The Imaging Protocol Manager application helps to ensure confidentiality, integrity, and availability of customer data. To support adequate security for customer data, GE Healthcare has implemented required security measures at physical, network, and application levels of the application.
Physical & network level
The application will be hosted in a physically secured AWS (Amazon Web Services™) data center and GE Healthcare will monitor and deploy the application in a network security controlled environment. The configuration of network security components (i.e. firewall) is reviewed and configured by the GE Healthcare experts.
Application level
In accordance with its internal security standards, GE Healthcare has built all required security measures into the application.
Some of those specific measures are:
- Security risk assessment of the application
- Threat modeling and mitigation
- Encryption of the data at rest and in transit
- Strong authentication methods for every access
- Data integrity controls
- Audit trails for compliance purposes
- Specific security checks for protocol upload and download
GE Healthcare propriety and confidentiality
Imaging Protocol Manager only utilizes protocol configuration detail in conjunction with cloud-based services and applications to share settings. The data transmitted from the scanner includes scanner meta data, dependencies, and capabilities. No patient information (PHI) is being transmitted from scanner to the cloud.