Skip to content
MedScan v1.6 · DICOM
Privacy & Compliance

Why Your DICOM Viewer Should Work 100% Offline

Updated April 2026 · 5 min read

Many modern DICOM viewers require uploading medical images to cloud servers for viewing. While convenient, this approach raises serious privacy, compliance, and practical concerns. Here's why offline-first DICOM viewing should be the default.

The HIPAA Problem with Cloud Viewers

HIPAA (Health Insurance Portability and Accountability Act) regulates how Protected Health Information (PHI) is stored and transmitted. DICOM files are rich with PHI — patient name, date of birth, medical record number, referring physician, and the images themselves.

When you upload a DICOM file to a cloud viewer, you're transmitting PHI to a third-party server. This requires:

  • A Business Associate Agreement (BAA) with the cloud provider
  • Encryption in transit and at rest
  • Access controls and audit logging
  • Data retention and deletion policies
  • Breach notification procedures

Many free cloud DICOM viewers don't offer BAAs or meet these requirements. Using them with real patient data is a compliance risk.

The Practical Problem

Beyond compliance, cloud viewers have practical issues:

Upload time: A 500-slice CT study is 200-500 MB. Uploading on hospital WiFi can take minutes.
Internet dependency: Hospital basements, rural clinics, and airplanes have no reliable internet.
Data residency: Some jurisdictions require medical data to remain within national borders.
Server downtime: Cloud services have outages. Local processing never goes down.
Speed: Network latency adds seconds to every operation. Local processing is instant.

The MedScan Approach: Offline-First

MedScan was designed from the ground up for offline operation:

All DICOM parsing, rendering, and navigation happens locally on your device
No account registration — no user database to breach
No telemetry on medical images — only anonymous app usage analytics
Optional PACS import is the only network feature — and it talks only to your server

Cloud vs Offline: Quick Comparison

AspectCloud ViewersMedScan (Offline)
PHI transmittedYes — to cloudNo — stays on device
Works without internetNoYes
Upload requiredYes (minutes)No (instant open)
BAA requiredYesNot applicable
SpeedNetwork-dependent33ms cached reopen
Account requiredUsually yesNo

When Online is Acceptable

Offline-first doesn't mean never-online. The optional PACS/DICOMweb import needs a network connection to reach your own server — but that traffic goes directly between your device and your PACS. MedScan itself never uploads studies to any third-party cloud.

This hybrid approach — complete offline capability for viewing, with optional AI assistance — is the right balance for clinical workflows.

Ready to Try MedScan?

Free to download. View any DICOM file on iPhone & iPad. No account required.

Download Free on App Store