Data Boundary
Plain-language explanation — June 16, 2026
What this page explains
This page describes what data NexaRad handles, what it does not handle, and what boundaries are enforced in the current demo and research platform. We wrote this in plain language so that radiologists, imaging center operators, researchers, and visitors can understand exactly where the platform stands.
No protected health information (PHI)
The NexaRad demo and research platform does not accept, store, or process PHI. PHI uploads are actively blocked. The platform checks uploaded DICOM files for PHI-like content and rejects files that appear to contain real patient identifiers, names, dates of birth, accession numbers, or other protected data elements.
All demo data is synthetic or properly de-identified. No real patient records are used in the demo environment. Any study, finding, or report shown in the demo is fabricated for demonstration purposes and does not correspond to a real patient.
What data we do collect
In the demo platform, we collect only what is needed to operate the application:
- Account information — email address, name, and organization role for login and access control.
- Session data — secure session cookies to keep you logged in. No tracking cookies or advertising identifiers.
- DICOM metadata — modality, body part, study description, and other non-identifying DICOM header fields from uploaded studies.
- Audit logs — records of application actions (upload, view, analysis, report edit, export) for security and traceability. These logs do not contain PHI.
- Feedback — any feedback or notes you voluntarily provide through the feedback form.
What data we do not collect
- Patient names, dates of birth, or medical record numbers.
- Real DICOM pixel data with patient identifiers embedded in headers or burned into images.
- Clinical history or indications from real patient records.
- Browser fingerprinting or device tracking.
- Third-party analytics or advertising data.
- Any data sold, shared, or rented to third parties for any purpose.
No clinical use
NexaRad is not a clinical diagnostic product. It is not FDA cleared or authorized. No clinical decisions should be made based on NexaRad outputs. The platform is designed for demonstration, research, and product evaluation only. See our Not for Clinical Use notice for full details.
No performance claims
NexaRad makes no claims about diagnostic accuracy, sensitivity, specificity, turnaround-time improvement, radiologist productivity, or patient outcomes. Any numbers, metrics, or confidence scores shown in the platform are research/demo illustrations. They have not been validated in a clinical study and should not be interpreted as evidence of clinical performance.
Where data is stored and how it is protected
Application data is stored on AWS with encryption at rest (AES-256 via AWS KMS) and encryption in transit (TLS 1.2+). The platform uses private networking, security groups with least-privilege access, and role-based access controls. Demo and research environments are separated from any future clinical environments. See our Security page for details.
Data deletion
Demo data is not permanent. The demo environment may be reset, reseeded, or deleted at any time as part of product development. If you need your account or uploaded content removed, contact [email protected].
When this might change
If NexaRad enters clinical evaluation or cleared clinical modes, the data boundary will change. PHI processing would require: an executed AWS Business Associate Agreement (BAA), customer BAAs where required, HIPAA-compliant infrastructure configuration, locked and validated model versions, approved operating procedures, completed security and compliance reviews, and applicable regulatory clearance or authorization. This page will be updated before any such change.
Questions
For questions about this data boundary or to report a concern, contact [email protected].
Demo / Research / Not for Clinical Use