Skip to main content
Connect your PACS and imaging modalities to Stenoa using standard DICOM connectivity.

Overview

The Stenoa DICOM Gateway connects your hospital’s imaging systems to Stenoa’s platforms. It runs as a self-contained virtual appliance entirely within your own virtualization environment, and integrates with your PACS and modalities over standard DICOM (DIMSE). No new web-facing services are required. The gateway operates on a least-connectivity model, and all communication with Stenoa’s cloud is encrypted. Only imaging studies that match a configured intake rule or that a clinician retrieves on demand leave your hospital.

How it works

The solution has two principal components:
  1. Stenoa DICOM Gateway: A DICOM server delivered as a virtual appliance (OVA) and deployed on your hospital-managed hypervisor. One gateway can be deployed per site, or at the Network level.
  2. Stenoa Cloud: Imaging is stored and served using AWS HealthImaging, a HIPAA-eligible service. Case management, clinical alerting, and the Stenoa web and mobile viewer are hosted in Stenoa’s cloud environment.

Data flow

  1. Acquisition. A modality or PACS at your hospital generates a study.
  2. Ingest. Your PACS or modalities push studies to the gateway via standard DICOM (C-STORE). For manually created Cases, the gateway can instead retrieve a specific study on demand from the source PACS (C-FIND/C-MOVE).
  3. Rule-based filtering. The gateway evaluates each study against your configured intake rules (modality, study description, body part). Only matching or manually retrieved studies are retained; non-matching studies are discarded and never persisted or transmitted.
  4. Encrypted egress. Matched studies are transmitted outbound to Stenoa’s cloud over HTTPS (TLS 1.2+). The connection is always gateway-initiated. The cloud never connects into the gateway.
  5. Cloud storage. Studies are stored in AWS HealthImaging, encrypted at rest.
  6. Case creation and alerting. A matched study triggers Case creation in the configured Flow and notifies the care team.
  7. Clinical viewing. Clinicians view studies in the Stenoa web and mobile viewer via authenticated, encrypted web APIs.

Security and data protection

Secure internet access

All cloud traffic is encrypted and limited to Stenoa and AWS service endpoints.

Data minimization

Only studies matching your intake rules, or manually retrieved by a clinician, leave the hospital. Everything else is discarded at the gateway and never transmitted or stored in the cloud.

Encryption in transit

All traffic between the gateway and Stenoa’s cloud is encrypted with TLS 1.2+. DICOM traffic between your PACS/modalities and the gateway remains on your internal clinical network.

Encryption at rest

Imaging is stored in AWS HealthImaging, a HIPAA-eligible service operated under a signed Business Associate Addendum (BAA), and encrypted at rest using AWS Key Management Service (KMS).

Access control

  • Application access: Clinicians access the Stenoa web and mobile applications via SSO and multi-factor authentication. See Sign-in methods.
  • Cloud access: Imaging access is authenticated and follows least-privilege principles.
  • Gateway management: Administrative access to the appliance is restricted to your hospital’s private network and follows least-privilege, key-based authentication practices.

Auditability

The gateway logs each received study and its intake decision (matched and retained, or discarded), including the matching rule and reason. Logs are continuously forwarded to Stenoa’s cloud and are accessible to authorized users through the Stenoa web application. This provides a centralized, tamper-evident audit trail retained independently of the appliance. Retention periods are configurable to align with your regulatory and record-keeping requirements.

Deployment

The gateway is delivered as an OVA for deployment on your own hypervisor. Minimum virtual machine specifications: Stenoa maintains the appliance and its operating system, and updates them remotely as needed (including security patches) over the same encrypted outbound channel used for cloud communication. No on-site or inbound access is required. Intake rules are managed centrally: authorized users can create or update them at any time through the Stenoa web application, and changes take effect on the gateway without on-site access. To deploy the DICOM Gateway at your site, contact your Account Manager. For security or privacy inquiries, reach out to legal@stenoa.com. For more on Stenoa’s governance and compliance program, see Security posture.