Help centerCommon topicsPrivacy, PHI protection, and ZDR

Privacy, PHI protection, and ZDR

RadAIChat provides privacy controls for images, prompts, provider retention, shared cases, and chat history. You remain responsible for following your organization’s policies and applicable requirements.

How images are handled

  • DICOM files are parsed locally in your browser. DICOM headers and PHI metadata are not uploaded.
  • Only images you explicitly select are uploaded for the case.
  • Uploaded non-DICOM images are stripped of metadata and handled securely.

Learn more about selecting DICOM content in Work with DICOM studies.

Text PHI guardrail

RadAIChat can check prompt text for patient-identifying information before it is sent to AI models. If a prompt is blocked, remove identifying details and send it again.

You can manage the text guardrail under Settings → Privacy → PHI guardrails. Turning it off makes you fully responsible for preventing PHI from being sent. The confirmation dialog explains the risk before the setting changes.

Enforce zero data retention

Open Settings → Privacy → Enforce ZDR to require models for which RadAIChat can request zero data retention from the provider.

When Enforce ZDR is on:

  • Models without ZDR support are unavailable or show a warning.
  • Replace an incompatible model before sending the case.
  • Current compatibility is shown on the Models page.

If you turn Enforce ZDR off, a provider may store or review prompts, images, and other request data according to its own policies. RadAIChat asks for ZDR whenever a model supports it, even when enforcement is off.

Chat-history retention

Under Settings → Privacy → Data retention, choose how long RadAIChat keeps chat history before automatically removing it. Available choices are 7, 30, or 90 days, or indefinite retention.

Review the Privacy Policy for the complete policy.