Skip to main content
HubNex
Solution Benefits How It Works Integration & Trust About Talk to our team

Integration & Trust

Built to work with your systems, and to be checked

What connects, what is protected, and what is still to come.

Contents

Your existing systems The Edge Agent What setting up a collaboration involves Where data is processed and stored Security controls Certifications and independent testing Responsibilities and support

1 Your existing systems

HubNex connects to the radiology systems your hospital already runs rather than replacing them. It works through standard interfaces: DICOM for images, HL7 for orders, and, where a hospital chooses to configure it, FHIR for clinical context.

  • PACS: images and viewing stay in your PACS.
  • RIS: requests and worklists stay in your RIS.
  • Reporting: radiologists keep using the tools they use today; the finished report returns through the agreed workflow.

Compatibility is confirmed with each hospital's own PACS and RIS during onboarding. Support for a standard does not by itself mean every product has been tested, and we do not display vendor logos without a verified relationship.

2 The Edge Agent

An Edge Agent runs inside each participating hospital's network and handles both sending and receiving of studies.

  • It opens outbound connections only. No inbound firewall ports are opened on the hospital side.
  • It is authenticated to the platform over TLS 1.3, with mutual TLS (mTLS) in production deployments.
  • It can pseudonymise studies before they leave the hospital network.
  • Hospital IT controls where it is placed, its network egress rules and which modalities it accepts.
  • If connectivity is lost, it keeps studies in an encrypted buffer and forwards them when the connection returns.

3 What setting up a collaboration involves

"Without replacing your systems" does not mean no work. Setup involves installing and configuring the Edge Agent, connecting it to your PACS and RIS, agreeing routing rules and participation with the other hospitals, and completing your own security and data-protection review. Scope, responsibilities and timeline are agreed with each hospital during onboarding.

Pilots progress in stages, each gated by the hospital's sign-off: first synthetic data to validate integration and workflow, then pseudonymised data, and real patient data only after an independent penetration test and pre-go-live hardening are complete.

4 Where data is processed and stored

  • Region: the platform is hosted in the EU with an ISO 27001-certified infrastructure provider (Germany or Finland during the pilot). The provider's certification belongs to the provider, not to HubNex.
  • Studies: studies shared for reading are transferred from the sending hospital's Edge Agent to the HubNex platform, encrypted in transit and at rest.
  • Minimal data: HubNex extracts and retains only what is needed to route a study and return a report. Clinical context from a hospital is reduced to an age band, gender, priority and a coded indication; names and dates of birth are not shared.
  • Retention: patient data is kept for the pilot period and deleted within 30 days of its end.

5 Security controls

  • Encryption in transit: TLS 1.3 on every connection to the platform; DICOM TLS between the hospital PACS and the Edge Agent.
  • Encryption at rest: AES-256 on an encrypted volume holding all application data. The unlock passphrases are held by HubNex, not by the hosting provider. Backups are encrypted separately.
  • Access: role-based and least-privilege. Multi-factor authentication is required for administrators. In the pilot, each hospital manages its own clinical users within its existing PACS and identity systems.
  • Audit: authentication and authorisation events and actions on studies are recorded in append-only audit logs.
  • Network: a single public entry point, default-deny firewall and rate limiting. Hospital IT can restrict platform access to its own network ranges.

6 Certifications and independent testing

We separate what has been achieved from what is planned.

  • Available now: a GDPR Article 28 data processing agreement and a DPIA support package for your DPO. A security white paper and security Q&A are available on request.
  • Planned: an independent penetration test before any pilot with real patient data, repeated at least annually.
  • Targeted: ISO 27001 certification of HubNex itself. This has not yet been achieved.
  • Regulatory: HubNex does not currently claim medical-device certification; MDR Class IIa is planned for a later phase.

Regulatory requirements depend on the country and the workflow, and are assessed with each hospital rather than assumed.

7 Responsibilities and support

Hospitals remain responsible for their own systems, users, clinical decisions and the agreements between participating hospitals. HubNex is responsible for the platform. Support and service levels for the pilot are set out in the pilot agreement. Security researchers can report findings to security@hubnex.net.

Talk to our team
HubNex
Integration & Trust About Privacy Policy Legal Notice Terms of Service

© 2026 HubNex. All rights reserved.

HubNex is currently in the pilot development phase. Inquire for early access.