Compliance

HIPAA Compliance Checklist for Imaging Centers

A practical, non-exhaustive checklist for imaging-specific HIPAA exposure — the places PHI actually leaks in a radiology environment.

General HIPAA checklists talk about access controls and encryption in the abstract. Imaging environments have their own, more specific exposure points — this is the checklist we actually walk through with clients.

Access & identity

  • PACS and RIS accounts tied to individual users, not shared logins.
  • Role-based access separating techs, radiologists, referring physicians, and administrative staff.
  • Automatic session timeout on viewing workstations, especially shared reading-room terminals.
  • Offboarding process that actually revokes PACS/VNA access on the day someone leaves.

Transmission & networking

  • DICOM traffic encrypted in transit between sites, not just relying on network isolation.
  • VPN or dedicated links for any modality or gateway communicating outside your firewall.
  • Business associate agreements in place with every vendor that touches PHI-bearing studies — including AI vendors and cloud storage providers.

De-identification & data sharing

  • A documented process for both header-level and pixel-level de-identification before any external data sharing.
  • Visual or OCR-based review of burned-in text on ultrasound, C-arm, and secondary-capture images before release.
  • An audit trail showing what was de-identified, when, and by what process — not just an assumption that "the export tool handles it."

Vendor & third-party risk

  • Security review completed for any AI vendor with access to live studies.
  • Clear data retention and deletion terms with cloud PACS or VNA providers.
  • Incident response plan that includes imaging systems specifically, not just the EHR.
This checklist is a starting point, not a substitute for a formal risk assessment. If any of these items raise a question you can't answer confidently, that's worth a closer look before an auditor — or a breach — finds it first.
Get in touch →