in its own right: it supports yours. EU imaging is processed under a signed data processing agreement, on your documented instructions, and data subject rights requests are honored through the controller, which is the facility that ordered the study. Interpretation happens in the United States, and any cross-border flow of personal data relies on approved transfer mechanisms.

How do patients exercise their HIPAA rights over records AstraRad holds?

Send access, amendment, and accounting requests to the facility that ordered the study. That facility is the covered entity, and it holds the designated record set your rights attach to. AstraRad supports the facility's response under the BAA, and you may also reach us through our contact page so we can route the request to the right place.

What analytics does astrarad.com use, and can I opt out?

Four tools, and they do different things. Google Analytics 4 measures page performance and where traffic came from. Microsoft Clarity records aggregate interaction data such as scroll depth and clicks. Two are not page analytics at all, and they are the two worth knowing about. Leadfeeder, from Dealfront, resolves the visitor IP address to an organization so we can see which companies read the site, which is standard business-to-business practice. The OpenAI pixel is advertising measurement: when a visit arrives from an OpenAI ad it carries a click identifier in the URL, the pixel stores that identifier in a first-party cookie for 30 days, and it reports back which actions on this site followed that click. If you submit a form, it also sends a SHA-256 hash of the email address you typed, never the address itself, so a conversion can be matched to an ad click. It does not run on the signed-in areas of the site. None of the four is ever joined to a platform account or to PHI. The site does not yet present a consent banner, so all four run for every visitor. You can opt out today with Google's Analytics opt-out browser add-on, by blocking cookies in your browser settings, or with any tracker-blocking extension, which stops all four.

How do I report a privacy concern or suspected breach?

Submit the details through the contact form on astrarad.com and mark the inquiry as a privacy matter. That form is the contact route for privacy questions, and submissions are logged and acknowledged promptly. A suspected breach involving PHI follows the notification timelines written into the applicable BAA and HIPAA's Breach Notification Rule.

Put a radiologist's name on your next read.

Tell us your modalities and monthly volume. A complete per-report rate card, with turnaround tiers and SLA terms in writing, lands in your inbox within one business day.