What Medical Image Storage and Communication Means in a Connected Workflow
Medical image storage and communication describes how a health image moves electronically after it’s captured: a copy is kept somewhere (storage) and sent or displayed somewhere else (communication). A connected diagnostics workflow is any setup where these steps happen digitally instead of on paper or film, and understanding how each step is regulated helps you ask better questions before relying on one.
Myth Versus Reality: What Oversight Actually Covers
Federal guidance on this topic is narrower than many people assume. Here is what the primary sources actually say, compared with common assumptions.
- Myth: If an app stores or transmits a health image, the FDA has reviewed it as safe and accurate. Reality: The FDA’s 2022 guidance on medical device data systems states that it does not intend to enforce device requirements on hardware or software limited to electronically transferring, storing, converting the format of, or displaying medical device data and results, including images. Software that only performs those functions is explicitly treated as not meeting the definition of a device, which means it is not subject to the FDA’s device review process for that function.
- Myth: Once a health image or record has been sent to an app I chose, it stays protected the same way it was with my provider. Reality: According to HHS guidance on the HIPAA access right, once electronic protected health information is sent, at the individual’s direction, to an app that is not itself a covered entity or a business associate of one, HIPAA’s privacy and security protections no longer apply to what that app does with the information afterward.
- Myth: A provider can refuse to send my image to an app I’ve chosen if they’re worried about that app’s security. Reality: HHS guidance states that a covered entity generally cannot refuse to fulfill a patient’s request to route their electronic health information to a third-party app of their choosing, including one that doesn’t encrypt data at rest, as long as the information is producible in the format the app uses. Providers may, however, tell the patient about the risks before the transfer happens.
What “Not a Device” and “Not Covered by HIPAA” Actually Change
These two findings matter for different reasons. The device classification question is about safety and performance oversight — whether a system’s storage or transmission function had to clear an FDA review process. The HIPAA question is about who is legally accountable if the information is misused after it leaves your provider’s systems.
A tool can be completely legal and still fall outside both kinds of oversight for a specific function. That is not automatically a red flag on its own, but it is information you’re entitled to have before you decide how much to rely on it. If a platform is silent on both questions, treat that silence as a reason to ask directly rather than a reason to assume the answer is favorable.
Evidence Limits: What These Two Sources Do Not Tell You
Neither source answers every practical question, and it’s worth being clear about the gaps.
- The FDA guidance addresses regulatory enforcement posture for storage and communication functions. It does not evaluate the accuracy, quality, or clinical reliability of any specific product’s images.
- The HHS guidance addresses accountability under federal HIPAA rules. It does not describe any single app’s actual security practices, encryption strength, or data retention period — those vary by vendor and are not standardized by this guidance.
- Neither source covers state-level privacy laws, which can be stricter than HIPAA and apply in addition to it.
- Neither source tells you how long a specific platform keeps a copy of your image, or what happens to that copy if the company changes hands or shuts down. That information has to come from the platform’s own policy.
A Step-by-Step Worksheet Before You Rely on a Connected Image Workflow
Before you rely on a connected workflow to store or send a health image, work through these questions in order.
- Origin: Was this image captured by a device, or uploaded from an existing file? Does the platform state whether its storage or transmission function falls under the FDA carve-out described above?
- Storage and access: Who can access the stored copy, and does the platform say whether it is encrypted at rest? Is the company that operates the platform a HIPAA covered entity or business associate, or neither?
- Sharing: If the image is shared with a clinician or another app, does that recipient fall under HIPAA, or does the information leave HIPAA’s protection at that point? Was the sharing method something you specifically chose, or a default setting?
- Retention: Does the platform state how long it keeps the image, and whether you can request deletion? What happens to stored images if the service is discontinued?
- Clinical handoff: If the image is meant to inform a clinical decision, is there a documented point where responsibility for interpreting it transfers from you, or the app, to a licensed clinician?
If a platform cannot answer questions 2 through 5 in its own written policy, treat that as a gap to raise with the platform or your clinician directly — not as evidence one way or the other about safety.
A Note on Timing
None of this is a reason to delay care. If an image relates to a symptom that is worsening, painful, or concerning, contact a clinician or local emergency services first and sort out the storage and sharing questions afterward.
Frequently Asked Questions
Does FDA review every app that stores or sends medical images?
No. Under the FDA’s 2022 guidance, software limited to transferring, storing, converting the format of, or displaying medical images and data is treated as not meeting the definition of a medical device, so it does not go through the FDA’s device review process for that function.
Is my health image still protected once I send it to a third-party app?
It depends on the app’s relationship to your provider. If the app is not a HIPAA covered entity or business associate, HHS guidance states that HIPAA’s protections no longer apply to that app’s use of the information once you’ve directed it there.
Can my provider block a transfer to an app I’ve chosen for security reasons?
Generally no. HHS guidance states a covered entity cannot refuse a patient’s request to route their data to an app of their choosing solely over security concerns, though the provider can first tell the patient about the risks involved.
Sources and Limits of This Guide
This article draws on two federal primary sources: the FDA’s September 2022 final guidance, Medical Device Data Systems, Medical Image Storage Devices, and Medical Image Communications Devices, and HHS guidance on the HIPAA access right as it applies to health apps and APIs. It translates their stated positions into questions you can ask; it does not evaluate any specific product, app, or provider, and it is not legal or medical advice. For background on how we select and read sources like these, see How We Research. If you’re new to this publication, Start Here explains what we cover and don’t cover. Our full medical information disclaimer applies to everything on this site, and our independence and domain-history notice explains this publication’s relationship to the former CellScope company.
This article is for general education about medical image storage and communication oversight. It is not medical advice and does not diagnose, treat, or provide clinical guidance. It is not legal advice about your specific privacy rights, which can vary by state and situation. Connected Diagnostics Evidence is an independent editorial publication and is not affiliated with, and does not speak on behalf of, the former CellScope company or any device manufacturer, telehealth platform, or app named or implied here.
By Connected Diagnostics Evidence Editorial Team. Last updated September 9, 2026.
Leave a Reply