Governance & security

Governed cardiac imaging tele-reporting

Clinical, data-transfer and retention arrangements are agreed with each partner institution before go-live.

Data transfer, reporting, escalation and retention are agreed site-by-site

Oxcardio works with partner institutions to agree a data-transfer, reporting, escalation and retention process before go-live. A site-specific data processing agreement and service specification can be provided during onboarding.

Discuss governance requirements

Documentation for your review

We can share service and data-protection documentation for your institution's governance review, including a data processing agreement.

What is relevant differs from site to site, so we discuss it with your team rather than working from a fixed list.

How onboarding runs

Each stage is agreed with your institution before clinical reporting begins.

  1. Introductory call Service scope, the modalities involved and the clinical contacts on both sides.
  2. Technical scoping Transfer options are scoped with your IT team and may include encrypted DICOM routing or VPN-supported pathways.
  3. Secure transfer setup Access control, retention and the site-specific data processing agreement are settled.
  4. Test cases and reporting Reporter credentials, signing responsibility and the escalation route for urgent findings are confirmed.
  5. Review and next steps Capacity, availability and cover are reviewed so commitments match the volume accepted.

What is agreed before reporting starts

  • Clinical responsibilityReporter credentials, signing responsibility, escalation contacts and reporting cover arrangements are confirmed before go-live.
  • Urgent findingsUnexpected or urgent findings need a clear route back to the local clinical team. Escalation expectations are agreed as part of the service specification.
  • DiscrepanciesClinical queries, addenda, discrepancy review and complaint handling are managed through an agreed institutional process.
  • Business continuityCapacity, availability and cover are discussed openly so reporting commitments match the agreed volume.
  • Secure transferTransfer options may include encrypted DICOM routing, VPN-supported pathways or other local IT-approved methods.
  • Access controlAccess to imaging data is limited to authorised reporting clinicians and the support required for the agreed service.
  • Data protectionUK GDPR/Data Protection Act considerations, international transfer requirements and local institutional policies are reviewed before go-live.
  • Retention and deletionRetention periods, report copies and deletion expectations are agreed with each partner institution and reflected in onboarding documentation.

Ask us about governance.

Tell us what your institution needs and we will share the relevant documentation directly.

Contact Oxcardio