User's Manual

Vave Personal Ultrasound • USER MANUAL
12
CONFIDENTIAL & PROPRIETARY. CAUTION — Investigational device. Limited by Federal law to investigational use. Not commercially available in the US.
Encryption
The Vave App automatically encrypts information and images contained within the Vave App. For additional
protection, we recommend enabling device encryption to help ensure all data stored on the system is protected
and increase the strength of your access-control, rendering data unrecoverable by unauthorized users.
Physical Device Control
You and your healthcare organization should control and limit physical access to the Vave Phased Array Probe to
prevent accidental, casual, or deliberate contact by unauthorized individuals.
Report any loss of theft of your Vave Ultrasound Probe or Mobile device to your security and/or privacy ocer.
Visual Access Control
Minimize unauthorized visual access to protected patient information by maintaining awareness of where the device
is being used, positioning the device to prevent viewing from over-the-shoulder, through doorways, hallways, and
other trac areas.
Image Export, Transmission, and Upload
Normal operation of the device operates over the secure/encrypted dedicated Wi-Fi network between the mobile
device and Vave Phased Array Probe and Vave App encrypted data store.
Exported data will be saved to the local “camera roll” of the device and is no longer protected by Vave App
credentials. Exported data is de-identified to minimize the risk of data breach.
Exported images may also be shared or emailed via your local institution Wi-Fi network, cellular network, text/SMS,
or other public Wi-Fi network. Follow your institutions policy on the proper and approved use of institution email,
personal email services and text/SMS when attempting to export or share data from the Vave Ultrasound Device.
Warning: Personal email services, text/SMS, and untrusted Wi-Fi networks may not be secure and could compromise
patient privacy.
!
Caution: Any individual with biometric, password, or PIN access to your Mobile device will be able to view and
access de-identified images in your camera roll.
1.5.3 Confidentiality
Patient Information in the Vave App is encrypted in storage — and in transmit between the probe and app — using
industry standard AES encryption to reduce the risk of data breach if the device is lost or stolen.
Credential information (passwords) for the Vave App is stored using a one-way cryptographic function in a secure key
enclave on the mobile device.
Images shared or exported to a saved scan folder or to the camera roll are de-identified and do not contain
Protected Health Information (PHI). We recommend ultrasound images are reasonably secured and access
to image data be restricted when possible. We recommend deleting images in the local camera roll when
no-longer needed.
1.5.4 Integrity
Integrity of the data transmitted between the Vave Phased Array Probe and the Vave App is assured as follows:
Authentication and encryption reduce the risk of a malicious user interception, viewing, or modifying data.
• Integrity checks ensure the completion and validity of image data received
TCP channels are used to ensure that image information is delivered correctly
– UDP channels are used for image transmission with checksums
– If data for an image is incomplete or invalid, the entire image frame is discarded