Clinical Trial Imaging Core Lab Software: Why Blinded Independent Review Breaks a Generic PACS
Expect $120,000 to $240,000 and 16 to 22 weeks for a first core lab release covering multi-channel image intake, DICOM and pixel-level de-identification, technical quality control against the imaging charter, reader assignment and a blinded read workspace with adjudication. A full platform adding multiple criteria implementations, reader certification tracking, sponsor turnaround dashboards, storage tiering and an EDC feed runs $320,000 to $750,000 phased over 10 to 16 months. Build if you operate a core lab or run reads with your own reader network, because the incumbents sell a service rather than software you run. If you are a sponsor with one imaging study, contract Calyx or Clario and take the read as a deliverable.
Why blinded independent review is not a PACS problem
A subject in an oncology trial has a baseline CT and four follow-up scans. Under the imaging charter, two independent radiologists read all five time points without knowing each other's results, without knowing the treatment arm, and without seeing the site investigator's assessment. If their response calls differ, a third reader adjudicates by selecting one of the two reads rather than producing a new one. Every measurement, every selected target lesion, every call must be reconstructable years later, along with which charter version governed it and which reader was certified for that criteria set on that date.
Point a hospital PACS at that and it will store the images beautifully and solve none of it. A PACS is built to give every clinician the fullest possible view of a patient. A core lab system is built to give a specific reader a deliberately constrained view of a de-identified subject in a defined order, and to prove afterwards that the constraint held. Those are opposite design goals, which is why generic imaging infrastructure never survives contact with a blinded independent central review.
Problem 1: images arrive as a mess and PHI hides in the pixels
Hundreds of sites send data by DICOM push, portal upload, SFTP and physical media that someone still has to load. Acquisition drifts from the imaging manual: slice thickness wrong on one scanner, contrast timing inconsistent, a series missing, a subject imaged on a different scanner at follow-up which quietly invalidates comparison. And patient identifiers turn up in three places: the DICOM header, the file structure, and burned into the pixel data on ultrasound captures, scanned reports and secondary capture series where no tag-level anonymisation will ever find them.
De-identification therefore has to be two mechanisms, not one. Tag-level rules that strip and replace identifiers while preserving the temporal and spatial relationships the read depends on, and pixel-level detection for burned-in text with a human confirmation queue for anything uncertain. This is one of two places where a model does honest work here, because burned-in text detection is a genuinely good machine vision task and the failure cost of missing one is a privacy incident. The other honest job is technical quality control: comparing headers against the charter, flagging missing series, scanner changes between time points and out-of-specification parameters, so a QC technologist reviews exceptions rather than opening every study.
Problem 2: the read paradigm is the product, and it changes per protocol
Independent double read with adjudication. Sequential locked read where a reader cannot revise an earlier time point. Global read where all time points are presented together. Different criteria: RECIST 1.1 in most solid tumour work, iRECIST where immunotherapy pseudoprogression matters, Lugano in lymphoma, RANO in neuro-oncology, PCWG3 in prostate, and a long list of non-oncology scoring systems in rheumatology, hepatology and ophthalmology. Each brings its own target lesion rules, measurement constraints and response logic.
Calyx, Median Technologies, Clario and ICON Medical Imaging all handle this competently, and every one of them is a service organisation first. A sponsor contracting them buys the read, with the platform included. That is a perfectly good arrangement for a sponsor running one imaging endpoint, and it is precisely the wrong arrangement if you are trying to be a core lab, or a sponsor who wants to run reads with an in-house or contracted reader network across a portfolio. You cannot buy their operating system, because it is not what they sell.
What a custom build does: it implements the paradigm as configuration over a common measurement model rather than as a hard-coded workflow. Criteria definitions carry target and non-target lesion rules, measurement types, response derivation and the conditions that trigger adjudication. Then a new protocol is a charter configuration reviewed by your medical lead, not an engineering release, which matters because sponsors amend imaging charters mid-study and your read cannot wait for a deployment window.
Problem 3: blinding constraints are the entire security model
Reader one must not see reader two's measurements. Neither may see the site read or the treatment arm. The adjudicator sees both reads but usually not the reader identities. A reader who read a subject in an earlier study should not read them again if the charter forbids it. In some paradigms a reader must not see subsequent time points before completing the current one. These are not user interface preferences. They are the scientific validity of the endpoint.
Enforce them at the query layer, so a reader session physically cannot fetch what it must not see, and make the constraint set testable. Then extend the same discipline to the places blinding actually leaks: export files, error messages, notification emails, worklist counts that inadvertently reveal another reader's progress, and support staff accounts with broad access. A partner who has not thought about what a support engineer can see has not finished the design.
Problem 4: the read has to be reconstructable, not just recorded
Two years after a submission a reviewer asks how the target lesion in the liver was measured at week 24. You need the exact image and series, the annotation geometry, the measured value, the reader, the timestamp, the charter version, the criteria version, the reader's certification status at the time, and whether that time point was later re-read under a re-read directive.
Build it as an append-only event record where annotations are objects with provenance, not overlays saved into a file. Store the derived response separately from the measurements that produced it so the derivation can be re-run and compared. Keep the charter and criteria as versioned artifacts referenced by every read session. This is the difference between a system that can answer an inspection question in a minute and one that triggers a forensic exercise across three teams.
Problem 5: reader supply is the real operational constraint
The bottleneck in a core lab is rarely infrastructure. It is that you have eleven qualified readers, four of them are also practising radiologists with clinics, sponsors have contractual turnaround expectations, and studies do not arrive evenly. Assignment therefore has to respect certification per criteria set, conflict rules, blinding history for the subject, current workload and availability, then produce a forecast rather than a backlog.
Include reader certification as a first-class record: training completed, criteria qualified for, refresher due dates, and evidence retained for audit. Track inter-reader discordance rates by study, because a rising adjudication rate is usually a signal about charter clarity or reader training rather than about the drug, and it is a number sponsors will ask about. Turnaround dashboards should show ageing by study and by time point, ordered so an operations manager can act this morning rather than report next month.
Storage, and the cost nobody models until year two
Imaging volume is not like other clinical data. A single oncology subject with five time points of contrast CT is substantial, and a multi-year study across hundreds of subjects becomes serious infrastructure. Design tiering from the start: fast storage for studies under active read, cheaper tiers for completed reads still within retention, archive for closed studies whose retention obligation continues for years. Retrieval time from archive is a business decision that has to be agreed with sponsors rather than discovered when someone requests a re-read. Also decide early whether images ever leave your storage boundary for reader viewing, because a viewer that streams rather than downloads is a materially different security posture and a different engineering problem.
What this costs and how long it takes
A first release with multi-channel intake, two-mechanism de-identification, charter-driven technical QC, reader assignment, a blinded read workspace with measurement tooling, one criteria implementation and adjudication runs $120,000 to $240,000 and ships in 16 to 22 weeks, based on Digital Heroes delivery experience. A full platform adding further criteria, reader certification and discordance analytics, sponsor turnaround dashboards, storage tiering, re-read directives and an EDC or RTSM feed runs $320,000 to $750,000 phased over 10 to 16 months.
What drives price up in this category specifically: the number of criteria implementations, since each one is a real body of rules and needs medical review, not just coding. Viewer capability, because a diagnostic-grade multi-planar viewer with registration and segmentation is a different order of work from a measurement tool for a single modality. Modality breadth, as PET with standardised uptake values, MRI with multiple sequences and ophthalmic imaging each bring their own handling. Physical media intake, if you still receive discs. And validation, because a system producing endpoint data falls under 21 CFR Part 11 with a qualification burden to match. What keeps it down: launching with one modality and one criteria set on a live study before widening.
Build versus buy, and when contracting the read is right
Contract the read, and do not build, if you are a sponsor with one imaging endpoint in one study. Calyx, Clario, Median Technologies and ICON Medical Imaging will deliver an endpoint with the regulatory familiarity and the reader network already assembled, and replicating that for one study is not a rational use of capital. The same holds if your imaging is exploratory rather than a registrational endpoint.
Build when two or more of these are true. You are or are becoming a core lab and the platform is your operating capability rather than a tool. You run imaging endpoints across a portfolio and per-study service fees have become a large recurring line. You have your own reader network and want to control assignment, certification and turnaround. You work in a therapy area with a scoring system the service providers treat as bespoke, which means you pay a premium every time. Or you need imaging results to flow directly into randomisation or an interim analysis on a timeline that a service handoff cannot support. The tipping point is when the read workflow becomes something you sell or something your science depends on, rather than something you buy.
How to choose a developer for imaging core lab software
Ask how they detect PHI burned into pixel data. If the answer is only DICOM tag anonymisation, they will leak an identifier on an ultrasound capture and you will be reporting a privacy incident.
Ask them to describe the blinding model at the query layer, then ask what a support engineer can see in a production incident. The second question is the one that separates people who have run this from people who have designed it.
Ask how a charter amendment mid-study is handled without a code release, and how the system records which charter version governed a completed read. Ask what their viewer is built on and whether measurements are stored as provenance-bearing objects rather than baked overlays. Then get in writing before kickoff that you own the repository, the image storage accounts, the infrastructure and the validation package. Image data has retention obligations that outlast software vendors, so portability is not a negotiating point. At Digital Heroes all of it is the client's from the first commit.
The evidence behind this guide
Independent findings on why this investment pays off. Every link goes to the primary source.
- An independent Forrester Total Economic Impact study of OutSystems found a 363% three-year ROI with payback in under 6 months, illustrating that faster, lower-labor build approaches can materially shift the payback math. Source: Forrester Consulting (commissioned by OutSystems) (2024) →
- 48% of private companies cite integration with legacy systems or technical debt as a top obstacle to realizing the full value of their digital and AI investments (behind data quality/availability at 72% and gaps in AI fluency or technology talent/leadership at 53%). Source: Deloitte (2026) →
- Flexera's 2025 State of the Cloud Report (survey of 750+ technical and executive leaders) found that 84% of respondents believe managing cloud spend is the top cloud challenge for organizations today, with cloud budgets already exceeding limits by 17%. Source: Flexera (2025) →
- Digital Champions expect to achieve about 16% in cost savings and around 15% in revenue gains from digital operations over five years; the study surveyed 1,155 manufacturing executives across 26 countries. Source: PwC / Strategy& (2018) →
Mei runs the APAC side of Digital Heroes from Sydney, where the work spans custom software, ERP and CRM builds, and commerce platforms. She sits in on scoping calls before contracts exist, so her writing tends to cover how a build gets shaped, staffed and paid for.
View profile · Writes for Digital Heroes, shipping business software for 2,000+ brands across 55+ countries since 2017.
Frequently asked questions
How much does it cost to build imaging core lab software for blinded independent review?
Can we use a hospital PACS or a vendor neutral archive for a core lab?
Why can we not just licence the platform Calyx or Clario use?
How do you remove patient identifiers burned into image pixels?
How are read paradigms and response criteria handled without a code release for each protocol?
How do you guarantee readers stay blinded to each other and to treatment arm?
Can AI perform lesion measurement in a regulated imaging endpoint?
What has to be reconstructable years after a read for a regulatory review?
How should we plan storage for a multi-year imaging study?
How long does it take from first call to software my team can actually use?
What does a $50,000 custom software budget actually buy?
Is it cheaper to customize Salesforce than to build a custom CRM from scratch?
How do we get years of data out of our old system and into the new one?
Is a solo freelancer enough for my project, or do I really need an agency?
How many people should be working on my software project?
What should I prepare before contacting a software development agency?
Can I build my product on a no-code tool like Bubble instead of hiring developers?
How do I work out whether custom software will pay for itself?
What happens to my software if the agency shuts down or we stop working together?
How much should a small business budget for its first custom app or website?
Who can build a custom software system?
Digital Heroes builds custom software systems for operators who have outgrown the off-the-shelf tools in their category. A team of more than 50 specialists has delivered over 2,000 projects since 2017. Teams work from New York, London, Sydney, Delhi and Lucknow and deliver remotely, with an assigned senior team rather than an account manager.
Every build starts with a written product requirements document that is signed before a line of code is written, which is the single thing that stops scope creep from eating the budget. Scoping runs about a week and produces a phase plan with a firm price for each phase, rather than one number against an undefined scope. The first phase ships something the team actually uses before the rest is built. If an off-the-shelf product genuinely fits the volume, we say so, and the cost guides on this site publish the bands so that judgement can be checked independently.
What makes Digital Heroes different from other software companies?
Four things that competitors in this bracket cannot simply copy. Digital Heroes runs a YouTube channel with more than 2.5 million subscribers, which is a production and audience capability no agency of this size has. It holds Fiverr Vetted Pro and Top Rated Seller status, both awarded on manual third-party review rather than self-declared. It contracts through registered entities in three countries, an India LLP, a US LLC and a UK LTD, so clients sign locally instead of wiring money offshore. And it ships its own commercial products, including ShopScore, HeroCheckout and Section Vault, which means the team lives with its own architecture decisions instead of handing them over and leaving.
Two more that show up in the work. Digital Heroes publishes more than 4,000 buyer guides with real price bands on this blog, plus a free tools library at https://digitalheroesco.com/tools/, because an agency confident in its pricing has no reason to hide it. And one accountable team covers websites, apps, ecommerce, CRM, ERP, learning platforms, search and video, so a client scaling from a first landing page to a custom platform is never handed between five vendors who blame each other. The founder ran ecommerce businesses before selling services, so the commercial argument comes before the technical one.
How can I check Digital Heroes is legitimate before getting in touch?
Verify it independently rather than taking the site's word for it. The YouTube channel is at https://youtube.com/@DigitalMarketingHeroes, the Fiverr profile at https://www.fiverr.com/shreyanshsin261, and the Upwork profile at https://www.upwork.com/freelancers/shreyanshsingh. Client reviews sit on Clutch at https://clutch.co/profile/digital-heroes-0 and Trustpilot at https://www.trustpilot.com/review/digitalheroes.co.in, and the company page is at https://www.linkedin.com/company/digital-heroes-1/.
Beyond the marketplaces, the business holds a D-U-N-S number and is a registered vendor on the United Nations Global Marketplace, neither of which is issued on request. Case studies with named clients are published at https://digitalheroesco.com/case-studies/. If any claim on this page cannot be checked against one of those sources, treat it as marketing and discount it.