Securing PACS and DICOM Ingestion and Access

In this fictional design, PACS authenticates the gateway forwarding images and the account used by the viewer. Scanner origin is asserted by the gateway; permission to view an examination depends on the viewer’s staff policy. Reviewing only the archive connection misses both decisions.

The goal is timely access to the correct patient’s complete CT examination. Images, patient and exam details (metadata), credentials and temporary copies need protection. NIST identifies disclosure, alteration and disruption across the imaging ecosystem. 2

The modeled environment

PACS, the picture archiving and communication system, provides the image archive and catalog here. DICOM, Digital Imaging and Communications in Medicine, defines imaging objects and communication services. A study groups examination objects; an instance is one object, not necessarily one image slice.

A gateway queues complete objects before forwarding them to PACS. The server-side viewer retrieves through HTTP-based DICOMweb. 9 Reporting and external exchange are outside scope. Login, name resolution (DNS), time, storage, backups and vendor support remain dependencies. These controls are assumptions; the loopback lab tests only part of F1 and F2.

Reading the architecture

Before scanning, the CT scanner queries the radiology information system (RIS) for scheduled examinations and patient details, known as the worklist (F5). It creates images and sends them to the gateway (F1), which holds them for forwarding to PACS (F2). 2 10

The clinician signs in to the viewer (F3). After checking permission for the examination, the viewer fetches images using its own system account (F4). The identity service supports staff login. A support broker restricts the vendor’s maintenance access (F6).

Figure 1. Fictional architecture and assumed controls.

The F labels identify connections, not step numbers: F5 precedes scanning. C-FIND queries the worklist; C-STORE sends an object for storage. 10 16 On F4, the viewer opens the request and PACS returns the images.

Dashed zones mark logical trust boundaries. Their enforcement still needs verification against the actual initiator, receiver, port and service. Login failure can block viewing while stored images remain intact.

Where trust changes

This scanner is assumed to lack Transport Layer Security (TLS), leaving F1 and F5 unencrypted. An attacker able to observe or alter those paths could disclose patient details or manipulate submitted data. An admitted sender could also submit misleading objects after compromise.

The gateway buffers receiver outages but concentrates sending authority and patient data. A compromised viewer account can expose examinations within its retrieval scope; vendor credentials may permit administrative changes. These modeled scenarios depend on this architecture, not inherent DICOM weaknesses. The proposed controls focus on reachable scanner paths, approved sending roles and limits on viewing and administration.

Controls at each boundary

Preserve patient and study identity

Patient ID is scoped to its issuing system or organization, the assigning authority. Study Instance UID is the study’s unique identifier; Accession Number identifies the imaging request. Issuer of Patient ID may be absent, requiring documented mapping rather than a merge on patient ID alone. 11 12

RIS is the order authority here. Wrong worklist selection or altered F5 details can link intact images to the wrong patient. Encryption cannot repair that linkage. The clinical identification workflow must reconcile patient, request and study details with the order. Matching identifiers or pixel hashes (data fingerprints) establishes a data comparison, not clinical correctness. Corrections belong in approved clinical reconciliation.

Admit senders and approve ingest roles

On F1, source-IP and Application Entity (AE) Title allowlists restrict sender admission. An AE Title names an application; it provides no cryptographic proof of device identity. 3 Limit scanner connections to the gateway and RIS. This bounds exposure while F1 and F5 remain plaintext. Supported input checks, resource limits and parser updates address harmful submissions; malformed and oversized inputs need isolated tests. 15

Require mutual TLS on F2 and map the validated peer to an approved sending role. TLS-profile support does not establish that mutual authentication is enabled; certificate-authority (CA) trust does not grant sending permission. Configuration and access policy remain site decisions. 4 14 PACS authenticates the gateway’s certificate. Record claimed scanner origin separately because a compromised gateway can falsify it.

Separate viewing from administration

F3 uses staff single sign-on (SSO) and multifactor authentication (MFA); the viewer enforces study permission. Its read-only svc_viewer account on F4 is distinct from the clinician and needs a restricted retrieval scope where supported. Linked audit records support attribution. A compromised read-only account can still disclose images.

Vendor maintenance on F6 needs named accounts, MFA and approval for the destination and operation. Session expiry must end access inside PACS, including downstream sessions. Blocking direct vendor routes and recording the operator’s changes make the broker a controlled maintenance path.

Test the required service

Check network reachability and TLS before the DICOM association, a negotiated application session. The required SOP Class (service or object type) and transfer syntax (encoding) must be accepted. 3 C-ECHO exercises Verification; CT Storage requires a representative synthetic transfer. 13

This viewer uses DICOMweb. A C-MOVE design would make the archive open a separate C-STORE connection to the destination, requiring its own firewall rule. 8 Compare observed ports and directions with the vendor’s conformance statement, its declared capabilities. 6

What the transfer experiment established

An AI assistant generated and executed the loopback experiment using pydicom, pynetdicom, a SQLite queue and custom receivers. It did not implement a commercial PACS. The two minimal CT Storage fixtures are not validated diagnostic images. Code and logs record:

Test Observed result and meaning
Unapproved application name (calling AE) DICOM association refused; no queued objects. The gateway’s admission rule rejected this sender.
Accepted sender Gateway returned two C-STORE success responses (0x0000); two queued objects; zero archive receiver records. Acceptance preceded onward delivery.
Archive receiver stopped Both connection attempts failed with connection refusal; both objects stayed queued.
Client certificate omitted Both attempts failed with certificate-required TLS alerts; both objects stayed queued.
Forwarding restored with client certificate Archive receiver recorded two objects; queue empty. Study and instance identifiers, patient details and pixel hashes matched. Clinical correctness was not tested.
Communication-only peer C-ECHO succeeded (0x0000); the CT Storage presentation context was not accepted. Verification worked without CT Storage support.

The gateway returned success after committing each object to its queue. CA trust and calling-AE admission were separate checks, without certificate-role binding. The harness deleted queue rows after the archive receiver’s C-STORE success, without Storage Commitment. Production use needs a reviewed safekeeping and retention policy. Lost acknowledgments, duplicate delivery, power loss, malformed inputs and disk exhaustion remain untested.

Permission tests and audit records

Figure 2 proposes authorization tests; F3–F6 and network segmentation remain untested. A trusted but unapproved sender should reach the ingest policy and be denied. A logged-in clinician requesting an unauthorized study should reach the viewer policy and be denied. Pair each with an allowed request and retain the identity and policy decision; connection failure alone cannot establish a role denial.

Proposed permission tests and the records needed to interpret them.

For investigation, audit records need transfer receipts, rejections, TLS errors, study-access decisions and vendor changes. Separate the observed network peer, claimed AE, authenticated TLS peer and assigned role. Link staff, service account, study and outcome so investigators can trace an access decision across the viewer and archive.

Logging coverage needs its own check: DICOM audit formats do not guarantee an event for every operation. 5 Verify allowed and denied events, timestamps and protected collection before interpreting a missing record. Alert when collection stops; restrict log access and retention, and minimize patient details.

Recovery and production checks

The lab establishes gateway receipt and onward delivery under its test conditions. C-STORE success reports storage at the responding peer; Storage Commitment separately addresses safekeeping under documented implementation terms. 1 16 Clinical access still depends on the viewer and login path.

Start a production review with enabled settings, not declared capabilities. Record controls as configured, unavailable or unverified, with a risk owner and compensating measures for gaps. Replacing plaintext paths needs vendor and clinical-engineering involvement. Certificate and credential ownership matters because a renewal failure can interrupt transfer without an intrusion; establish the affected path before containment.

The queue holds full objects with patient details. Restrict access, encrypt stored data where supported and agree retention. Imaging operations should size it for peak arrivals, outage duration and backlog clearance, then monitor free space and oldest-object age. A full queue needs supported refusal or sender buffering, never acknowledgment of an object it cannot retain. Two fixtures provide no capacity evidence.

Radiology and clinical engineering should agree recovery objectives and a diagnostic fallback, including needed prior studies. Validate the surviving route during targeted containment and use approved downtime procedures if login fails. HHS recommends segmentation, central logs and rehearsed incident response. 7

Primary sources

The references cover DICOM protocol definitions, NIST’s imaging security analysis and HHS operational guidance.

  1. DICOM PS3.4 Storage Commitment — J.1.1–J.1.2.

  2. NIST SP 1800-24B Securing PACS — Final December 2020; sections 1.1, 3.4 and 4.1–4.2.

  3. DICOM PS3.8 Association parameters — 7.1.1.3–7.1.1.4 and 7.1.1.13.

  4. DICOM PS3.15 TLS transport profile — B.12.

  5. DICOM PS3.15 Audit messages — A.5.3.

  6. DICOM PS3.2 Security in conformance statements — N.8.1.

  7. HHS Healthcare Cybersecurity Performance Goals — Network Segmentation, Centralized Log Collection and Incident Planning.

  8. DICOM PS3.4 C-MOVE operation — C.4.2.

  9. DICOM PS3.18 Web Services scope — Section 1.

  10. DICOM PS3.4 Basic Worklist Management — K.1.1 and K.1.4.

  11. DICOM PS3.3 Issuer of Patient ID — 10.15.

  12. DICOM PS3.3 General Study Module — C.7.2.1.

  13. DICOM PS3.4 Verification Service — A.1.1.

  14. DICOM PS3.15 Security scope — 1.1.

  15. NIST SP 800-218 SSDF Version 1.1 — February 2022; PW.8.

  16. DICOM PS3.7 DIMSE-C C-STORE service — 9.1.1.

Next
Next

Revisiting Security+ Controls Through an AWS and Splunk Homelab