A supervised camera that measures OR workflow—engineered so patient data never leaves the device.
Below is a plain-language summary of everything. Open any + to see more. The answer is on the line before you even click, and deeper detail nests underneath. Everything you've opened stays in place, so you can go as deep as you need on the topics you care about and skip the rest.
UNITED STATES · OR CAMERA · DATA SECURITY & HIPAA · v1.0
VIDEO RESIDENCY
AWS US-East-1
Video in the US. Process data in the EU.
90 days
RETENTION (DEFAULT)
From upload; hospital-defined.
PHI IN THE CLOUD
None
Only de-identified data is stored.
CROSS-CORDER PHI
None
PHI never leaves the OR device.
Informational overview—not legal advice. It does not account for state-specific recording, consent, or privacy law, which varies by state and changes over time. Verify the requirements for your jurisdiction before deployment.
How the camera works
A centrally managed iPhone (via MDM) records a full surgical day. Every frame is de-identified on the device — all skin, including faces, is blurred and speech removed — and only the de-identified result is sent to the cloud. The raw recording never leaves the phone and is deleted right after de-identification.
The four steps, start to finish Capture → de-identify → encrypted upload → insight
1 · Capture. The managed iPhone records the OR over a full surgical day. Raw video and audio are written only to the app's encrypted, sandboxed storage on the device, reachable by no other app.
2 · De-identify. All skin, including faces, is blurred and speech is removed — entirely on the device. The raw recording is deleted as soon as the de-identified version is produced, before anything is sent.
3 · Encrypted upload. Only the de-identified video is uploaded over TLS to AWS US-East-1, then deleted from the phone once upload completes.
4 · Insight. The derivative becomes timings, task sequences and role activity — the operational-excellence report the hospital receives.
Tech Does it connect to the hospital IT network?
No connection to the hospital's internal network is required. The device uploads over guest Wi-Fi or its own mobile data, and never touches clinical systems or the hospital LAN.
Tech Network & transport specifics TLS 1.2+/1.3, AWS S3 SDK, upload-only credential
- Transport is TLS 1.2 minimum, 1.3 preferred, via the AWS S3 SDK.
- The device authenticates with a limited, upload-only credential (create-recording permission; no list, read or delete), using short-lived Cognito credentials.
- No inbound access to the device is exposed; the phone initiates all connections outbound.
- Cellular is available via a DEO-provided eSIM as a fallback; in practice hospital guest Wi-Fi is used.
Security What DEO can reach on the device remotely Device-lifecycle management only — no path to read recordings
The iPhones are supervised (Apple Business Manager) and managed by MDM. MDM covers the device lifecycle only — configure, restrict, lock, wipe — and provides no path to read recordings, buffered video, or app data. Administrative management from Europe cannot reach patient data.
Tech What happens to the raw recording? Encrypted on the phone; deleted right after anonymisation
Raw video and audio are written only to the app's private, encrypted storage — never to the camera roll, Files, iCloud, or any shared location — so they are not accessible to the person using the device (this comes from the app sandbox, independent of any device passcode). The raw recording is deleted immediately after on-device anonymisation, and the de-identified video is deleted immediately after upload. If an upload cannot complete, only de-identified data remains on the device — the raw recording is already gone. The device is used solely for this purpose, with no in-app path to view or export files.
Tech Why the deletion is irreversible
Deletion destroys the per-file encryption key, a NIST SP 800-88 Rev. 2 Purge (crypto-erase) at file granularity. The class key cannot reconstruct it, so the ciphertext remaining on flash is unrecoverable. Files are never written to the camera roll or app cache, and iCloud Photos and backup are disabled on the supervised devices.
Tech The de-identification engine Internally built, integrating a licensed YOLO model — detection only
An internally-built engine integrating a licensed detection model (YOLO). It performs detection only — bounding boxes that drive the blur — never facial or hand recognition, and computes no biometric template. It is validated against a deliberately hard baseline (PPE, surgical draping, non-standard angles).
Tech What if de-identification fails on a frame?
If on-device de-identification does not meet its quality threshold, upload is blocked, the raw frames are deleted, and the operator is prompted to retry or delete. Raw footage never falls through to the cloud.
What is — and is not — measured
The output is process data only: how the OR day flows. No patient identifiers, no clinical records, no individual staff scoring. Analysis is role- and team-based.
Detail The full measured / not-measured list
| MEASURED (PROCESS DATA) | NEVER COLLECTED |
|---|---|
|
|
Tech Does DEO.care see our EHR or clinical systems?
No. DEO.care never accesses electronic health records, medical records, or clinical databases, and does not integrate with hospital IT systems. The only data leaving the OR is the de-identified video derivative.
Why patient privacy is protected
Blurring, speech muting, random file names and full-day aggregation strip identity from what's transmitted. Identifying a recording would need two keys held by two different parties — so DEO.care on its own cannot link any recording to a patient.
Legal How re-identification is split between two parties
Files are named with a random GUID; the storage tenancy holds no hospital, case or patient identifier. Re-identification is deliberately split:
- DEO.care holds, in a database separate from the video, only GUID → recording date + hospital.
- The hospital holds date → patient in its own surgical schedule.
- Linking a recording to a patient requires both; neither party can do it alone, and the linking mechanism is disclosed to no third party.
One full-day file also aggregates multiple sequential procedures with no internal segmentation cue, so a file maps to no single patient.
Legal The HIPAA de-identification basis (§164.514)
The transmitted derivative qualifies as de-identified data under 45 CFR §164.514, combining the Safe Harbor transformations (§164.514(b)(2)) with the re-identification-code framework (§164.514(c)). Because the AWS-side data is de-identified, it is not PHI for HIPAA purposes; DEO.care nonetheless holds an AWS Business Associate Addendum as defence-in-depth.
Legal The 18 Safe Harbor identifiers, addressed
| IDENTIFIER | HOW IT IS HANDLED |
|---|---|
| Names | Not in workflow data; faces blurred at source |
| Geography < state; dates; phone/fax; email; SSN; MRN; plan, account, certificate, vehicle, URL numbers | Not captured. Recording-time metadata stripped; recording date held only in DEO.care's separate database (GUID + hospital, not patient) |
| Device identifiers | iPhone hardware ID held in DEO.care's device inventory only; not in the derivative or its storage |
| IP addresses | Upload IP logged for audit only; not embedded in the content |
| Biometric identifiers (finger / voice prints) | Speech is detected and removed on-device before anything leaves the OR, so no voice/speech (voiceprint) is transmitted. Faces/hands detected for blur only — never recognised; no template computed, stored or transmitted |
| Full-face photos & comparable images | Faces and exposed skin blurred at source; scope limited to high-volume procedures so distinctive features don't narrow the population |
| Any other unique code | GUID randomly generated (§164.514(c)(1)); full-day aggregation removes per-patient cues |
| Actual-knowledge test (§164.514(b)(2)(ii)) | Met by split knowledge — DEO.care alone has no knowledge that could re-identify any patient |
HIPAA roles & who decides on consent
The hospital is the Covered Entity and decides how patients are informed; DEO.care is a Business Associate under a signed agreement (BAA) and processes only what the hospital instructs.
Legal Who plays which role
- Hospital — Covered Entity. Determines purpose, scope, case selection, retention; documents the patient pathway.
- DEO.care — Business Associate under a BAA. Processes only on documented instruction; defines no independent purpose.
- AWS — Subcontractor BA (US-East-1). Receives only de-identified data; BAA held as defence-in-depth.
Legal How are patients informed — is authorization required?
The hospital decides — DEO.care does not make this call.
- Primary — Healthcare Operations (45 CFR 164.506(a); definition at 164.501): OR workflow analysis supports quality assessment and improvement, with coverage in the Notice of Privacy Practices. The Privacy Officer documents the determination under 164.530(j).
- Alternative — HIPAA Authorization (164.508): collected in the pre-operative process where the hospital or state law calls for it.
Legal State law may add requirements
| STATE | WHAT IT ADDS |
|---|---|
| California (CMIA) | Expects specific written authorization for video/audio; separate de-identification analysis |
| Illinois (BIPA) | Biometrics — addressed by detection-only pipeline; written notice + retention policy as defence-in-depth |
| Texas (HB 300) | Offshore-disclosure notice not triggered — PHI stays on-device in the US |
| NY SHIELD / MA 201 CMR 17 | Information-security-program requirements — met by DEO.care's ISMS |
| Two-party audio states | Residual exposure negligible — speech removed on-device before anything leaves the OR; advance notice given |
Legal Breach notification
DEO.care notifies the hospital of any breach of unsecured PHI without unreasonable delay under 45 CFR 164.410. The BAA carries the full HIPAA §164.504(e) contents, subcontractor flow-down, and return-or-destroy obligations.
Legal We're a European company — does GDPR apply, and does our data go to the EU?
No PHI is transferred to the EU. Raw PHI never leaves the in-OR device, and the video recordings are stored in the US (AWS US-East-1). DEO.care's operational database — the process data and the recording-to-hospital mapping — is hosted in the EU; it contains no PHI and cannot identify a patient (the mapping links a recording only to a date and hospital, never to a patient — see the split-knowledge design under “Why patient privacy is protected”).
So some de-identified data does reside in the EU, but the hospital's PHI does not. DEO.care is separately subject to the EU GDPR for its own EU processing; that is independent of HIPAA and does not extend GDPR to the hospital's US PHI.
What this means for OR staff
Recording is open, not covert, and is never used to evaluate, discipline or credential individuals. You are told in advance, and you can object.
Detail Purpose limitation & how notice works
- Purpose limitation. Not used for individual performance management, discipline, credentialing, clinical-outcome attribution, patient monitoring, or marketing — written into the BAA and the workforce notice.
- Advance written notice before any recording window — purpose, dates, ORs in scope, and the objection channel. Consent is not relied on in the employment relationship; notice is the mechanism.
- Objection raised to a supervisor or the Privacy Officer; exclusion accommodated where operationally feasible.
Legal Biometrics (BIPA) and recorded audio
- BIPA (Illinois) & similar. The pipeline performs face/hand detection only — never recognition — and computes, stores or transmits no biometric template. Written notice and a retention/destruction policy are held as defence-in-depth.
- NLRA. The mitigation for chilling effects is advance written notice plus the purpose-limitation above.
Tech Exactly how audio is handled
- The recording includes an audio track. An on-device speech-detection model (voice-activity detection) identifies speech and removes it — those sections contain no audio data. It is not speech recognition, speaker identification, or emotion inference.
- Audio leaves the OR, but speech does not. The transmitted audio track is used only to mark workflow events — for example, the sound of a saw — which is why it is retained; the speech portions are already blanked before anything is sent.
- Because speech is removed on-device before anything leaves the OR, and staff receive advance notice in a non-confidential staffed OR, residual two-party-consent exposure is negligible.
What this means for OR staff
Recording is open, not covert, and is never used to evaluate, discipline or credential individuals. You are told in advance, and you can object.
Detail Purpose limitation & how notice works
- Purpose limitation. Not used for individual performance management, discipline, credentialing, clinical-outcome attribution, patient monitoring, or marketing — written into the BAA and the workforce notice.
- Advance written notice before any recording window — purpose, dates, ORs in scope, and the objection channel. Consent is not relied on in the employment relationship; notice is the mechanism.
- Objection raised to a supervisor or the Privacy Officer; exclusion accommodated where operationally feasible.
Legal Biometrics (BIPA) and recorded audio
- BIPA (Illinois) & similar. The pipeline performs face/hand detection only — never recognition — and computes, stores or transmits no biometric template. Written notice and a retention/destruction policy are held as defence-in-depth.
- NLRA. The mitigation for chilling effects is advance written notice plus the purpose-limitation above.
Tech Exactly how audio is handled
- The recording includes an audio track. An on-device speech-detection model (voice-activity detection) identifies speech and removes it — those sections contain no audio data. It is not speech recognition, speaker identification, or emotion inference.
- Audio leaves the OR, but speech does not. The transmitted audio track is used only to mark workflow events — for example, the sound of a saw — which is why it is retained; the speech portions are already blanked before anything is sent.
- Because speech is removed on-device before anything leaves the OR, and staff receive advance notice in a non-confidential staffed OR, residual two-party-consent exposure is negligible.
Retention, transparency & security
Recordings are kept for a hospital-defined period (default 90 days), then destroyed. The camera is deliberately visible, and the whole pipeline runs inside an ISO 27001-certified security program with no access to hospital networks or clinical systems.
Detail Retention & litigation hold
- Default 90 calendar days from upload; hospital-definable, recorded in the engagement schedule.
- A litigation-hold protocol suspends destruction on receipt of a preservation notice.
- Where state law and governance permit, the engagement is scoped under the hospital's quality-improvement committee to support peer-review privilege.
Detail Transparency — why it isn't covert
- Conspicuously positioned camera — visible to staff and patients.
- Advance workforce briefing (written, in-person offered); patient information sheet; OR poster during any recording window.
- Explicit non-covert framing in all engagement materials.
Security Security controls in detail
- Encryption. In transit TLS 1.2+/1.3; at rest AWS SSE-KMS; on device AES-256, with raw crypto-erased after processing.
- Least-privilege upload. Upload-only credential (no list/read/delete) via short-lived Cognito credentials.
- Processing environment. MFA enforced; role-based access; access logging and monitoring under the ISMS.
- Governance. Operated within DEO.care's ISO/IEC 27001-certified ISMS, with a formal incident-management and breach-notification process.
Security Device management & lost-device handling
Supervised iPhones (Apple Business Manager) under MDM, used solely for the DEO recording app. MDM covers the device lifecycle only — configure, restrict, lock, wipe — with no path to read recordings or app data. Loss or theft is covered by full-disk encryption (AES-256), crypto-erase on deletion, remote wipe, and Activation Lock following wipe (a wiped device is unusable without DEO.care's account).
What DEO.care does — and does not — do
DEO.care measures and improves OR workflow from de-identified data. It does not evaluate individuals, touch clinical systems, or store PHI in the cloud.
Detail The full does / does-not list
| DEO.CARE DOES | DEO.CARE DOES NOT |
|---|---|
|
|
Privacy notices: DEO.care supplies model patient and OR-staff privacy notices. The hospital determines the applicable notification and authorization requirements under HIPAA and any applicable state law.