ClinicalRIS
FeaturesSolutionsSecond OpinionAI + ExpertPricingAbout UsContactClinicalHIS
HIPAA & GDPR Compliant
ISO 27001 ISMS

Enterprise Privacy & Healthcare Data Policy

ClinicalRIS by Claridad Health Solutions enforces stringent safeguards to protect Protected Health Information (PHI), DICOM diagnostic studies, and personal data across our cloud radiology platform.

Last Version Revision: January 15, 2026 | Effective Date: January 15, 2026

Sections:1. Scope2. Data Categories3. HIPAA BAA4. GDPR Rights5. Encryption6. Sub-processors7. Breach Protocol

Enterprise Data Protection Executive Summary

  • FIPS 140-2 AES-256 GCM encryption for stored DICOM files and database backups.
  • Standardized Business Associate Agreements (BAA) signed with all Covered Entities.
  • Zero Data Monetization: We never sell, advertise, or license PHI or clinical records.
  • Immutable Audit Trails recording all access, exports, and modifications to patient data.

1. Introduction & Regulatory Scope

ClinicalRIS is an enterprise medical software platform operated by Claridad Health Solutions ("Claridad", "we", "us", or "our"). We provide Radiology Information Systems (RIS), Picture Archiving and Communication Systems (PACS), diagnostic reporting tools, and AI CAD integrations to hospitals, imaging centers, teleradiologists, and referring physicians.

This Privacy Policy describes how we handle information in compliance with global health privacy regulations, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, the General Data Protection Regulation (EU GDPR / UK GDPR), and applicable national medical data laws.

2. Categories of Information We Process

Depending on your interaction with ClinicalRIS, we process three distinct categories of data:

2.1 Protected Health Information (PHI)

When healthcare providers upload DICOM images or generate diagnostic reports, we process PHI on behalf of the Covered Entity. This includes:

  • Patient Identifiers: Full name, Medical Record Number (MRN), Date of Birth, gender, national health identifier, and contact details.
  • Diagnostic DICOM Metadata & Pixels: X-ray, CT, MRI, Ultrasound, Mammography, and Nuclear Medicine imaging series containing embedded DICOM tags.
  • Clinical Reports & Orders: Radiologist findings, impressions, critical findings alerts, dictation audio, and referring physician orders.

2.2 Professional Account Data

Information collected when healthcare staff create account credentials:

  • Full legal name, professional medical license numbers, clinical sub-specialties, NPI numbers, and digital signatures.
  • Institutional email address, organizational role, center assignments, and multi-factor authentication (MFA) parameters.

2.3 Telemetry & Diagnostic Logs

Automated system telemetry collected to maintain 99.99% uptime and security audit compliance:

  • IP address, browser user-agent, session tokens, DICOM WADO-RS retrieval latencies, and granular user action timestamps.

3. HIPAA Business Associate Framework (45 CFR § 164.502)

Under HIPAA regulations, Claridad Health Solutions acts strictly as a Business Associate to healthcare providers ("Covered Entities").

  • Business Associate Agreement (BAA): Prior to processing PHI, Claridad executes a standard BAA with Covered Entities governing permissible uses, data retention, administrative safeguards, and breach notifications.
  • Minimum Necessary Standard: Systems restrict access to PHI based on role-based access control (RBAC). Technologists, radiologists, and billing personnel only view data required for their specific clinical workflows.
  • De-identification Standards: Any data utilized for AI benchmarking or platform quality assurance is fully de-identified in strict accordance with HIPAA Safe Harbor principles (45 CFR § 164.514(b)(2)).

4. GDPR & International Data Subject Rights

For users and patients residing within the European Economic Area (EEA), United Kingdom, or jurisdictions with international privacy rights:

Right to Access & Portability

Request a copy of stored personal credentials and export DICOM instances in standard JSON/ZIP formats.

Right to Rectification

Correct inaccurate account records or professional license information via institutional center admins.

Right to Erasure (Medical Exception)

Request deletion of personal account data. Note: Clinical PHI retention is subject to statutory medical record retention laws (typically 7–10 years).

Restriction of Processing

Restrict processing during legal disputes or verification of administrative accuracy.

5. Cryptographic Controls & Security Standards

ClinicalRIS implements defense-in-depth cryptographic controls across all infrastructure tiers:

  • Data at Rest: DICOM object stores, PostgreSQL databases, and audit logs are encrypted using AES-256 GCM with keys rotated automatically via hardware security modules (HSM).
  • Data in Transit: All HTTP connections require TLS 1.3 (with fallback to TLS 1.2 using strong cipher suites). Cleartext HTTP is disabled.
  • Session Security: Keycloak OAuth2 / OpenID Connect tokens with HTTP-only, secure, SameSite cookies and short token lifetimes.

6. Infrastructure Sub-processors

We partner with Tier-IV compliant cloud providers to deliver cloud hosting, container orchestration, and AI inference. All sub-processors undergo rigorous SOC 2 Type II vendor audits and execute HIPAA BAAs:

Sub-processorPurposeLocationSecurity Certification
Amazon Web Services (AWS)Cloud Infrastructure & DICOM Object StorageUSA / EU RegionsISO 27001, SOC 2 Type II, HIPAA Compliant
Google Cloud Platform (GCP)AI CAD Inference & Backup StorageUSA / EU RegionsISO 27001, SOC 2 Type II, HIPAA Compliant
Keycloak IAM EngineFederated Identity & OAuth AuthenticationDedicated Isolated VPCOpenID Certified, FIPS 140-2

7. Incident Response & 72-Hour Breach Notification

Claridad Health Solutions maintains a dedicated Security Operations Center (SOC) monitoring platform telemetry 24/7. In the unlikely event of a confirmed security incident impacting PHI:

  • 72-Hour SLA: Affected Covered Entities will be notified in writing within 72 hours of incident confirmation, detailing the scope of impacted records and immediate remediation steps taken.
  • Regulatory Filings: Claridad assists Covered Entities with required filings to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) or European Data Protection Authorities.

8. Contact Our Data Protection Officer (DPO)

For privacy inquiries, BAA requests, or Data Subject Access Requests (DSAR), contact our compliance team:

Claridad Health Solutions — Privacy & Compliance Directorate
Email: privacy@clinicalris.com
Security Team: security@clinicalris.com
Address: 100 Enterprise Way, Suite 400, Healthcare Technology Park
All PACS & AI Ingestion Systems Operational (99.99% SLA)

Stay ahead in Diagnostic Imaging & AI Telemetry

Get monthly product updates, DICOM protocol benchmarks, and clinical case studies.

ClinicalRIS

Next-generation AI-accelerated Radiology Information System & Cloud PACS. Engineered for diagnostic speed, high concurrency, and zero-compromise security.

HIPAA Compliant
SOC 2 Type II
DICOM 3.0 / HL7 FHIR

Product

  • Features & Modalities
  • Clinical Solutions
  • AI Second Opinion
  • Regional Pricing
  • Changelog & Releases
  • ClinicalHIS Hospital Platform

Resources

  • Interactive Documentation
  • DICOMweb & REST API
  • User Manuals & SOP
  • Radiology Research Blog
  • 24/7 Clinical Support

Legal & Security

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Security Whitepaper

© 2026 ClinicalRIS Platform. All rights reserved. Precision Medical Informatics.

Multi-Region Enterprise Cloud PACS•High-Throughput Diagnostic AI Engine