What Is Cybersecurity Like in PACS Systems?

Discover the challenges and solutions related to cybersecurity and data protection when choosing a PACS system to improve the management of radiology and medical imaging services.
In the modern world, the use of information technology (IT) has seen extensive development in the medical field. Perhaps one of the greatest advances in hospital management took place in the 1970s, with the introduction of hospital information systems (HIS).
The widespread use of diagnostic imaging modalities such as computed tomography (CT) and magnetic resonance imaging (MRI) also began in the 1970s and 1980s. Meanwhile, picture archiving and communication systems (PACS) and digital copy reading became popular between the 1980s and 1990s. All of this contributed to the electronic exchange of clinical information between institutions, physicians, regions, or even internationally, as is common practice today.
The internet has become an indispensable source of information and an efficient, fast, and inexpensive means of communication. However, the widespread use of information technology and the internet has also created new challenges. An issue that has become increasingly important for hospitals is cybersecurity, a term that the Oxford English Dictionary defines as "the state of being protected against the criminal or unauthorized use of electronic data, or the measures taken to achieve this."
Types of Attacks That Can Affect Hospital Cybersecurity
One particularly damaging type of malware (or malicious software) that affects organizations and computer users worldwide is ransomware. This is software that, once downloaded and executed, proceeds to encrypt as many files as possible and then demands a ransom payment (usually using a cryptocurrency such as Bitcoin), with the promise that the decryption key for the files will be provided after payment, which does not always happen.
A document published by the United States Department of Justice states that in 2016, 4,000 ransomware attacks per day were reported, a fourfold increase compared to 2015. Furthermore, the healthcare sector is among the most affected, accounting for 15% of all cases. It also notes that 50% of all cybersecurity incidents in hospitals in 2017 were related to ransomware.
Furthermore, government institutions around the world have acknowledged that healthcare institutions are part of a society's critical infrastructure, and therefore require complete protection, especially against cyber threats.
For example, the United States and European Union governments have designed specific plans for the protection of cybersecurity in the healthcare sector. Meanwhile, in Germany, hospitals with more than 30,000 patients annually adopted the measures of a cybersecurity law to protect themselves.
What Threats Can Affect Hospital Cybersecurity?
Currently, the cybersecurity threats facing hospitals have reached a new level of alert. While attacks in the past were often widespread and random, they are now increasingly targeting the healthcare sector, which is apparently viewed as an attractive target by the groups behind these threats.
For example, phishing practices (email in which the sender impersonates someone else) or spam (unsolicited email) are common, in which users are generally asked to open an attached file.
However, the spear phishing technique is becoming increasingly common. A user, for example, an employee in the human resources department, will receive a convincing-looking email with an attached or linked document that, when opened, turns out to be malware that infects the computer.
Over the past decade, medical images have largely shifted from printed copies to digital format, for example through PACS systems. These are easier to share, which speeds up diagnosis time. They can also be uploaded, stored, and shared across all types of devices, which also makes them a target for cybercriminals.
In turn, they are also very interested in acquiring other types of medical information that can be highly valuable, such as electronic medical records, regulatory records, hospital information systems, and even information related to governments, academic files, and business records. This leaves healthcare services vulnerable to potential security breaches, allowing cybercriminals to target and steal this important data.
Common Cybersecurity Challenges in PACS Systems
For this reason, when choosing a PACS system, it is good practice to verify that the vendor can guarantee that various electronic security and data protection measures are in place.
The PACS system vendor must offer at least the following cybersecurity guarantees:
- Monitor and control internal user accounts.
- Identify outliers in behavior (for example, a large number of downloads within a short period of time).
- Maintain access control and tracking for all external users.
- The integrity of image data must be guaranteed.
- Constantly monitor connections to the system.
- Full assurance and monitoring of connections to and from systems that are not part of the internal system.
- Provide security, data protection, and access management without affecting the productivity and performance of the system.
When choosing a PACS system, it is important to verify that the vendor complies with international cybersecurity and data protection standards, such as HIPAA compliance.
Security Architecture of PACS Systems
Using commercially available products, the United States National Institute of Standards and Technology (NIST) created a reference network architecture. It provides an example for healthcare providers to separate their networks into zones to reduce access and, therefore, risk.
To minimize risks, the reference architecture in the NIST practice guide presents various technical and process controls to implement. These are:
• A defense-in-depth solution, including network zoning, which allows more granular control of network traffic flows and limits communication capabilities.
• An access control mechanism that includes multifactor authentication for care providers, certificate-based authentication for imaging devices and clinical systems, and mechanisms that limit vendor remote support to medical imaging components.
• Also a holistic risk management approach that includes managing medical device assets, strengthening enterprise security controls, and leveraging behavioral analysis tools for threat management.
References
- Challenges and methods for PACS Systems. 24 by 7 Security.
- PACS: flaws that put data at risk. Data Breach Today.
- Cybersecurity in PACS and Medical Imaging. Springer.
- "Sistemas para archivo y comunicación de imágenes (PACS)" (Systems for image archiving and communication (PACS)). Guía tecnológica no. 41 (Technology Guide No. 41). Secretaría de Salud, México (Mexican Ministry of Health), 2009.