Before go-live
Data transfer, reporting, escalation and retention are agreed site-by-site
Oxcardio works with partner institutions to agree a data-transfer, reporting, escalation and retention process before go-live. A site-specific data processing agreement and service specification can be provided during onboarding.
Discuss governance requirementsAvailable on request
Documentation for your review
We can share service and data-protection documentation for your institution's governance review, including a data processing agreement.
What is relevant differs from site to site, so we discuss it with your team rather than working from a fixed list.
Onboarding
How onboarding runs
Each stage is agreed with your institution before clinical reporting begins.
- Introductory call Service scope, the modalities involved and the clinical contacts on both sides.
- Technical scoping Transfer options are scoped with your IT team and may include encrypted DICOM routing or VPN-supported pathways.
- Secure transfer setup Access control, retention and the site-specific data processing agreement are settled.
- Test cases and reporting Reporter credentials, signing responsibility and the escalation route for urgent findings are confirmed.
- Review and next steps Capacity, availability and cover are reviewed so commitments match the volume accepted.
Governance domains
What is agreed before reporting starts
Clinical
- Clinical responsibilityReporter credentials, signing responsibility, escalation contacts and reporting cover arrangements are confirmed before go-live.
- Urgent findingsUnexpected or urgent findings need a clear route back to the local clinical team. Escalation expectations are agreed as part of the service specification.
- DiscrepanciesClinical queries, addenda, discrepancy review and complaint handling are managed through an agreed institutional process.
- Business continuityCapacity, availability and cover are discussed openly so reporting commitments match the agreed volume.
Data and security
- Secure transferTransfer options may include encrypted DICOM routing, VPN-supported pathways or other local IT-approved methods.
- Access controlAccess to imaging data is limited to authorised reporting clinicians and the support required for the agreed service.
- Data protectionUK GDPR/Data Protection Act considerations, international transfer requirements and local institutional policies are reviewed before go-live.
- Retention and deletionRetention periods, report copies and deletion expectations are agreed with each partner institution and reflected in onboarding documentation.