๐Ÿ”’ Security ยท Privacy ยท Compliance

Built for clinical trust.
Designed for enterprise scale.

IOLDx Clinical is architected with a privacy-first, local-data model โ€” with a clear roadmap to HIPAA-compliant cloud infrastructure for enterprise deployment.

โœ“
Data Privacy
No PHI transmitted
All session data processed locally in browser. No patient data sent to external servers.
โš 
HIPAA Compliance
Local-only ยท BAA on request
Current build: no PHI transmitted. Enterprise HIPAA-BAA available for institutional deployment.
โ„น
FDA Classification
Non-device CDS
Clinical decision support tool under 21st Century Cures Act. Not subject to 510(k) clearance.
01 โ€” Data Architecture & Privacy

Nothing leaves
the browser.

IOLDx Clinical is deployed as a client-side web application hosted on AWS CloudFront/S3. This is an intentional architectural decision for the early-access phase.

No patient data leaves the browser. Biometric inputs are processed entirely in JavaScript on the user's device.
No backend database. Session outcomes are stored in localStorage โ€” scoped to the user's browser, never transmitted.
No user accounts required. No login means no identity data collected.
Claude Vision API is used only for biometer image parsing. Images are sent via a Lambda proxy โ€” not stored or logged.

A surgeon entering AL=24.2mm and K=44.5D generates no identifiable health information. IOLDx Clinical does not collect names, DOB, MRN, or any PHI as defined under HIPAA.

Data Storage
Browser localStorage only
โœ“ No server-side storage
Data Transmission
Biometer images โ†’ Lambda โ†’ Claude API (optional)
โš  Images not retained
CDN / Hosting
AWS CloudFront + S3
โœ“ HTTPS enforced, TLS 1.2+
Analytics
Google Analytics 4 (page views only)
โœ“ No PII collected
02 โ€” FDA Regulatory Classification

Non-device CDS
under the 21st Century Cures Act.

IOLDx Clinical is a clinical decision support (CDS) tool intended for use by licensed ophthalmic surgeons. Under the 21st Century Cures Act and FDA's 2019 CDS guidance, software that meets the following criteria is classified as non-device CDS and does not require 510(k) clearance:

Not intended to replace clinical judgment
Displays the basis for its recommendations so clinicians can independently review
Used by qualified healthcare professionals

Current intended use: IOLDx Clinical assists qualified ophthalmic surgeons in reviewing published defocus curve data and calculating estimated IOL power targets. All outputs must be independently verified by the treating surgeon before clinical use.

RegulationApplicabilityStatus
FDA 510(k) Medical DeviceNon-device CDS โ€” does not replace clinical judgmentExempt
FDA CDS Guidance (2019)Displays basis for recommendations; used by qualified professionalsCompliant
FDA 21 CFR Part 11Applies to records submitted to FDA. IOLDx does not submit records.N/A
HIPAA Privacy RuleNo PHI collected or transmitted in current deploymentN/A (v1)
HIPAA Security RuleRequired for enterprise cloud deployment with stored PHIRoadmap
SOC 2 Type IIRequired for enterprise SaaS with institutional contractsRoadmap
GDPR (EU)No personal data collected from EU users in current deploymentCompliant (v1)
03 โ€” Cloud Architecture Roadmap

Lightweight today.
Enterprise-ready tomorrow.

The current deployment is intentionally lightweight for early validation. The enterprise architecture roadmap is designed to support acquisition-level scale.

Current โ€” v1 Early Access
AWS CloudFront + S3 CDN
AWS Lambda API proxy
Flutter Web (IOL Planner); standard HTML/JS (all other pages)
Client-side only โ€” no database
No user accounts
localStorage only
Enterprise Roadmap โ€” v2
Supabase / PostgreSQL cloud DB
Auth0 / Supabase Auth (SSO-ready)
HIPAA BAA with cloud provider
Role-based access (surgeon/admin)
Practice-level outcomes dashboard
HL7 FHIR export capability

For Alcon enterprise integration: IOLDx Clinical's Flutter Web architecture supports direct embedding into existing web portals. The API layer is designed for ARGOS/Lenstar CSV import and could be extended to support SMARTCataract or NGENUITY data export. Timeline: 60โ€“90 days for enterprise API integration post-agreement.

04 โ€” Clinical Data Sources & Methodology

FDA SSED data.
Peer-reviewed where SSED unavailable.

All defocus curve data used in IOLDx Clinical is sourced from publicly available regulatory submissions and peer-reviewed literature. No proprietary or confidential manufacturer data is used.

IOLData SourceType
Clareon PanOptix (TFNT00)FDA SSED PMA P930014/S131FDA SSED
Clareon Vivity (DFT015/DFW015)FDA SSED PMA P930014/S152FDA SSED
AcrySof IQ MonofocalFDA SSED PMA P930014FDA SSED
Clareon MonofocalFDA SSED PMA P930014/S148FDA SSED
TECNIS Symfony (ZXR00)FDA SSED PMA P060040/S050FDA SSED
TECNIS Synergy (DFR00V)FDA SSED PMA P060040/S079FDA SSED
IC-8 AptheraFDA SSED PMA P200037FDA SSED
Additional IOLs (6)Peer-reviewed literature + manufacturer dataGenerated

For IOLs without publicly available FDA SSED defocus curve data, curves are generated using published clinical study mean logMAR values at standard defocus steps. These are clearly labeled "Generated" in the interface.

05 โ€” Enterprise Inquiries

Ready to discuss
institutional licensing.

For enterprise deployment, institutional licensing, HIPAA Business Associate Agreement (BAA), or Alcon integration discussions:

Get in touch

Available documentation includes Intended Use Statement, Data Flow Diagram, source code (on request), BAA template, and SOC 2 readiness assessment.

Developer
Balamurali Vasudevan, BSOptom, PhD, MBA
Role
Optometrist & Clinical Technologist