Securing PACS & Imaging Infrastructure: Protecting the Foundation Beneath Modern Radiology
CybersecurityOctober 1, 2026

Securing PACS & Imaging Infrastructure

Protecting the Foundation Beneath Modern Radiology

Securing PACS and imaging infrastructure is crucial as the cybersecurity landscape continues to evolve. Radiology organizations have always faced a difficult infrastructure challenge: managing enormous amounts of highly valuable data while ensuring that clinicians can access images and information when they need them. Today, that challenge extends well beyond storage capacity and application performance.

 

PACS environments, imaging applications, HL7 interfaces, servers, databases, networks, APIs, workstations, and other connected systems create an increasingly complex infrastructure ecosystem. Every connection between those systems creates another potential path that must be understood and protected.

 

For radiology organizations, securing your imaging environment means protecting more than the data itself. It means understanding and securing the infrastructure that moves, stores, processes, and provides access to that data.

Why Is Medical Data So Valuable?

Medical data is extremely valuable to attackers. This is because protected health information (PHI) is worth a lot of money on the black market. Medical records often contain Social Security numbers, birthdays, and contact information, which can be used to commit identity theft. Attacks on healthcare organizations often involve attempts to obtain data for fraudulent activity or attempts to encrypt existing data and prevent legitimate users from accessing it until a ransom is paid. Healthcare facilities are seen as easy targets for attackers as they often don’t have the financial means or expertise to prioritize cybersecurity. The focus is on their patients, not their technology systems.

 

According to the FBI’s Annual Internet Crime Report, healthcare/ public health was the most targeted sector for ransomware in 2025. This sector also ranked number 3 for the most data breaches that year. The HIPAA Journal reports that the number of data breaches reported by HIPAA-regulated organizations continues to increase every year, with healthcare breaches in 2023/2024 reported at twice the rate they were reported in 2018. IBM’s 2026 Cost of a Data Breach Report also notes an average healthcare breach cost of $6.64 million.

 

Radiology practices in particular are attractive targets due to the volume and value of the data they manage.

Why Is Radiology at Risk?

Medical imaging generates enormous files, and even compressed images require significant storage capacity. Imaging environments must also manage large numbers of smaller files and messages, including HL7 data. A single image can generate multiple HL7 files, meaning that large practices may ultimately manage millions of individual files across their environments. That combination creates a significant infrastructure challenge.

 

There is a tremendous amount of valuable information moving through an imaging environment, often between numerous systems and applications. Healthcare data also requires patient care to be connected across different environments, as medical data frequently moves between clinicians, facilities, and transactions. A study published by the National Institutes of Health (NIH) looked at how healthcare data is remarkably vulnerable to hacking, and specifically how wide variations in digital health usage complicates cybersecurity, as it can be difficult to create solutions that work for each context or clinician.

Securing PACS & Imaging Infrastructure: The image shows a radiology looking at a computer displaying brain scans with an MRI room in the background

PACS Security Is an Infrastructure Problem

PACS load times are extremely important in the field of radiology. Slow PACS performance impacts how long it takes for a radiologist to read and process studies. Radiologists are in high demand, so reliable PACS performance is a significant consideration for radiologists when deciding to work for a practice.

 

PACS is often discussed primarily as an application or data-security concern, but applications don’t exist in isolation. Images move across networks. Applications communicate with servers. Servers access storage. Systems exchange HL7 messages. APIs connect applications and services. Users and devices request access to resources. Each one of these interactions occurs through infrastructure.

 

This is why securing a PACS environment requires visibility beyond the PACS application itself. A secure, infrastructure-focused approach must look at how the entire environment operates:

  • How systems communicate with one another
  • Where imaging data is stored
  • Which systems can access that data
  • How applications communicate with supporting services
  • Where external access exists
  • How permissions are granted and changed
  • How backups are connected to production systems
  • What happens when suspicious activity occurs

Whether your environment is physical/ on-premises (on-prem), virtual, cloud-based, or hybrid, infrastructure remains a key part of the equation.

Cloud Does Not Eliminate the Risk

Moving imaging infrastructure to the cloud can change how an environment is architected and managed, but it does not eliminate the underlying security challenges. Cloud environments still contain servers, applications, storage, networks, credentials, APIs, and numerous connections between systems.

 

The same is true for hybrid environments, where some applications or data may remain on-prem while other services operate in the cloud. Therefore, when considering public cloud vs. private cloud vs. on-prem, it’s important to consider how your imaging environment communicates and what happens if a component is compromised.

The Increasing Complexity of AI-Driven Attacks

One of the biggest changes in the cybersecurity landscape is the rapidly increasing capability of AI models. For example, the recent Open AI-Hugging Face incident demonstrates the potential for AI systems to adapt their approach, identify alternative paths, and work around restrictions rather than simply following a predetermined attack sequence. Copy Fail also shows how attackers are already using AI to accelerate cyberattacks and expand their blast radius.

 

Future attacks may not look like a traditional attempt to compromise a single website, server, or endpoint. Instead, increasingly capable systems could potentially examine an organization’s interconnected environment and identify weaknesses across multiple points of entry.

 

That could include third-party vendors, APIs, websites, email systems, exposed services, and other connected infrastructure. For radiology organizations, this matters because PACS rarely exists as a completely isolated system. Imaging environments depend on numerous interconnected applications and services. As the number of connections increases, the more important it becomes to understand those connections and how to protect them.

Why Security Tools Aren’t Enough

One response to a growing threat landscape is to continue adding security products. However, adding more security tools doesn’t automatically address underlying problems. If an attacker compromises one component of an environment, the critical question becomes: what can that component access next and how far can the attacker get?

 

A properly secured environment should make that path difficult. The goal is to introduce enough controls and obstacles that compromising one system doesn’t automatically put everything else at risk. This is particularly important in imaging environments where PACS, RIS, modalities, databases, storage, interfaces, workstations, and other systems may depend on one another. Security should therefore be considered as an architectural characteristic of the environment rather than a collection of disconnected products.

The image shows brain scans displayed on a computer screen

How to Secure PACS & Imaging Infrastructure

Reduce Unnecessary Access

One of the most crucial things you can do to secure your PACS and imaging infrastructure is to ensure PACS is only exposed to endpoints it absolutely must communicate with.

 

Access should be limited to only what is required, so it’s important for organizations to be smart about what can access PACS. This includes reviewing VPN access and reducing exposed endpoints where possible. VPN endpoints should be limited to specific servers rather than creating unnecessarily broad access into the environment.

 

Zero Trust provides a useful framework: access should not be assumed simply because a user, device, or application is already inside the network. Every request for access should be evaluated according to the appropriate credentials and permissions. For imaging infrastructure, that means thinking carefully about who or what can access PACS, storage, databases, interfaces, and other critical resources.

Monitor for Changes in Access

It’s important to monitor systems for attempts to increase permissions. An attacker who gains access to one account or system may attempt to escalate privileges and expand their access. Monitoring for those behaviors can provide an opportunity to identify suspicious activity before it develops into a larger compromise. However, not all monitoring is created equal. With generic monitoring dashboards, your metrics can appear fine, even when users are experiencing issues or abnormal activity is occurring. Therefore, it is crucial that the metrics you’re measuring are tailored to your organization’s specific workflows.

 

For imaging infrastructure, organizations must look beyond whether a system is technically “up” or whether a firewall is blocking known threats. Security monitoring must continuously consider what systems and users are attempting to do.

 

Who is requesting access?

What are they trying to access?

Are permissions changing?

Is a server attempting to communicate with systems it normally doesn’t communicate with?

Are established patterns of behavior changing?

 

Detailed infrastructure visibility helps answer those questions.

Create Obstacles Between Critical Systems

Another important principle is limiting how easily an attacker can move through the environment. If every system can freely communicate with every other system, compromising one component will provide an attacker with a much larger attack surface. Crafting controlled boundaries between systems can make that movement significantly more difficult. Critical resources should not automatically be accessible from every part of the production environment. Additionally, backups should be isolated and immutable.

 

For a radiology environment, this means carefully considering how PACS, storage, databases, backup systems, modalities, interfaces, and other infrastructure components interact. The objective isn’t simply to prevent an attacker from getting in, but to prevent one compromised component from becoming a pathway to everything else.

Don’t Overlook Internal APIs

APIs can be an important part of modern imaging environments, connecting applications and services that need to exchange information. They can also be an overlooked access path.

 

Internal APIs should be reviewed to ensure they are properly secured and use appropriate authentication mechanisms, including encrypted credentials and security tokens where applicable. The important point is to consider the entire application ecosystem rather than treating PACS as a single isolated application. Every integration creates a relationship. Every relationship should be understood. Every access path should have an appropriate security control.

Building a More Resilient Imaging Environment

Securing PACS and imaging infrastructure requires more than protecting the perimeter. It requires visibility into how the environment actually operates. This means understanding application dependencies, monitoring activity across systems, restricting unnecessary access, creating boundaries between critical resources, securing APIs, designing the environment with multiple layers of protection, and responding when something unusual happens.

 

A modern cybersecurity approach requires a combination of more obstacles, detailed monitoring, and automated responses. Once again, the goal isn’t to build an environment that assumes an attack will never happen. The goal is to build an environment where an attack is harder to execute, easier to detect, and more difficult to expand.

Infrastructure Starts with Understanding the Application

PACS and imaging applications depend on the infrastructure underneath them. Storage, compute, networking, virtualization, security controls, interfaces, backups, and connectivity all affect how those applications perform and how securely they operate.

 

Protecting the infrastructure without understanding the application can leave important gaps. At the same time, optimizing the application without understanding the infrastructure can create performance, reliability, and security problems.

 

A more effective approach is to design and secure the infrastructure around how the application actually works. That means understanding the entire environment — not just the PACS, not just the network, and not just the security tools.

 

Secure the application. Secure the infrastructure. Understand how the two work together.

 

For radiology organizations managing critical imaging data, that integrated approach can help create an environment that is more resilient against both today's threats and the increasingly sophisticated attacks of tomorrow.

 

Is your imaging infrastructure ready for the next threat?

 

Contact Protected Harbor for a Complimentary Radiology Infrastructure Review. Our team of experts will evaluate your environment and identify:

  • Areas of vulnerability
  • Cyberattack blast radius and exposure points
  • Performance bottlenecks tied to infrastructure design
  • Security gaps impacting availability and resilience
  • Opportunities to improve scalability, reliability, and performance

No obligation — just clarity on where you stand.

radiologyhealthcareradiology cybersecurityhealthcare cybersecuritysecuring PACSsecuring imaging infrastructure
PreviousCybersecurity Awareness Month 2026SEPTEMBER 23, 2026Next SaaS Security is ChangingOCTOBER 6, 2026