Is RadPlan CT Simulation HIPAA-Compliant for Radiation Oncology Dosimetry Exports?

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Is RadPlan CT Simulation HIPAA-Compliant for Radiation Oncology Dosimetry Exports?

Kevin Henry

HIPAA

August 05, 2026

7 minutes read
Share this article
Is RadPlan CT Simulation HIPAA-Compliant for Radiation Oncology Dosimetry Exports?

Your central question—whether RadPlan CT Simulation is HIPAA-compliant for radiation oncology dosimetry exports—doesn’t have a one-word answer. HIPAA compliance is a program, not a product label. No vendor is officially “HIPAA-certified”; instead, you evaluate features, security controls, contractual commitments, and how you configure and operate the software. This guide helps you assess Protected Health Information (PHI) risks, required Data Privacy Safeguards, and practical steps to keep Radiation Therapy Data Security front and center. This material is informational and not legal advice.

Overview of RadPlan CT Simulation

CT simulation software in radiation oncology acquires and prepares image sets for treatment planning, contouring, and dose calculation. In routine use, it handles DICOM images and DICOM-RT objects—such as RTSTRUCT, RTPLAN, and RTDOSE—that can embed identifiers in headers and sometimes in pixel data (e.g., burned-in annotations). Those artifacts move downstream through Data Export Protocols to planning systems, QA tools, research databases, and collaborators.

Because these datasets often contain names, medical record numbers, study dates, and device identifiers, they constitute PHI. Any export, transfer, or disclosure—whether for clinical care, consulting, research, or vendor support—must be governed by HIPAA’s Privacy, Security, and Breach Notification Rules and your organization’s policies.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Key HIPAA Requirements for Radiation Oncology

Administrative safeguards

  • Conduct and document a risk analysis focused on CT simulation workflows and dosimetry exports, then implement risk management actions.
  • Establish policies for minimum necessary use, role definitions (dosimetrist, physicist, IT), and records of disclosures.
  • Execute Business Associate Agreements (BAAs) with any vendor or service provider that handles PHI.
  • Provide workforce training tailored to DICOM-RT objects and export scenarios.

Technical safeguards

  • Access controls: unique user IDs, least-privilege roles, and preferably MFA integrated with your SSO.
  • Audit controls: comprehensive HIPAA Audit Trails capturing user, action (e.g., export), patient/plan IDs, timestamps, destination, and success/failure.
  • Integrity and transmission security: hashing/signatures where feasible; TLS 1.2/1.3 for network transfers; PHI Encryption Standards (e.g., AES-256 with FIPS-validated modules) for data at rest and on removable media.
  • Automatic logoff and session timeouts on workstations in clinical areas.

Physical safeguards

  • Workstation security in sim rooms and planning suites; privacy screens as needed.
  • Device and media controls for USB drives, external disks, and CD/DVD burners; documented chain-of-custody.
  • Secure storage and verified destruction of exported media and temporary files.

Privacy and breach rules

Protecting PHI in Dosimetry Exports

De-identification and minimization

  • Use de-identification profiles that remove or pseudonymize direct identifiers in DICOM and DICOM-RT while preserving essential clinical context (e.g., dose grid, structure labels).
  • Address private tags and secondary captures; evaluate overlays and burned-in text in images.
  • When full de-identification would break downstream workflows, produce a limited data set with a Data Use Agreement and strong access controls.

Encryption and transfer controls

  • For in-transit security, use SFTP or HTTPS over TLS 1.2/1.3 within a VPN or trusted network segment.
  • For at-rest security, encrypt exports using PHI Encryption Standards (e.g., AES-256) with centralized key management; prefer hardware-encrypted drives when offline processing is required.
  • Package exports in tamper-evident archives; include checksums to verify integrity upon receipt.

Operational discipline

  • Standardize Data Export Protocols with approved destinations, naming conventions, and metadata templates.
  • Prevent ad hoc exports by restricting privileges and gating exceptions through a documented approval process.
  • Log, monitor, and periodically reconcile all exports against clinical or research requests.

Compliance Challenges and Risk Mitigation

  • Hidden PHI in headers and private tags: Validate de-identification against real-world sample sets; scan for sensitive tags before release.
  • Temporary files and caches: Configure secure temp locations, auto-clean on close, and encrypted local disks.
  • Removable media loss: Default to network transfers; when media is necessary, use hardware encryption and chain-of-custody forms.
  • Version drift: Lock configurations; test after upgrades; maintain change control for export templates.
  • Third-party collaboration: Use BAAs or DUAs; segregate research data; restrict re-disclosure.
  • Human error: Provide role-based training with radiation therapy–specific examples; perform periodic drills and spot audits.

Best Practices for Secure Data Handling

  • Define a pre-export decision tree: treatment, QA, education, or research—each with the minimum necessary rule.
  • Apply least-privilege access; require MFA for users who can export or de-identify datasets.
  • Standardize and lock de-identification presets; review structure nomenclature to avoid embedding identifiers.
  • Encrypt everywhere: databases, staging folders, exports, backups, and removable media.
  • Centralize logging; forward Audit Trails to a secure SIEM with time synchronization and alerting.
  • Maintain a retention schedule and secure destruction procedures for exported datasets.
  • Run periodic Compliance Risk Assessments covering people, process, and technology; track remediation to closure.

Role of Audit Trails and Offline Processing

Audit trail essentials

  • Capture who exported, what objects (patient, accession, RTPLAN/RTDOSE identifiers), when, from where, to which destination, and by which method.
  • Ensure logs are tamper-evident, retained per policy, and regularly reviewed with exception reporting.
  • Correlate application logs with OS, storage, and network logs to reconstruct the full chain of custody.

Offline processing: benefits, gaps, and controls

  • Benefits: smaller attack surface and resilience during network outages.
  • Gaps: higher risk of lost media, weaker centralized oversight, and delayed incident detection.
  • Controls: hardware-encrypted drives, signed exports, media check-in/out, locked storage, and verified secure deletion after import.

Evaluating Vendor Compliance Statements

What to ask the vendor

  • Willingness to sign a BAA and provide a security overview (encryption details, key management, access controls, patching cadence).
  • Evidence of a mature security program (e.g., SOC 2 Type II or comparable attestations), plus recent penetration test summaries and vulnerability management practices.
  • Specifics on HIPAA Audit Trails: event types captured, fields logged, retention options, and exportability to your SIEM.
  • DICOM de-identification capabilities, handling of private tags, and configurable templates aligned to clinical and research use cases.
  • Support for SSO/MFA, role-based access, secure defaults, and the ability to disable unneeded services and ports.

Compliance Risk Assessment

  • Map workflows end-to-end: acquisition → processing → export → transfer → storage → secondary use.
  • Score risks across confidentiality, integrity, availability, and traceability; consider both online and offline paths.
  • Document compensating controls and residual risks; obtain leadership sign-off before go-live.

Conclusion

RadPlan CT Simulation can support HIPAA-aligned operations when you combine strong platform controls with disciplined processes: enforce least privilege, standardize de-identification, encrypt in transit and at rest, maintain robust audit trails, and formalize BAAs. The decisive factor is your end-to-end governance of dosimetry exports—not a generic “HIPAA-compliant” label.

FAQs.

What makes dosimetry exports subject to HIPAA regulations?

Dosimetry exports typically contain PHI in DICOM and DICOM-RT headers—names, MRNs, dates—and sometimes in pixel data or overlays. Transferring those files to another system or party is a disclosure under HIPAA. Unless fully de-identified or otherwise permitted, such disclosures must follow the Privacy Rule’s minimum necessary standard and be secured under the Security Rule.

How can healthcare providers ensure RadPlan CT Simulation meets HIPAA standards?

Start with a documented risk analysis, then verify configuration and controls: enable strong authentication, restrict export privileges, standardize de-identification templates, and encrypt data at rest and in transit. Confirm detailed audit logging, test exports for residual identifiers, and execute a BAA with the vendor. Periodically review logs, retrain staff, and re-test after upgrades.

Are offline processing and audit trails sufficient for HIPAA compliance?

No. They are necessary components, but you also need administrative policies, physical safeguards, encryption, access controls, incident response, vendor oversight, and ongoing risk management. Offline workflows and rich logs reduce risk, yet compliance depends on the full set of HIPAA safeguards working together.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles