ClinicalRIS by Claridad Health Solutions enforces stringent safeguards to protect Protected Health Information (PHI), DICOM diagnostic studies, and personal data across our cloud radiology platform.
Last Version Revision: January 15, 2026 | Effective Date: January 15, 2026
ClinicalRIS is an enterprise medical software platform operated by Claridad Health Solutions ("Claridad", "we", "us", or "our"). We provide Radiology Information Systems (RIS), Picture Archiving and Communication Systems (PACS), diagnostic reporting tools, and AI CAD integrations to hospitals, imaging centers, teleradiologists, and referring physicians.
This Privacy Policy describes how we handle information in compliance with global health privacy regulations, including the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, the General Data Protection Regulation (EU GDPR / UK GDPR), and applicable national medical data laws.
Depending on your interaction with ClinicalRIS, we process three distinct categories of data:
When healthcare providers upload DICOM images or generate diagnostic reports, we process PHI on behalf of the Covered Entity. This includes:
Information collected when healthcare staff create account credentials:
Automated system telemetry collected to maintain 99.99% uptime and security audit compliance:
Under HIPAA regulations, Claridad Health Solutions acts strictly as a Business Associate to healthcare providers ("Covered Entities").
For users and patients residing within the European Economic Area (EEA), United Kingdom, or jurisdictions with international privacy rights:
Request a copy of stored personal credentials and export DICOM instances in standard JSON/ZIP formats.
Correct inaccurate account records or professional license information via institutional center admins.
Request deletion of personal account data. Note: Clinical PHI retention is subject to statutory medical record retention laws (typically 7–10 years).
Restrict processing during legal disputes or verification of administrative accuracy.
ClinicalRIS implements defense-in-depth cryptographic controls across all infrastructure tiers:
We partner with Tier-IV compliant cloud providers to deliver cloud hosting, container orchestration, and AI inference. All sub-processors undergo rigorous SOC 2 Type II vendor audits and execute HIPAA BAAs:
| Sub-processor | Purpose | Location | Security Certification |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud Infrastructure & DICOM Object Storage | USA / EU Regions | ISO 27001, SOC 2 Type II, HIPAA Compliant |
| Google Cloud Platform (GCP) | AI CAD Inference & Backup Storage | USA / EU Regions | ISO 27001, SOC 2 Type II, HIPAA Compliant |
| Keycloak IAM Engine | Federated Identity & OAuth Authentication | Dedicated Isolated VPC | OpenID Certified, FIPS 140-2 |
Claridad Health Solutions maintains a dedicated Security Operations Center (SOC) monitoring platform telemetry 24/7. In the unlikely event of a confirmed security incident impacting PHI:
For privacy inquiries, BAA requests, or Data Subject Access Requests (DSAR), contact our compliance team: