Is PetFusion Overnight Reads HIPAA-Compliant for PET/CT Teleradiology Workflows?

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Is PetFusion Overnight Reads HIPAA-Compliant for PET/CT Teleradiology Workflows?

Kevin Henry

HIPAA

August 03, 2026

8 minutes read
Share this article
Is PetFusion Overnight Reads HIPAA-Compliant for PET/CT Teleradiology Workflows?

Short answer: it depends on how PetFusion Overnight Reads is implemented and governed within your organization. HIPAA compliance is a shared responsibility across vendor capabilities and your internal policies, especially when handling Protected Health Information (PHI) in PET/CT teleradiology.

The sections below outline what you must validate across Business Associate obligations, radiologist credentialing, administrative and technical safeguards, critical results communication, and breach notification. Use them as a structured due-diligence framework to determine whether your PetFusion deployment can operate compliantly.

Business Associate Agreement Requirements

If PetFusion Overnight Reads creates, receives, maintains, or transmits PHI on your behalf, it functions as a Business Associate. A signed Business Associate Agreement (BAA) is therefore foundational to lawful data sharing and to setting enforceable security expectations.

Minimum BAA clauses to require

  • Permitted and required uses/disclosures of PHI, including minimum-necessary standards.
  • Administrative, physical, and technical safeguards aligned to the HIPAA Security Rule.
  • Obligation to report security incidents and suspected or confirmed breaches within a defined timeframe.
  • Flow-down requirements ensuring subcontractors who handle PHI also execute BAAs.
  • Right to access, amend, and obtain accounting of disclosures to support your HIPAA Privacy Rule duties.
  • Return or secure destruction of PHI at contract termination, with documented verification.
  • Right to audit or receive reasonable assurance reporting (e.g., SOC 2 Type II, HITRUST) without exposing PHI.

What to verify with PetFusion

  • Availability of a standard BAA that addresses Encryption in Transit and at rest, Access Controls, and Audit Logging.
  • Named breach-notification timeframes to you (e.g., “without unreasonable delay” and no later than a set number of days).
  • Subprocessor list and flow-down BAAs for any cloud, messaging, or analytics services involved.
  • Clear data-return/deletion timelines and key destruction procedures at offboarding.

Common pitfalls

  • Assuming a vendor is “HIPAA certified.” No official HIPAA certification exists; you need a BAA plus evidence of controls.
  • Omitting subcontractors from the BAA scope, leaving gaps in downstream protections.

Radiologist Licensing and Credentialing

Compliance also hinges on who reads the images. Radiologists must be licensed in the state where the patient is located at the time of service, and properly credentialed and privileged by the receiving facility or via credentialing by proxy where permitted.

Radiologist Credentialing essentials

  • Active, unencumbered state licenses for all patient states served (teleradiology often spans multiple jurisdictions).
  • Board certification and documented PET/CT competency per facility policy and payer expectations.
  • Primary-source verification, OIG/SAM exclusion checks, malpractice coverage, and ongoing performance monitoring.
  • Use of the Interstate Medical Licensure Compact (where applicable) to expedite multi-state licensing.

Operational considerations

  • Maintain an updated roster mapping radiologist licenses to patient-service states to prevent routing mismatches.
  • Ensure on-call schedules only assign cases to radiologists authorized for that state/facility.

Administrative Safeguards in Teleradiology

Administrative safeguards govern risk, workforce behavior, and vendor management—key for remote PET/CT workflows. Your policies must complement PetFusion’s controls to close the compliance loop.

Program-level controls

  • Enterprise risk analysis and documented risk management plans covering all teleradiology data flows.
  • Workforce training on PHI handling, minimum necessary, secure remote work, and sanctioned device use.
  • Access provisioning and deprovisioning procedures with least privilege and periodic recertifications.
  • Contingency planning: backups, disaster recovery, and emergency access procedures for image and report availability.
  • Vendor oversight: BAA governance, performance SLAs, and annual security due diligence.

Remote-reading safeguards

  • Approved devices only, with full-disk encryption, endpoint protection, and screen privacy measures.
  • Prohibition of local PHI downloads unless policy-approved with secure storage and timed deletion.

Technical Safeguards and Data Encryption

Technical safeguards operationalize security. Confirm that PetFusion’s platform and your environment enforce strong Access Controls, Encryption in Transit, encryption at rest, and comprehensive Audit Logging.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Access Controls

  • Unique user IDs, role-based access, and separation of duties for radiologists, technologists, and admins.
  • Multi-factor authentication by default, with conditional access for high-risk logins and remote sessions.
  • Automatic session timeouts, device lock, and emergency access procedures with audit trails.

Encryption in Transit and at rest

  • TLS 1.2+ for all web, API, DICOMweb, and messaging channels; VPN or zero-trust access for admin planes.
  • Strong encryption at rest (e.g., AES-256) for databases, object storage, backups, and message queues.
  • Secure key management with rotation, separation of duties, and restricted administrator access.

Audit Logging and monitoring

  • Immutable logs capturing user logins, image access, report edits, exports, and configuration changes.
  • Time-synchronized log aggregation with alerting on anomalous access patterns and failed logins.
  • Retention consistent with policy and legal requirements, plus documented log-review procedures.

Data lifecycle and interoperability

  • Secure DICOM transfer, HL7/FHIR interfaces with encryption, and de-identification tools for non-treatment use.
  • Configurable retention and purge schedules to meet minimum-necessary and data-minimization goals.

Critical Results Communication Procedures

For PET/CT, time-sensitive findings require closed-loop communication. Your policies and PetFusion’s workflow must ensure rapid, documented delivery to the responsible clinician.

Closed-loop communication essentials

  • Clear definitions of “critical,” “urgent,” and “unexpected” results with required timeframes for notification.
  • Direct, reliable channels (e.g., phone with read-back, secure messaging with explicit acknowledgment).
  • Escalation paths if the ordering provider is unreachable, including alternates and chain-of-command.
  • Documentation of who was reached, when, by what method, the message content, and acknowledgment received.
  • Routine QA audits of critical-results logs to validate timeliness and completeness.

Breach Notification and Reporting Protocols

When an incident involves unsecured PHI, the Breach Notification Rule requires timely action. Your BAA should specify how quickly PetFusion notifies you, so you can meet legal deadlines.

Core elements

  • Incident triage and risk assessment addressing the nature of PHI, unauthorized recipient, access/viewing likelihood, and mitigation.
  • Individual notices without unreasonable delay and no later than 60 days after discovery, using approved methods.
  • For incidents affecting 500+ individuals in a state/jurisdiction, concurrent notice to regulators and media as required; smaller incidents logged and reported annually as applicable.
  • Encryption “safe harbor”: if PHI was encrypted in line with recognized standards, breach notification may not be triggered.
  • Post-incident remediation, user re-education, and control hardening, with documented lessons learned.

Evaluating PetFusion Compliance Status

Use a deliberate evidence-based review to decide whether PetFusion Overnight Reads can operate compliantly in your PET/CT teleradiology program.

Evidence to request from PetFusion

  • Executed BAA and any security annexes covering Access Controls, Encryption in Transit/at rest, and Audit Logging.
  • Recent independent security attestations (e.g., SOC 2 Type II or equivalent), penetration-test summaries, and vulnerability management cadence.
  • Documented HIPAA risk analysis, risk treatment plans, incident response playbooks, and breach-notification procedures.
  • Subprocessor inventory with flow-down BAAs and data-flow diagrams for image routing and report delivery.
  • Operational runbooks for critical-results communication and proof of log retention/audit capabilities.

Configuration checklist on your side

  • Restrict user roles to minimum necessary and enforce MFA across all accounts and endpoints.
  • Harden remote-reading devices and disable local PHI storage unless explicitly authorized and encrypted.
  • Enable comprehensive access and activity logging; review logs routinely with documented sign-off.
  • Confirm radiologist licensing and Radiologist Credentialing per patient-state coverage before routing cases.
  • Test critical-results workflows and breach-response drills at least annually.

Conclusion

PetFusion Overnight Reads can participate in a HIPAA-compliant PET/CT teleradiology workflow if—and only if—you have a robust BAA in place, validate licensing and credentialing, and implement strong administrative and technical safeguards with verifiable logging and timely Breach Notification. Compliance is demonstrable through evidence, not assumptions; require documentation and test the controls regularly.

FAQs

What is required for HIPAA compliance in teleradiology?

You need a signed BAA with your teleradiology vendor, verified administrative safeguards (policies, training, risk management), strong technical safeguards (Access Controls, Encryption in Transit and at rest, Audit Logging), and documented workflows for image handling, critical-results communication, and incident response. Radiologist licensing and credentialing must align with patient-state requirements.

How does a Business Associate Agreement protect PHI?

A BAA contractually obligates the vendor to safeguard PHI, limit its use and disclosure, report incidents, bind subcontractors to equivalent protections, and return or destroy PHI at the end of the engagement. It also grants you oversight rights, helping you verify ongoing compliance.

Are radiologists required to be licensed in patient states?

Yes. In teleradiology, the interpreting radiologist must hold an active license in the state where the patient received care, and be properly credentialed or privileged by the facility (or through credentialing by proxy where allowed). Multi-state coverage often relies on expedited pathways but still requires state licensure.

What safeguards ensure secure PET/CT image transmission?

Use TLS 1.2+ for all transfers, enforce MFA and role-based Access Controls, encrypt data at rest, and maintain immutable Audit Logging of image access and report actions. Combine these with hardened endpoints, disciplined key management, and continuous monitoring to reduce risk across the full image lifecycle.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles