Security

Security and privacy by design

Designed with privacy and security principles appropriate for sensitive healthcare workflows.

Security philosophy

FAHMS is designed with a local-first privacy architecture, minimizing unnecessary centralized storage of patient imaging data while providing controlled access, encryption and auditability.
No technology can guarantee that authorized users, compromised devices or screenshots will never expose information. FAHMS therefore uses defense-in-depth security controls to reduce risk and control access.

Controls in place

Identity & authentication

Email/password sign-in with password reset, session controls and audit records of sign-in events.

Authorization

Roles are checked by the database itself, not just the screen. Organization actions require explicit per-role permissions.

Case-level access

Clinical details are readable only by the case owner, assignee and people explicitly authorized for that case.

Encryption

Encryption in transit for all traffic. Studies, case details, reports, consultation questions and messages are encrypted in the browser before storage or transfer.

Temporary access, expiry & revocation

Consultation access is time-limited, ends automatically and can be revoked at any time by the requester.

Audit logs

Account, case and consultation events are recorded in activity histories without patient content.

Data minimization

DICOM files, pixels and measurements stay on your device. Notifications never contain patient details.

Organization controls

Member roles and per-role permissions; organization membership alone never grants clinical access.

Administrator limits

Administrative authority does not equal access to clinical information — administrators cannot read encrypted patient content.

Retention & deletion

Encrypted transfers are removed after delivery or expiry by a scheduled clean-up. Local cases stay under your control.

Incident response & backup

An incident-response and backup/recovery process covers account data. Local encrypted vaults are your responsibility to keep.

AI privacy

No AI features process clinical data today. Future AI features will be purpose-specific and minimize identifiers.

Patient data deserves a different level of protection.

Patient imaging

Processed locally in the browser; only encrypted, temporary copies are transferred.

Patient identifiers

Minimized, encrypted with clinical text, and never used in URLs, notifications or billing.

Clinical reports

Protected clinical information, kept in your encrypted local vault.

Professional profiles

Shown according to each person's visibility settings.

Operational data

Used for workflow, auditing and administration.

Security secrets

Passwords, encryption keys and credentials are protected separately; your transfer passphrase never leaves your device.

Public demonstrations on this website use fictional, synthetic data only.

Responsible disclosure

Found a security issue? Please contact supportdicom@fahteldigitalhub.com with details. Do not access other users' data while testing.

Security controls and compliance capabilities evolve as FAHMS develops. Organizations remain responsible for configuring FAHMS appropriately for their workflows and applicable legal and regulatory obligations. FAHMS does not currently claim HIPAA, GDPR or NDPR certification.

Start working from anywhere.

View. Analyze. Report. Collaborate.