Your imaging archive may be reachable from the internet.
Independent research has repeatedly found unprotected PACS and DICOM endpoints exposing hundreds of millions of medical images, often with patient identifiers burned into the files. The cause is almost never an exotic attack. It is a system connected directly to a public network because that was the fastest way to make it work.
- Indicative range
- Typically €8,000–18,000, scoped after review
- Shape
- Usually two to five weeks, remote.
What you are already seeing
- Remote access to imaging was arranged quickly, and nobody revisited it afterwards.
- A vendor, a clinic or an integrator holds access nobody has reviewed in years.
- Modality and archive traffic shares a network with everything else.
- No one can produce a current list of what is reachable from outside.
What gets examined
- 01
What of your imaging estate answers from an external network, with your written authorisation.
- 02
How archive, modality and viewer traffic is separated, or is not.
- 03
Authentication and access on interfaces that were assumed to be internal.
- 04
Which third parties hold routes in, and under what agreement.
What you are left holding
- 01
An evidenced inventory of externally reachable imaging interfaces.
- 02
A separation and access plan sequenced around clinical availability.
- 03
Findings tied to the requirement each one breaches, not to a scanner label.
- 04
Closure evidence that survives an audit or a customer review.
Before you send anything
Plain language is enough — the system, who owns the outcome, and the date that matters. Keep confidential reports, credentials and production data out of a first message; a secure exchange route is agreed before any of it moves. Indicative ranges are exactly that: the scope, exclusions and price are confirmed in a written proposal before work starts.