Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Pen testing · Clinical care providers

Penetration Testing for Medical Imaging Clinics

Penetration testing for an imaging clinic answers one question directly: could your PACS be found the same way unprotected DICOM servers have been found leaking studies across 52 countries? We test what's reachable from the internet, what a compromised workstation could reach inside your network, and whether your teleradiology VPN actually holds under pressure. Testing usually starts before a teleradiology contract, ahead of a modality upgrade, or after a ransomware scare at a comparable clinic.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

What a test has to cover in a RIS/PACS environment

An imaging clinic's attack surface is not a generic office network; it includes protocols and devices most penetration testers rarely encounter.

Internet-facing PACS and archive services

Any PACS, VNA or web-viewer endpoint reachable from outside the clinic's network is tested for the same misconfiguration pattern that has exposed studies at internet scale elsewhere.

DICOM ports on modalities

DR panels, ultrasound carts and MRI or CT consoles expose DICOM services on the network, and testing checks whether they accept connections from further than they should, without disrupting a live scan.

The RIS and its integration points

Scheduling, worklist and billing integrations between the RIS and PACS are examined for authentication weaknesses and lateral-movement paths between the two systems.

The remote-reading tunnel under attack simulation

The tunnel reading radiologists use to reach studies from outside the clinic is tested for the same credential and configuration weaknesses that compromise any remote-access path.

Physician report portals and patient-facing systems

Web portals that let referring physicians or patients retrieve reports are tested from an outside attacker's perspective, since they sit deliberately open to the internet by design.

Regulatory map

Why testing evidence matters beyond the technical finding

No statute names penetration testing directly, but the expectations built around Decision 249 point straight at it.

PHIPA's reasonable-safeguards duty

Section 12(2) requires reasonable steps to protect personal health information, and a documented test is one of the clearest ways a clinic demonstrates it actually verified its safeguards rather than assumed them.

Primary source →

Decision 249's privileged-access guidance

The IPC's prevention expectations following the 550,000-record breach specifically address privileged and administrative access, exactly what a penetration test is designed to probe and prove.

Primary source →

Teleradiology contract security attestations

Hospitals and reading groups increasingly ask for evidence of independent testing before referrals flow through a teleradiology arrangement, making a current report a condition of the contract itself.

Accreditation Canada's inspection-evidence expectations

O. Reg. 215/23's four-year facility-standard cycle looks favourably on a clinic that can produce recent testing evidence alongside its other operational documentation.

Primary source →

What goes wrong

What testing finds before an attacker does

The global pattern behind exposed medical imaging is well documented, and it maps directly onto what a test checks for.

  • A PACS reachable without real authentication

    Investigative reporting found unprotected PACS servers across 52 countries leaking studies, describing the failure as walking through an open door rather than a sophisticated hack, exactly the exposure a test is built to catch.

    Source →

  • A modality accepting unauthenticated DICOM connections

    Some devices ship configured to accept connections from any address on the network, a setting testing surfaces before it becomes the path a ransomware actor takes to the archive.

  • A dormant administrative account like Decision 249's

    The clinic behind the province's flagship ransomware case was breached through a privileged account nobody had disabled; testing includes checking for exactly this kind of forgotten access.

    Source →

  • A teleradiology tunnel with weak credentials

    A VPN into the reading workflow protected only by a shared password or missing MFA is one of the more common findings in remote-access testing across healthcare environments generally.

Our pen testing for medical imaging clinics

What our imaging clinic testing engagement includes

Deliverables built to answer both the technical question and the question your teleradiology partner or inspector will ask next.

Two data analysts Working on data analysis dashboard for business strategy
  1. Scoped vulnerability exploration

    High-level testing across the PACS, RIS, modality network and remote-access points the clinic controls directly, identifying where weaknesses may exist before they're exploited.

  2. Modality-safe testing methodology

    Devices connected to active patient care are tested with methods and timing agreed in advance, so probing DICOM ports never risks interrupting a scan in progress.

  3. Response capability observation

    Insight into how your environment and staff react during simulated attempts, useful for judging whether detection and escalation would actually work during a real incident.

  4. Defensive improvement guidance

    Directional findings on where controls need strengthening, prioritized so a small IT team or MSP can address the highest-risk items first rather than working a flat list.

  5. A report built for a teleradiology partner or inspector

    Findings are written so both your clinic leadership and an outside party requesting attestations can follow them without needing a security background to interpret the results.

How the engagement runs

How testing is scoped around a live clinical environment

The first conversation is about what's safe to touch and when, given patients are being scanned during business hours.

  1. Step 1

    Define scope and safe testing windows

    We confirm with your PACS administrator and IT support which systems can be tested during clinic hours and which require an after-hours window around modality connections.

  2. Step 2

    Test the environment

    PACS, RIS, remote-access points and, where agreed, modality network segments are tested using methods matched to a clinical setting, not a generic corporate playbook.

  3. Step 3

    Report findings by priority

    Results are delivered with clear severity and remediation guidance, organized so your IT lead or MSP can act on the highest-risk items first.

  4. Step 4

    Retest and document for the contract or inspection file

    A follow-up check confirms fixes hold, and the full record becomes evidence you can hand to a teleradiology partner or produce during an inspection.

What it costs

What drives penetration testing pricing for an imaging clinic

Cost follows scope: how many systems and sites are in play, whether modality DICOM testing is included alongside the PACS and RIS, and whether a teleradiology VPN or a physician report portal adds testing surface.

A single ultrasound clinic testing one PACS instance costs far less than a multi-site MRI and CT group testing modality networks, teleradiology links and a portal at the same time. Tell us your systems and site count and we will scope a tailored quote.

Medical Imaging Clinics: Pen testing questions, answered

That's exactly what the engagement determines. Testing checks whether your PACS, archive or web-viewer endpoints are reachable from outside the clinic network the way investigative reporting found unprotected servers leaking studies across 52 countries. Where an endpoint needs to be internet-facing for a legitimate purpose, testing verifies the authentication in front of it actually holds rather than assuming a firewall rule is sufficient.

Yes, with agreed methods and timing that keep active patient care untouched. Modality testing typically happens outside scanning hours or against a configured test environment where one exists, and the rules of engagement explicitly define which devices are in scope, which are observed only, and what to do if anything unexpected occurs during the test window.

The engagement tests the tunnel's authentication strength, whether MFA is actually enforced rather than optional, and whether a compromised set of credentials could reach further into the RIS or PACS than a reading radiologist's role requires. Weak remote-access credentials are among the more common findings in healthcare environments generally, and a teleradiology link is exactly the kind of connection worth verifying before, not after, a contract depends on it.

Annually as a baseline, with an additional test around any major change, a new modality, a teleradiology contract, a PACS migration, since new integration points are where configuration mistakes most often hide. A clinic preparing for an Accreditation Canada inspection or a hospital's teleradiology security attestation typically times a test to land shortly before that review.

No, that's built into the scope from the start. Rules of engagement set testing windows around clinic hours, exclude live modalities from disruptive techniques, and include an agreed process to pause immediately if anything unexpected happens. Your PACS administrator has a direct line to the testing team throughout, so a false alarm never turns into an interrupted scan.

It gets documented clearly and routed correctly. If a finding traces to a setting your team controls, it goes into your remediation list like any other result. If it points to a default configuration shipped by the PACS or modality vendor itself, we write it up so you can raise it with the vendor directly, since that's a conversation the clinic needs vendor cooperation to resolve.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.