Trust Center

Security & Compliance

RadPal handles clinical report text with care. We operate as a HIPAA Business Associate, maintain signed agreements with every vendor in our data chain, and run on HIPAA-designated infrastructure. This page is written for the IT and security teams evaluating RadPal.

At a glance

Signed BAAs

Business Associate Agreements with every subprocessor that touches PHI.

HIPAA infrastructure

HIPAA-designated cloud with PITR, SSL enforcement, and network restrictions.

Encrypted end to end at rest & in transit

TLS 1.2+ in transit, AES-256 at rest, on all stored data.

US data residency

All customer data stored in AWS us-east (Ohio, USA). Nothing stored offshore.

PHI minimization

Always-on redaction of patient identifiers before AI processing or storage.

No tracking

No analytics, advertising, or third-party tracking SDKs in the application.

How data flows

Only the radiologist's dictated report text is processed. RadPal never accesses images, orders, PACS, RIS, or EHR systems, and ingests no patient demographics.

Radiologist workstation
Identifier scrubbing (always on)
TLS 1.2+
RadPal cloud (AES-256 at rest, US)
AI providers under BAA

PHI minimization

Before any text reaches an AI provider or is stored, RadPal applies automatic, always-on redaction of patient identifiers — including labeled patient names, dates of birth, medical record, account, and accession numbers, ages 90 and over, and identifier-like tokens. This redaction cannot be disabled by end users. It is a safeguard rather than a guarantee of de-identification, and works alongside our BAAs as defense-in-depth. Clinical text is never used to train AI models.

Security controls

Data protection

  • TLS 1.2+ for all data in transit; AES-256 encryption at rest.
  • PostgreSQL row-level security: every user can read only their own report history.
  • Point-in-time recovery, SSL enforcement, and network restrictions enabled on production.
  • Database connection logging enabled for audit evidence.

Access control

  • Multi-factor authentication enforced on all administrative and infrastructure accounts.
  • Service-role credentials confined to server-side functions — never shipped in the client app.
  • AI prompt logic resolved server-side, so credentials and proprietary rules never reach client devices.
  • Least-privilege access, reviewed periodically by the Security Officer.

Application security

  • Signed Windows executables with verified auto-updates.
  • Serverless AI proxy that persists no prompt or response content.
  • Risk-minimizing release process: feature flags, kill switches, deploy-then-verify.
  • Changes to PHI-handling paths reviewed against an internal PHI checklist before release.

Monitoring & response

  • Immutable audit logs for PHI-relevant and security events.
  • Documented Incident Response & Breach Notification Procedure.
  • Continuous cloud security-posture monitoring with drift alerts.
  • Breach notification without unreasonable delay, no later than 60 days of discovery.

Subprocessors & agreements

Every subprocessor that processes PHI operates under an executed Business Associate Agreement.

ProviderPurposeStatus
AI language providersAI text generationUS-based · HIPAA BAA · no model training · retention restricted by BAA · specific vendors disclosed under NDA
Supabase (on AWS)Database & authenticationBAA signed · HIPAA add-on · SOC 2 Type 2
VercelWebsite hostingNo PHI processed · SOC 2 Type 2
StripePayment processingNo PHI processed · PCI DSS

Governance & policies

  • Documented Information Security Policy, Incident Response & Breach Notification Procedure, and Business Continuity / Disaster Recovery Plan, reviewed at least annually.
  • Designated Security Officer accountable for security, incident response, and vendor management.
  • Workforce confidentiality agreements, security-awareness training, and a disciplinary policy for violations.
  • Documented change management and third-party (subprocessor) risk management.
  • Immutable audit logs; six-year retention of security and incident records.

Compliance posture

RadPal operates as a HIPAA Business Associate and executes BAAs with covered-entity customers on request. All infrastructure runs on SOC 2 Type 2 certified providers (Supabase / AWS, Vercel) in US regions; RadPal inherits their physical and platform controls and layers its own application, access, and PHI-handling controls on top. RadPal itself is not separately SOC 2 audited. Subprocessor SOC 2 reports, our security policies, and architecture / data-flow documentation are available to your team under NDA.

For your IT & security team

We complete vendor security questionnaires and risk assessments on request.
We execute your institution's BAA, or provide our standard BAA for review.
Security policies, subprocessor SOC 2 reports, and data-flow diagrams available under NDA.
We support your vendor-review and application allow-listing process end to end.

RadPal is a documentation productivity tool for radiologists. It is not a medical device, does not render diagnoses, and every report is reviewed and signed by the interpreting radiologist.