Skip to main content
Visit status webhooks include a full referral snapshot. That payload is PHI: patient name, date of birth, contact, and clinical procedure detail. Notification webhooks are metadata only. Recipients and message bodies are never returned.

Requirements

  • Terminate TLS. Scan only accepts https:// webhook URLs.
  • Verify X-Scan-Signature (v1= HMAC-SHA256 of {timestamp}.{raw body}) and reject timestamps older than five minutes.
  • During signing-secret rotation Scan may send multiple v1= signatures for 24 hours. Accept if any matches.
  • Do not log raw payloads, tokens, or signing secrets.
  • Rotate the webhook secret from the API access tab. The previous secret is not displayed again.
  • Use synthetic data only in the sandbox.

Certifications and subprocessors

Scan maintains a SOC 2 Type II report. Email [email protected] to request it. An NDA must be in place before the report is shared. Imaging studies are retrieved from Ambra, Scan’s imaging-archive subprocessor. Notification webhooks never include study bytes; DICOM downloads go through the order-documents routes.

IP allowlisting

Scan does not currently publish a static egress IP list for webhooks. Authenticate with the signature, not the source address.

BAAs, retention, and incident SLAs

Contractual BAA language, retention periods, and support response times are issued by Security, Legal, and Support — they are not implied by this page. Email [email protected] for the current packet. If you suspect exposure of a Scan token or webhook secret, email [email protected] with the X-Request-Id of a recent call and revoke the credential from the API access tab.