The problem
Clinical imaging is the part of healthcare IT that generalist security consultants get wrong, because the constraints are not the ones they are used to.
DICOM was published in 1993 and designed for a trusted, isolated network. Its defaults reflect that: services that answer to anyone who can reach the port, authentication that is optional and frequently unused, and an association model where the reasonable assumption is that everything on the wire belongs there. Then the estate was connected to a wider network, given a web viewer, and joined to a national record.
Nothing about that is a vulnerability in the usual sense. It is a protocol working as designed, in an environment it was never designed for. The published research on exposed imaging archives, and the guidance the US Department of Health and Human Services has issued on PACS exposure, is what happens when that gap is left alone.
Meanwhile the clinical constraint is absolute. You cannot take the archive down for a weekend, you cannot break the modality worklist, and a radiologist who cannot pull a prior is a patient safety issue, not a service ticket.
What you get
- A survey of the imaging estate as it actually is: modalities, archive, worklist, viewers, gateways, routing rules, and every route in and out that somebody added and did not document
- DICOM and HL7 integration reviewed end to end, including the interfaces that were built once and never revisited
- A security assessment written for clinical reality: what can be segmented now, what needs a maintenance window, and what has to wait for a modality refresh
- Migration planning that treats the archive as the asset it is, with study integrity and prior availability as the acceptance criteria rather than an afterthought
- Data protection work on the imaging-specific questions: what is in the metadata, what leaves in a research export, and whether de-identification actually de-identifies
- Documentation your own team can operate from once the work ends
Proof point
Eight years running exactly this environment, from 2010 to 2018: PACS, DICOM, HL7, HIS and RIS implementation, vulnerability management and security audit across live clinical systems, and training clinical staff to operate them safely. The healthcare AI assurance practice grew out of it, which is why the questions here start with how the estate behaves rather than with a control framework.