Voxel Teleradiology
Legal Document

Privacy & Data Policy

How Voxel Teleradiology collects, uses, safeguards, and discloses information in the course of providing diagnostic radiology services to healthcare facilities and their patients.

Effective DateMarch 15, 2026
Last ReviewedMarch 15, 2026
Version3.2
JurisdictionIndia (HIPAA)
Compliance
HIPAA CompliantSOC 2 Type IIACR StandardsHL7 / DICOMBAA Ready21 CFR Part 11

Your privacy and the security of patient data are foundational to everything we do. This Privacy Policy applies to all services provided by Voxel Teleradiology, LLC and governs the handling of Protected Health Information (PHI), personal data, and technical information in accordance with the Health Insurance Portability and Accountability Act (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and all applicable state and federal regulations.

01

Information We Collect

Patient & Clinical Data

We collect medical imaging data (DICOM files, X-rays, CT scans, MRIs, and other radiological studies), patient demographic information, clinical history, and referring physician details as necessary to provide teleradiology interpretation services.

Account & Professional Information

For healthcare providers and partner facilities, we collect organizational details, professional credentials, contact information, and account authentication credentials to manage platform access.

Technical & Usage Data

We automatically collect log data, IP addresses, browser/device information, access timestamps, and platform interaction data to ensure system security, performance, and compliance with audit requirements.

02

How We Use Your Information

Delivering Radiology Services

Patient data and imaging studies are used exclusively to provide diagnostic radiology interpretations, generate reports, and communicate findings to the ordering provider.

Quality Assurance & Safety

We use de-identified or aggregated data to monitor diagnostic quality, conduct peer reviews, and continuously improve the accuracy and reliability of our radiologist network.

Regulatory Compliance

Information is processed as required to comply with HIPAA, applicable state medical practice laws, ACR standards, and other healthcare regulations governing teleradiology services.

Platform Operations

Technical data is used to authenticate users, maintain system integrity, prevent unauthorized access, troubleshoot issues, and fulfill our contractual obligations to partner facilities.

03

HIPAA Compliance & PHI

Business Associate Agreements

Voxel Teleradiology operates as a Business Associate under HIPAA. We execute Business Associate Agreements (BAAs) with all covered entity partners before any protected health information (PHI) is transmitted or processed.

Minimum Necessary Standard

We adhere strictly to the HIPAA Minimum Necessary Standard, ensuring that only the PHI required for the specific radiology service is accessed, used, or disclosed.

Breach Notification

In the event of a breach involving unsecured PHI, we will notify affected covered entities and individuals in accordance with the HIPAA Breach Notification Rule, within the timeframes mandated by law.

04

Data Sharing & Disclosure

Authorized Disclosures Only

We do not sell, rent, or trade patient data or PHI. Information is shared only with the referring facility, treating clinicians, and other parties explicitly authorized by the patient or required by law.

Subcontractors & Vendors

Any subcontractors or technology vendors who access PHI on our behalf are bound by HIPAA-compliant BAAs and are required to uphold the same privacy and security standards we maintain.

Legal Requirements

We may disclose information as required by valid legal process, court order, or to respond to lawful requests from public authorities in accordance with applicable law.

05

Data Security

Encryption

All medical imaging data and PHI are encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256 encryption. DICOM data is transmitted exclusively over secured, dedicated connections.

Access Controls

Role-based access controls (RBAC) and multi-factor authentication (MFA) are enforced across all platform access points. Access to PHI is logged, monitored, and limited to authorized personnel only.

Infrastructure & Auditing

Our infrastructure is hosted in HIPAA-eligible, SOC 2 Type II certified data centers. We conduct regular vulnerability assessments, penetration testing, and internal/external audits.

06

Data Retention

Retention Periods

Radiology reports and associated imaging studies are retained in accordance with applicable state and federal medical records laws, typically a minimum of seven (7) years from the date of service, or longer as required.

Secure Disposal

Upon expiration of applicable retention periods, PHI and related records are securely destroyed using methods that render the data unrecoverable, consistent with HIPAA requirements.

07

Patient Rights

Access & Amendment

Patients have the right to access their radiology reports and, where applicable, request amendments to their health information. Requests should be directed to the originating healthcare facility.

Accounting of Disclosures

Patients may request an accounting of disclosures of their PHI made by Voxel Teleradiology, as provided under HIPAA, by contacting our Privacy Officer.

Complaints

Patients who believe their privacy rights have been violated may file a complaint with their healthcare provider, with Voxel Teleradiology directly, or with the U.S. Department of Health and Human Services Office for Civil Rights.

08

Cookies & Tracking

Essential Cookies Only

The Voxel platform uses only essential session cookies required for secure authentication and platform operation. We do not use advertising trackers, third-party analytics cookies, or behavioral profiling technologies.

No Third-Party Advertising

We do not share platform usage data with advertisers or third-party marketing platforms. Our data practices are oriented solely around clinical service delivery and regulatory compliance.

09

Contact & Privacy Officer

Privacy Officer

For privacy-related inquiries, BAA requests, breach reporting, or to exercise your rights under HIPAA, please contact our designated Privacy Officer.

Contact Details

Email: privacy@voxelradiology.com Phone: 1-800-VOXEL-RX Mail: Voxel Teleradiology, Privacy Officer 1200 Imaging Way, Suite 400 San Francisco, CA 94105