Saltar al contenido

Tema de color

Región

Abre la misma página en otro sitio regional.

Idioma del sitio (Chile)

Español o Inglés. Aplica a este sitio regional.

Buscar en el sitio

Buscar páginas y artículos

Ctrl+K · Buscar en el sitio
Menú

Algunas páginas de detalle pueden mostrarse en inglés mientras completamos la traducción.

Cyber security for radiology and medical imaging

Cyber security for radiology and medical imaging practices

An imaging group concentrates cyber risk: the PACS archive is patient data at scale, modalities are long lived devices, and downtime stops reporting. Trucell secures radiology and imaging estates with certified controls, tested recovery, and the evidence your insurer and board actually ask for, from a partner whose ISO/IEC 27001 scope explicitly includes PACS/DICOM administration.

The audit is free for existing imaging practices: read only access, a written report, and no obligation to engage us afterwards.

At a glance

  • Imaging practices are a target because the value is concentrated: a PACS archive is patient data at scale, modalities are long lived devices that outlast their security support, and downtime stops reporting, which stops the practice.
  • Defensible looks like three things: certified controls rather than asserted ones, recovery that has been tested against real imaging volumes, and evidence an insurer or board reviewer will accept.
  • Trucell is ISO/IEC 27001:2022 certified with a scope that explicitly includes PACS/DICOM administration, holds an annual SOC 2 Type II report available under NDA, and publishes fixed price Essential Eight uplift packages.
  • The lowest risk starting point is the free 7 day Imaging Practice IT Risk Audit: a written record of where your estate stands, yours to keep whether you engage us or not.

Is this page for you?

Next step: book the free 7 day Imaging Practice IT Risk Audit (existing practices only). Prefer to start with a conversation? Book a fit call and we walk through where your estate stands against the controls your insurer expects, in plain language, before anything is scoped.

  • CFOs, practice principals, and board members of radiology and imaging groups who need to know whether the practice could survive a cyber event, and prove it.
  • Practices facing a cyber insurance renewal questionnaire that nobody inside the business can confidently answer.
  • Imaging groups whose IT is run by a generalist provider, where nobody clearly owns the security of the PACS archive, the modalities, or the reporting chain.
  • Boards that want evidence: certified controls, tested restores, and monitoring reports, rather than reassurance that everything is fine.

This page is not a technical hardening guide. If you run the systems day to day, start with our radiology IT support and managed security pages. This one is written for the people who sign the insurance renewal and answer to the board.

Evidence a board can verify before the first meeting

These are the same signals we hand to insurers, brokers, and procurement reviewers. Trucell, established in 2005, has supported medical imaging for almost two decades and supports 50+ healthcare sites across Australia.

  • ISO/IEC 27001:2022 with imaging in scope

    Certified for Trucell Pty Ltd by Citation Certification (JAS-ANZ accredited), certificate 500-27285-IS. The certified scope explicitly includes PACS/DICOM administration and the DICOMJet platform, so the management system audited each year is the one that touches your imaging estate. See governance and assurance.

  • Annual SOC 2 Type II report

    An annual SOC 2 Type II attestation report covering security controls across our service delivery environment, available to your reviewers under NDA as part of vendor risk assessment. See certifications.

  • Fixed price Essential Eight uplift

    ACSC Essential Eight assessment and uplift sold as fixed price packages, so the board approves a known scope and cost rather than an open ended security project. See Essential Eight.

  • Free 7 day Imaging Practice IT Risk Audit

    For existing imaging practices: a free, read only review of PACS and RIS uptime evidence, backup restore history, and security posture, delivered as a written report. See the risk audit.

Next step is the free 7 day Imaging Practice IT Risk Audit: read only access, a written report, and no obligation to engage us afterwards.

The risks an imaging board rarely sees until renewal time

Most imaging practices do not discover their cyber gaps in an attack. They discover them in an insurance questionnaire, a broker meeting, or a board paper nobody can complete.

These are the patterns we see most often when we review radiology and imaging estates. None of them show up in a normal IT report, and every one of them turns into a hard question at renewal.

  • The insurer questionnaire nobody inside the practice can answer: multi factor authentication coverage, endpoint detection, tested restores, network segmentation. The questions map closely to the Essential Eight, the deadline is the renewal date, and "our IT company handles that" is not an answer a board can sign.
  • A flat network where modalities sit beside reception PCs: one phishing click at the front desk and the scanners, the PACS archive, and the reporting workstations are all reachable on the same segment.
  • Backups that have never been restore tested against imaging volumes: a nightly job that reports success is not evidence the archive comes back, or of how long reporting is down while it does.
  • Incident plans that assume email still works: contact trees, playbooks, and insurer notification steps stored on the same systems an attacker has just encrypted.

None of these are exotic. They are the ordinary state of imaging estates that grew one modality and one workstation at a time, and every one of them is fixable with a plan the board can see and approve.

What a defensible imaging estate looks like

Defensible means an insurer, a broker, or a board reviewer can look at the controls and the evidence behind them and accept both. This is what we put in place for radiology and imaging groups.

  • Essential Eight uplift mapped to imaging estates

    ACSC Essential Eight assessment and uplift in fixed price packages, applied with imaging in mind: application control and patching planned around modalities and reporting workstations that cannot simply reboot mid list. See Essential Eight.

  • Network segmentation for modality and PACS pathways

    Modalities, the PACS archive, reporting workstations, and the front office separated so one compromised PC cannot reach the imaging chain. Designed and managed as part of network services.

  • Backup and restore evidence at imaging volumes

    Immutable backup with restores tested against real imaging volumes, so the evidence shows how long the archive takes to come back, not just that a job ran overnight. See backup and recovery.

  • SOC and SIEM monitoring

    Detection and response workflows that bring endpoint, identity, and Microsoft 365 signals into one escalation path, so an incident is noticed and owned rather than discovered by a radiographer mid list. See SOC and SIEM solutions.

  • Recovery capability proven in imaging

    Recovery is a capability, not a document. Example: full estate rebuild and security recovery for Quantum Radiology Group after a serious cyber event, with work that supported cyber insurance placement after assurance reviews.

  • Insurer and board evidence packs

    What we provide is the technical evidence: control status, restore test records, monitoring reports, and certification references your broker and board can work from. The wording of your policy and disclosures stays with your broker.

Start with evidence, not a proposal

The free 7 day Imaging Practice IT Risk Audit (existing practices only) gives you a written record of where your estate stands: PACS and RIS uptime evidence, backup restore history, security posture, and a plan to close the gaps. Yours to keep, whether you engage us or not.

¿Prefiere hablar ahora? +56 2 2581 4440

A generic security vendor vs an imaging literate security partner

The tools overlap. The difference is whether the people applying them understand what a radiology practice can and cannot switch off.

With an imaging literate security partner

  • Segmentation, patching, and application control planned around modalities, PACS and RIS, and reporting deadlines, so security work does not stop the list.
  • Restore evidence measured against imaging volumes and reporting downtime, which is the measure your board actually cares about, not a generic backup tick.
  • Certification that names your world: an ISO/IEC 27001 scope that explicitly includes PACS/DICOM administration, plus an annual SOC 2 Type II report your reviewers can read under NDA.

With a generic security vendor

  • Controls deployed as if the practice were an office: a patching window that reboots a modality mid list, or application control that blocks the RIS.
  • Backup reports that say success while nobody has ever timed a restore of the archive, so the first real test happens during the incident.
  • Security described as good practice, with no certification scope covering imaging and no evidence pack when the insurer or the board asks.

Cyber security for radiology FAQ

What principals, CFOs, and board members ask before committing to security work.

Will this satisfy our cyber insurer?

We cannot promise what an insurer will decide, and you should be wary of anyone who does. What we provide is the evidence that controls exist and are tested: Essential Eight posture, restore test records, monitoring reports, and certification references your broker can put in front of the underwriter. The insurer decides what that evidence is worth. Our job is to make sure it exists and stands up to review.

Do we have to replace our current MSP to get security?

No. Security can run co managed alongside your existing provider: we take ownership of the security controls, monitoring, and evidence while your current provider keeps running day to day IT. If you later want one accountable owner for both, that is a separate decision you make with the audit findings in hand.

Where do we start?

For existing imaging practices, start with the free 7 day Imaging Practice IT Risk Audit. It is read only, it needs very little of your team's time, and it produces a written record of where you stand: the document you would want in front of the board before approving any security spend.

Why does the ISO 27001 scope wording matter?

Any provider can hold an ISO 27001 certificate for something. What matters is what the certified scope covers. Trucell's ISO/IEC 27001:2022 certificate (500-27285-IS, Citation Certification, JAS-ANZ accredited) explicitly includes PACS/DICOM administration and the DICOMJet platform, which means the management system an auditor reviews each year is the same one that touches your imaging estate, not just our own office IT.

What does this cost?

The risk audit is free for existing imaging practices. Essential Eight uplift is sold as fixed price packages, published on the Essential Eight page. Broader security scope, such as segmentation, monitoring, and recovery work, is scoped and priced after the audit, because the honest answer depends on the size and state of your estate. We do not publish generic prices for work we have not scoped.

Give your board an answer it can rely on

Book the free 7 day Imaging Practice IT Risk Audit (existing practices only) and get a written record of where your estate stands, or book a fit call if you would rather start with a conversation. Either way, you leave with a clearer picture of your cyber risk and what it takes to make it defensible.

¿Prefiere hablar ahora? +56 2 2581 4440

On the call, mention how many sites you run, your PACS and RIS platforms, when your cyber insurance renews, and who manages your IT day to day.

Explore related areas

Most imaging groups we secure touch more than one of these areas.