Compliance Tool HIPAA Compliant SOC 2

Automatic DICOM Deidentification

Removes both burnt-in and DICOM metadata PHI. Compliant with Part 15 of the DICOM standard, HIPAA, and SOC 2 Type 2 — built for secure research, AI training, and external data sharing.

BEFORE — PHI PRESENT DOE, JANE MRN 428-3172-B DOB 04-18-1962 Study 2410-DU7713 · 14:32:07 DEID AFTER — DEIDENTIFIED BURNT-IN + METADATA PHI REMOVAL

What it does.

Every DICOM file contains personal health information (PHI) in two distinct locations: structured metadata tags (patient name, MRN, date of birth, referring physician, institution, and so on) and burnt-in annotations — pixel-level overlays written directly onto the image by the scanner's acquisition software. Removing only one layer is insufficient. InVision's Automatic DICOM Deidentification pipeline handles both.

The tool is built for secure research data sharing, external AI training datasets, and multi-site collaborations where regulatory compliance is non-negotiable. It is compliant with Part 15 of the DICOM Digital Imaging and Communications in Medicine standard, HIPAA, and SOC 2 Type 2 — the same compliance framework that underpins InVision's clinical AI products.

Deidentification runs as a fully automated step on studies leaving your clinical environment, with no manual review required. Clinical imaging data — chamber outlines, ultrasound cones, Doppler overlays — is preserved in full fidelity. Only the PHI is removed.

2
Layers of PHI removed — structured DICOM metadata and burnt-in pixel annotations
Part 15
DICOM Digital Imaging and Communications in Medicine standard compliance
100%
Automated — no manual review required for routine echocardiographic studies

Four layers of protection.

Burnt-in PHI
Removes pixel-level annotations that scanner software writes directly into the image — patient name, MRN, date of birth, study timestamp, and institutional headers.
01
DICOM metadata
Strips structured metadata fields across all applicable DICOM tags, including nested private tags that other tools commonly miss.
02
DICOM Part 15
Compliant with Part 15 of the DICOM Digital Imaging and Communications in Medicine standard — the canonical specification for security and system management profiles.
03
HIPAA · SOC 2
HIPAA Compliant and SOC 2 Type 2 Compliant — aligned with the same security posture applied to InVision's FDA-cleared clinical products.
04

Built for secure workflows.

Purpose
Automatic deidentification of DICOM imaging studies for research, AI training, and external data sharing
Input
Standard DICOM studies (echocardiography and related modalities)
PHI scope
Both burnt-in pixel annotations and structured metadata PHI fields
Standards
DICOM Part 15 · HIPAA · SOC 2 Type 2
Clinical fidelity
Preserves all clinical imaging content — chamber outlines, Doppler overlays, measurement annotations unchanged
Automation
Fully automated pipeline · No manual review required

Example deidentified DICOMs.

Illustrative examples of echocardiographic studies processed through the automatic deidentification pipeline. These visuals represent how clinical imaging can be preserved while structured metadata and burnt-in PHI are removed.

Removing annotations baked into pixels.

Burnt-in annotations — patient name, MRN, study date, and institutional headers written directly into the image by the scanner — cannot be removed by metadata scrubbing alone. These illustrative crops show representative pixel-level redaction while preserving surrounding clinical context.