Patient data stays protected at every step.
Radiology imaging data includes PHI tied to diagnosis. We built Radivault's data handling from the assumption that a DICOM file is not just an image: it is a patient record. De-identification, access controls, and audit logging are not features added on top. They are the default architecture.
Core data principles
PHI never enters model training
DICOM studies are de-identified at ingestion before any model processing occurs. Patient name, date of birth, MRN, and all other PHI fields are stripped from the DICOM header. The de-identified pixel data is used for inference only. PHI is never stored, transmitted to model infrastructure, or used in any model training or fine-tuning process.
Encrypted in transit and at rest
All data in motion uses TLS 1.3. Data at rest uses AES-256. Encryption keys are generated per tenant and are not shared across customers. Key management follows standard key rotation practices. There is no path where one customer's key material can be used to access another customer's data.
Audit log on every action
Every study received, every pre-read generated, every draft delivered, and every user action on a case is logged with timestamp, user identity, and access context. Audit logs are immutable and available to department administrators for compliance review. Logs can be exported for your own records management process.
Access scoped by role
Radiologist, department administrator, and technical administrator roles carry distinct permission sets. A radiologist account can access pre-reads for their assigned department only. A department administrator can configure settings and view the operations dashboard but cannot modify integration credentials. Role assignments are managed by your technical administrator, not by Radivault.
Designed with HIPAA controls in mind.
Radivault is designed to operate as a Business Associate within a HIPAA-covered entity's environment. We execute a Business Associate Agreement (BAA) as a standard step before any department goes live. Our data handling practices, including PHI de-identification at ingestion, access controls scoped by role, and audit logging of every study action, are designed to align with HIPAA Security Rule and Privacy Rule requirements.
We are not HIPAA certified. No formal third-party HIPAA certification program exists in the US. "Designed with HIPAA-aligned controls" means our engineering and access control decisions are made with HIPAA Security Rule requirements in view. BAA execution formalizes our obligations as a Business Associate. If your compliance team needs a technical controls document, contact us and we will share it.
BAA execution is included in all contracts. Contact us at [email protected] to initiate.