Image data
How to Source Licensed Medical Imaging Datasets for AI
Quick answer
To buy a medical imaging dataset for AI, decide first which legal pathway the data will travel (HIPAA Safe Harbor, Expert Determination, or a limited data set under a data use agreement), then source from a holder that can actually license it: a provider network, imaging center group, teleradiology practice or research archive with commercial terms. Specify modality, anatomy, scanner mix, reports, labels and outcomes in writing, and require a DICOM de-identification record that covers pixels, private tags and report text.
By SourceX Editorial · Updated
This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.
This guide covers the procurement path. For the broader image cluster, see image datasets for computer vision; for clinical text records rather than pixels, the owner page is licensing medical records for AI training.
Which HIPAA pathway fits an imaging purchase
The pathway decides what metadata survives, so choose it before you write the spec. HIPAA treats information as de-identified when it meets 45 CFR 164.514(a) through one of two methods in 164.514(b): Safe Harbor or Expert Determination [3][4]. A third route, the limited data set, keeps some identifiers but only under a data use agreement [4].
- Safe Harbor removes 18 identifier categories, including all date elements except year, geographic units smaller than a state (with a narrow ZIP3 exception), device identifiers and serial numbers, and "full face photographic images and any comparable images" [3]. For imaging this strips StudyDate and AcquisitionDateTime, many teams also remove DeviceSerialNumber as a conservative reading, and it forces a decision about whether head CT and MRI volumes need defacing.
- Expert Determination lets a qualified expert certify that re-identification risk is very small for a stated recipient and context [3]. It is how buyers keep shifted dates, scanner serial-level grouping or longitudinal links between priors, at the cost of a written report scoped to your use.
- Limited data set keeps dates, city, state and five-digit ZIP but excludes 16 direct identifiers, and 164.514(e) requires a data use agreement that limits uses, bars re-identification and contact, and binds downstream agents [4].
Read the expert's report, not just the certificate. It should name the recipient, the environment, the data elements retained and the conditions (for example, no linkage to other datasets) that the determination depends on. If your training pipeline or cloud vendor breaks those conditions, the determination may not hold.
DICOM de-identification: what Annex E covers and what it leaves to you
DICOM PS3.15 Annex E gives a reproducible tag-level method, but it explicitly does not guarantee removal of all identifying information [1]. The Basic Application Level Confidentiality Profile is a table of actions per attribute (remove, replace with dummy, clean, or keep), and named options change the outcome: Clean Pixel Data, Clean Descriptors, Clean Structured Content, Clean Graphics, Retain UIDs, Retain Device Identity, Retain Patient Characteristics, Retain Longitudinal Temporal Information (full or modified dates), Retain Safe Private and Retain Institution Identity [1]. These options originated in the clinical trial de-identification work of Supplement 142 [2].
Ask the supplier to list the exact options applied and record them in DeidentificationMethodCodeSequence (0012,0064), with PatientIdentityRemoved (0012,0062) set. That gives your data team a machine-readable audit trail per instance.
The common failure modes sit outside header tags:
- Burned-in text. Ultrasound, secondary capture, scanned film and some fluoroscopy frames carry names or MRNs in the pixels. Check BurnedInAnnotation (0028,0301), but do not trust it alone; ask for OCR-based pixel scrubbing evidence.
- Private tags. Vendor private groups can hold patient names, accession numbers or protocol notes. "Retain Safe Private" is only safe if the supplier maintains a vetted allowlist.
- Structured reports and free text. SR objects, StudyDescription, and the radiology report itself carry names, dates and referring physicians.
- Faces in volumes. Head and neck CT and MRI can be rendered into recognizable surfaces; specify a defacing tool and a QA check.
NIST's survey of de-identification documents real re-identification cases, which is why the method should be paired with contractual controls rather than treated as final [5].
Sourcing channels and what each can license
Who holds the data determines what terms are possible. Imaging data for AI typically comes from five places, each with a different rights profile.
| Channel | Typical holder | What you can usually get | Main procurement risk |
|---|---|---|---|
| Health system or academic medical center | HIPAA covered entity | Large, diverse modalities, reports, sometimes outcomes from the EHR | Long IRB or privacy review; commercial use and sale-of-PHI questions need counsel |
| Outpatient imaging center network | Covered entity, often multi-site | High-volume CT, MRI, mammography; consistent protocols | Narrow pathology mix; reports may sit in a separate RIS |
| Teleradiology practice | Business associate of many hospitals | Broad scanner and site diversity | Practice may lack rights to license data it reads for clients |
| Data aggregator or broker | Licensee of upstream sources | Curated, pre-de-identified cohorts | Chain-of-title gaps; sublicense limits; overlap with what competitors bought |
| Public research archive | Research consortium | Well-documented collections | Per-collection licenses, often non-commercial or attribution-bound |
The teleradiology row is where deals most often fail late. A business associate agreement generally permits the practice to use PHI to serve its clients, not to license that data onward, so ask who the covered entity is and whether it signed off. For a general framework on ownership and permitted use, see data provenance for AI training data and the owner guide on how to license proprietary data for AI training.
Outside HIPAA, imaging captured by consumer apps or wellness services can be "consumer health data" under laws such as Washington's My Health My Data Act, which carries its own consent requirements [7].
The specification to send suppliers
A precise request saves weeks of back-and-forth and lets suppliers say yes or no quickly. Describe the cohort and the fields, not the institution you hope to buy from.
Illustrative example: invented to show structure; it does not describe an available dataset.
request: chest_ct_nodule_cohort
modality: CT # (0008,0060)
body_part: CHEST # (0018,0015), verify against SeriesDescription
scanner_mix:
manufacturers_min: 3 # (0008,0070) Manufacturer
models_listed: true # (0008,1090) ManufacturerModelName
slice_thickness_mm: "<=1.5" # (0018,0050)
reconstruction_kernel: listed # (0018,1210)
studies_target: 5000 patients, priors where available
reports:
included: true
linkage: AccessionNumber -> pseudonymous key, same key in DICOM and report
deid_text: names, dates, MRNs, referring physician removed or shifted
labels:
source: radiologist report extraction + reader annotation
format: DICOM SEG or NIfTI masks, per-nodule JSON
readers: board-certified, inter-reader agreement reported
outcomes: biopsy pathology where available, 24-month follow-up flag
demographics: age band, sex, self-reported race/ethnicity where recorded
deid_pathway: Expert Determination (date shift preserved within patient)
annex_e_options: [CleanPixelData, CleanDescriptors, RetainLongitudinalModifiedDates, RetainDeviceIdentity]
delivery: DICOM Part 10 files + manifest CSV with SHA-256 per instance
Three choices in that spec decide model value. Scanner and kernel diversity drives generalization; see camera and acquisition diversity in image datasets for the general principle. Outcome linkage (pathology, follow-up) is what separates a detection set from a clinically meaningful one. Label provenance matters more than label count; compare pre-labeled datasets with annotating raw images yourself and choose mask versus box geometry with the annotation type guide.
How reports, labels and images stay linked after de-identification
Linkage must survive de-identification, or the dataset loses its text supervision and its outcomes. Ask the supplier to describe one pseudonymization key that maps PatientID, StudyInstanceUID and AccessionNumber consistently across DICOM headers, the report export from the RIS, and any EHR outcome extract.
Check these points in the sample:
- StudyInstanceUID, SeriesInstanceUID and SOPInstanceUID are regenerated consistently across images, SEG or SR objects and the manifest, so cross-references still resolve, and one pseudonymous PatientID still groups priors with the same patient (unless Retain UIDs is justified in the expert report).
- Date shifting uses one offset per patient across images and reports, so intervals between studies stay true.
- Report text was de-identified with a named method, and a reviewed sample shows residual identifier rates.
- Labels reference SOPInstanceUID or frame numbers, not filenames that change on export.
For the parallel problem in spoken clinical notes, see physician dictation audio for medical ASR.
Data use agreement and license terms to negotiate
DICOM does not define the purpose, recipients or sharing process, so the agreement has to [1]. Whether the instrument is a HIPAA data use agreement for a limited data set or a commercial license for de-identified data, it should state:
- Permitted uses: training, validation, testing, regulatory submission support, and whether derived models may be sold or deployed commercially.
- Re-identification and linkage bans: no attempt to identify or contact individuals, and no joining with other datasets beyond what the expert report allows [4].
- Recipients and environment: named affiliates, cloud regions and subprocessors, so the expert determination's assumptions hold.
- Record definition and refresh: what counts as a delivered study, how incremental pulls are scoped and versioned.
- Breach and incident handling: notice obligations if identifiers are found after delivery, and a takedown or replacement process.
- Retention and audit: how long you can hold the data and models trained on it, and what evidence you owe the supplier.
Quality evidence belongs in the contract too. ISO/IEC 5259-4 sets out a process framework for data quality in ML, including labeling of training data, which gives both sides a shared vocabulary for acceptance criteria [6]. For pricing logic before you commit, see estimating a dataset's value before you buy.
Acceptance checks before you sign off on delivery
Run acceptance on a sample before full payment or full ingestion. A practical sequence:
- Validate every file with a DICOM parser and confirm SOP Class, transfer syntax (compressed JPEG 2000 or JPEG-LS can hide decoding issues) and pixel spacing.
- Scan headers for any residual PatientName, PatientBirthDate, InstitutionAddress or OperatorsName values, and dump private groups.
- Run OCR on a sample of frames from ultrasound, secondary capture and scanned modalities.
- Reconcile the manifest: patient, study and instance counts, hashes, and the split of manufacturers and models against the spec.
- Check that report-to-image linkage resolves for the agreed percentage of studies.
Image metadata stripping in non-DICOM formats follows similar logic; see EXIF metadata in image training data.
Where SourceX fits for imaging-adjacent requests
SourceX sources operational datasets from US companies on request; it does not hold imaging in stock, and a request does not guarantee a match. Buyers describe the data they need, SourceX looks for US businesses that hold it, and every release is approved by the supplying company. Health records require HIPAA de-identification by Safe Harbor or Expert Determination, and personal details are removed or replaced before delivery with the method recorded and a sample checked, though no method is perfect. If you are weighing healthcare data more broadly, the healthcare buyers page and whether AI labs buy medical data give context, and you can submit a buyer request with your imaging spec.
Sourcing medical imaging data through SourceX
SourceX manages the commercial process from find and assess through license agreement, transaction and ongoing purchases, and every dataset is rights-reviewed and delivered under a license defining records, uses, term and delivery. Delivery runs through private, access-controlled workflows only after an executed agreement and supplier approval. Describe the imaging data you need.
Frequently asked questions
Is a DICOM-anonymized dataset automatically HIPAA de-identified?
No. Annex E profiles are a method for handling attributes, and the standard itself says they do not guarantee removal of all identifying information [1]. HIPAA de-identification is a legal standard met by Safe Harbor or Expert Determination [3]; the Annex E record is evidence toward it.
Can I keep exam dates for longitudinal models?
Not under Safe Harbor, which removes all date elements except year [3]. Buyers keep relative timing through patient-level date shifting under Expert Determination, or keep real dates in a limited data set under a data use agreement [4].
Do public research archives work for commercial models?
Sometimes. Licenses are set per collection, and many restrict commercial use or require attribution, so read each collection's terms and record them with the files.
Sources
- NEMA / DICOM Standards Committee, "DICOM PS3.15 - Security and System Management Profiles, Annex E: Attribute Confidentiality Profiles" (2026). https://dicom.nema.org/medical/dicom/current/output/chtml/part15/chapter_E.html
- DICOM Standards Committee, "DICOM Supplement 142: Clinical Trial De-identification Profiles". https://www.dicomstandard.org/News/ftsup/docs/sups/sup142.pdf
- U.S. Department of Health and Human Services, Office for Civil Rights, "Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule" (2012). https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification
- eCFR, Office of the Federal Register / HHS, "45 CFR 164.514 - Other requirements relating to uses and disclosures of protected health information" (2026). https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
- National Institute of Standards and Technology, "De-Identification of Personal Information (NISTIR 8053)" (2015). https://nvlpubs.nist.gov/nistpubs/ir/2015/NIST.IR.8053.pdf
- ISO/IEC JTC 1/SC 42, "ISO/IEC 5259-4:2024 Artificial intelligence - Data quality for analytics and machine learning - Part 4: Data quality process framework" (2024). https://www.iso.org/standard/81093.html
- Washington State Legislature, "Chapter 19.373 RCW - Washington My Health My Data Act". https://app.leg.wa.gov/RCW/default.aspx?cite=19.373&full=true
Tell us what your models need
Share scope, volume, language, format, timing and licensing requirements.