Security
Security and privacy by design
Security philosophy
No technology can guarantee that authorized users, compromised devices or screenshots will never expose information. FAHMS therefore uses defense-in-depth security controls to reduce risk and control access.
Controls in place
Identity & authentication
Email/password sign-in with password reset, session controls and audit records of sign-in events.
Authorization
Roles are checked by the database itself, not just the screen. Organization actions require explicit per-role permissions.
Case-level access
Clinical details are readable only by the case owner, assignee and people explicitly authorized for that case.
Encryption
Encryption in transit for all traffic. Studies, case details, reports, consultation questions and messages are encrypted in the browser before storage or transfer.
Temporary access, expiry & revocation
Consultation access is time-limited, ends automatically and can be revoked at any time by the requester.
Audit logs
Account, case and consultation events are recorded in activity histories without patient content.
Data minimization
DICOM files, pixels and measurements stay on your device. Notifications never contain patient details.
Organization controls
Member roles and per-role permissions; organization membership alone never grants clinical access.
Administrator limits
Administrative authority does not equal access to clinical information — administrators cannot read encrypted patient content.
Retention & deletion
Encrypted transfers are removed after delivery or expiry by a scheduled clean-up. Local cases stay under your control.
Incident response & backup
An incident-response and backup/recovery process covers account data. Local encrypted vaults are your responsibility to keep.
AI privacy
No AI features process clinical data today. Future AI features will be purpose-specific and minimize identifiers.
Patient data deserves a different level of protection.
Patient imaging
Processed locally in the browser; only encrypted, temporary copies are transferred.
Patient identifiers
Minimized, encrypted with clinical text, and never used in URLs, notifications or billing.
Clinical reports
Protected clinical information, kept in your encrypted local vault.
Professional profiles
Shown according to each person's visibility settings.
Operational data
Used for workflow, auditing and administration.
Security secrets
Passwords, encryption keys and credentials are protected separately; your transfer passphrase never leaves your device.
Public demonstrations on this website use fictional, synthetic data only.
Responsible disclosure
Security controls and compliance capabilities evolve as FAHMS develops. Organizations remain responsible for configuring FAHMS appropriately for their workflows and applicable legal and regulatory obligations. FAHMS does not currently claim HIPAA, GDPR or NDPR certification.
Start working from anywhere.
View. Analyze. Report. Collaborate.