Last updated: August 2, 2026
This Chrome extension ("Synthesis Worksheet Import - TA," "the Extension") is provided by Radiology Associates of San Luis Obispo ("RASLO," "we," "our") for internal use by our authenticated workforce. Distribution is restricted to accounts in the ra-slo.com Google Workspace domain, and the Extension is not intended for use by individuals outside our organization.
The Extension assists radiologists by extracting data from technologist worksheets and measurement screenshots displayed in Synthesis Health PACS, then importing that data into the FINDINGS section of the radiologist's active report. The radiologist reviews and edits all output before signing the report.
Pathology report addendum. When the radiologist uses the addendum workflow, the Extension captures images of pathology reports displayed in the Synthesis PDF viewer or imaging panels. These images are transmitted to our backend for AI-assisted transcription and the resulting text is inserted into the radiologist's addendum field. Patient identifiers visible in pathology report images are redacted by the AI during transcription. The same data handling, audit logging, and retention practices described below apply.
When you use the Extension, the following data is transmitted from your browser to our internal backend:
Authentication data. Your Google Workspace email address (associated with your @ra-slo.com account) and an OAuth bearer token obtained via Chrome's identity service. These are used to verify that you belong to our organization and to associate each request with a specific user for audit purposes.
Report content. The text of the radiology report draft you are currently editing, including any pre-populated metadata, clinical information, and findings text. This may contain Protected Health Information (PHI).
Worksheet and measurement images. Image captures of technologist worksheet panels and measurement screen snapshots that you explicitly select within the imaging viewer. Before transmission, the Extension crops the header region of the worksheet — the area in which patient identifiers are printed — so that identifiers are removed from the image prior to leaving your browser. Residual PHI may nonetheless remain in transmitted images, for example where identifiers appear outside the cropped region or in measurement screen captures, and all transmitted images are therefore handled as PHI.
Operational metadata. Exam type, request timestamp, latency, image counts and sizes, and processing status. Used for performance monitoring and audit logging.
Data submitted through the Extension is processed for one purpose: to assist you in drafting the FINDINGS section of a radiology report, or the text of a pathology addendum. The processing pipeline is:
Your browser sends the report draft and selected images to a Google Apps Script web app deployed within our Google Workspace organization.
The Apps Script calls Google's Gemini model to extract structured findings from the images and merge them into the report template.
The Apps Script returns the generated text to the Extension, which displays it for your review.
You decide whether to insert the generated text into your report.
A record of each request is logged to an internal Google Sheet within our Workspace, accessible only to designated RASLO administrators. The log includes the requesting user's email, timestamp, exam type, image count, the system prompt sent to the model, the model's output, and any error information. Because the model's output may contain PHI, this log is treated as a system containing PHI and is subject to the access controls and retention schedule described under "Data retention."
Data is transmitted to two Google services:
Google Apps Script, which hosts our internal backend. Apps Script operates within our Google Workspace and is a covered service under the Business Associate Agreement RASLO has executed with Google.
Google's Gemini model, which performs the AI text extraction. RASLO is migrating this processing to Vertex AI on Google Cloud, which is a HIPAA-eligible service under a Google Cloud Business Associate Agreement. Until that migration is complete, the Extension is operated as a limited-deployment internal tool and PHI exposure is mitigated through restricted distribution, workforce training, removal of patient names from the text payload, and audit logging.
We do not transmit data to any other third party. We do not use data handled by the Extension for advertising, profiling, model training, resale, or any purpose unrelated to the Extension's stated function.
The Extension does not persist report content, images, or patient data on your device. No browser-local copy of report content is retained between sessions. Chrome maintains a short-lived OAuth token cache independently of the Extension.
Clinical information — including report content, transmitted images, and model output recorded in the audit log — is retained for no longer than 30 days, after which it is purged.
Non-clinical operational metadata (requesting user, timestamp, exam type, image count, latency, and processing status) may be retained beyond 30 days for security and audit purposes. Access to the audit log is limited to designated RASLO administrators. The backend does not retain report content or images outside of the audit log described above.
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
identity — to obtain your Google Workspace identity and confirm you belong to the ra-slo.com domain.
storage — to save user preferences. No report content or patient data is stored.
scripting / host access to Synthesis Health PACS — to read worksheet and measurement panels and to write generated text into the report editor.
The Extension requests no permissions beyond those needed for these functions and accesses no other websites.
Use of the Extension is voluntary and may be discontinued at any time by uninstalling the Extension or by signing out of your Google Workspace account. As a member of our workforce, your use of the Extension is also governed by RASLO's HIPAA, security, and acceptable use policies, including any policy governing the use of generative AI tools with patient information.
If you have questions about how data is handled, or if you wish to request review of an audit log entry associated with your account, contact: tauran@ra-slo.com.
Communication between the Extension and the backend is conducted over HTTPS. Authentication is gated by Google Workspace single sign-on; only users authenticated against our ra-slo.com domain can access the backend. API credentials used by the backend are held in Google Apps Script's protected Script Properties storage and are never transmitted to client devices. The Extension contains no remotely hosted code; all executable code is contained in the published package.
We may update this policy from time to time. Material changes will be communicated to RASLO workforce members through our standard internal channels. The "Last updated" date above reflects the most recent revision.
Questions or concerns: tauran@ra-slo.com
Radiology Associates of San Luis Obispo 1310 Las Tablas Rd, Suite 206, Templeton, CA 93465