© Gorodenkoff – stock.adobe.com

Article • Exploring safeguards and incident response

Radiology vs. ransomware: How to defend imaging departments against cyberattacks

Cyberattacks on healthcare have reached unprecedented levels, with radiology departments emerging as particularly vulnerable targets. At the Society for Imaging Informatics in Medicine (SIIM) 2026 annual meeting in Pittsburgh, four authors of the new ACR/SIIM cybersecurity guidelines outlined the threats facing imaging enterprises – and the strategies needed to defend against them.

Report by Cynthia E. Keen

Healthcare has become the most targeted sector for cybercriminals. In 2024, at least 289 cybersecurity incidents affected EU healthcare providers – more than any other essential sector, according to the European Commission's Annual Report on NIS Directive Incidents. Ransomware attacks accounted for an estimated 71% of incidents that disrupted patient care, delaying diagnoses and treatments.1 In January 2025, the European Commission developed an Action Plan on the Cybersecurity of Hospitals and Healthcare Providers to strengthen the EU healthcare sector's cyber-resilience.2 

Portrait photo of Po-Hao Chen, MD
Po-Hao Chen, MD

Photo courtesy of Dr Chen 

The situation in the United States mirrors this trend. The FBI reported that in 2025, healthcare organisations experienced 182 data breaches and 460 ransomware attacks – the highest number among all critical infrastructure sectors.3 

‘Although no published data exists on successful attacks against hospital radiology departments specifically, they have increased exponentially since 2000’, said Po-Hao Chen, MD, security committee chair of the SIIM. That year correlates with the widespread conversion of US hospital radiology departments to all-digital functionality. 

In response to these growing threats, the American College of Radiology (ACR) and SIIM published comprehensive guidelines in 2025 for radiology department staff and IT/PACS administrators to protect radiology data and devices against cybersecurity threats.4 

Why radiology is particularly vulnerable

Portrait photo of Reza Forghani, MD, PhD
Reza Forghani, MD, PhD

Photo courtesy of Dr Forghani 

Radiology departments offer an abundance of opportunities for cyberattacks due to their large attack surface comprising multiple vulnerabilities and transfer risks. ‘Cyberattacks are not just an inconvenience, or just an IT issue, but rather a patient safety and operational issue’, said Reza Forghani, MD, PhD, neuroradiologist, medical AI expert, and chief medical information officer for imaging at AdventHealth, a non-profit healthcare system with 57 hospital campuses in nine US states. 

Categories of vulnerability include people, processes, physical equipment, software and hardware technologies, the supply chain, and third-party vendors. Locations of data transfer risk span EHR order entry, radiology information systems (RIS), modality imaging acquisition, PACS, archival storage, VNA, workstation use, radiology report preparation, and interactions with other radiology-specific software tools. 

An additional threat is the use of AI systems. These can impact modality image reconstruction, subsequently add or subtract artefacts, and distract radiologists from accurately diagnosing or making other assessments about an imaging exam. ‘AI is offering convenience to radiologists, but these conveniences and shortcuts also increase cybersecurity risks’, said Dr Forghani. He pointed out that overlooked vulnerabilities include offsite stolen credentials, which – with clever phishing – can open doors. Mobile data sources, such as USB drives and DICOM CD/DVDs, are easy to steal sensitive data from, or can be used to inject malware. Their contents should never be directly inputted into a hospital's system without rigorous safeguard review, he cautioned. 

Building layered defences

Safeguards must be numerous, layered, and always kept current for both internal operations and vendor ecosystems. Physical and technical controls must align perfectly. Monitoring must be continuous and immediately adaptable to new techniques and the mutational nature of cyberattacks. Regularly scheduled training is essential for all hospital staff whose jobs are impacted by a breach. 

Key safeguards are physical, technical, and administrative. Similar to legs on a stool, if any one becomes weak, the entire infrastructure becomes unstable

Benoît Desjardins

‘People are the weakest components of cyberattack protection. They can be duped during social interaction or clever phishing, and they may be lax in adhering to the protocols of strict physical security standards’, said Prof. Benoît Desjardins, MD, PhD, professor of radiology, Chief Medical Information Officer and Chief Medical Cybersecurity Officer at the Centre Hospitalier de l'Université de Montréal and the University of Pennsylvania. ‘Key safeguards are physical, technical, and administrative. Similar to legs on a stool, if any one becomes weak, the entire infrastructure becomes unstable.’ 

Physical safeguards – the first line of defence – require multiple layers of access control: locked doors, key cards, biometric scans, cameras, disabled USB ports, firewalls, and intrusion detection systems. Modality patches and software updates should be implemented immediately. Outdated workstations, hard drives, and media such as CD/DVDs should be disposed of in accordance with security protocols because they can contain recoverable data. 

Recommended article

Photo

Article • ECR 2026 explores LLM-based vulnerabilities

Poisoned pixels, phishing, prompt injection: Cybersecurity threats in AI-driven radiology

One phishing email sends an entire county’s health service back into the age of pen and paper for months. A hidden prompt is buried within an abdominal CT image: At ECR 2026 in Vienna, cybersecurity experts presented real-world cases that read like ghost stories: tales that exemplify new vulnerabilities in modern AI-driven radiology systems – and how to avoid them.

The imperative of continuous governance

Technical data protection mandates continuously updated policies and procedures. Passwords need frequent changes. Access to data needs adjustment with every personnel change. Audit logs, containing alerts, need rigorous monitoring. Regular training of all staff is essential because it reinforces cyber awareness. Training topics should include incident recognition, reporting, password management, workstation security, and social engineering protection. 

Prof. Desjardins emphasised that administrative safeguards to manage access and data throughout their life cycle are imperative. ‘Continuously assess cybersecurity risks, because threats evolve constantly. Programs must be designed to evolve with the ever-changing nature of cybersecurity attacks’, he explained. ‘Without continuous governance, technical controls become ineffective. A useful mindset is to presume an attack is already underway and to prepare accordingly.’ 

Resources need to be prioritised. Security policies for clearly established regular risk assessments and protocol evaluations need to identify vulnerable systems, networks, and data storage networks. Leadership policies are needed for access control, data encryption, and device management. Protocols are also needed for access, retention, and disposal of radiology records to ensure compliance. 

All vendors and third-party contractors must be held to the same standards and policies. Vendor ecosystems increase operational risk exposure. ‘Require a cybersecurity bill of materials for cyber devices. Always incorporate in contracts breach notification and rights to access vendor logs upon request, no matter how frequently’, recommended Prof. Desjardins. 

When disaster strikes: incident response and recovery

Portrait photo of Prof. James T. Whitfill, MD
Prof. James T. Whitfill, MD

Photo courtesy of Prof. Whitfill 

In spite of best efforts, what happens if a hospital gets attacked and the radiology network becomes inoperable for weeks? Prof. James T. Whitfill, MD, Senior Vice President and Chief Transformation Officer at HonorHealth, a non-profit Arizona-based health system with nine hospitals, described just how uninformed hospital clinicians and staff who rely on radiology department services may be. 

‘Ask hospital peers how they would respond to a cyberterror event. The most common response may be: “We'll wait for the network to come back up. The IT department will fix it”’, Prof. Whitfill commented. ‘Well, eventually. What people don't realise is that an outage due to a ransomware attack can take an entire network down, even unaffected parts that are shut down for protection.’ From his experience, a major cyberattack may take at least a week for the forensics alone to be done, assessing the extent of the damage done, and what it will take to cleanly restore. 

Radiologists can interpret images directly from the modality, but most modalities go into autopurge mode when their storage is full, the expert continued. To avoid data loss, scanners should therefore be equipped with additional external storage options, he advised. It should also be clear how reports and images are kept in sync when trying to restore them. 

How to get prepared for the worst-case scenario

Prof. Whitfill explained that a hospital incident command will have the goal of maintaining operations and prioritising needs. Technology response teams will start by assessing the extent of the attack. They go to backup copies and work backwards to try to identify where and when the attack began – to find a safe space to start the restoration. It is imperative to evaluate the viability of backups. Restoration plans for different scenarios, such as bare metal restore and file restoration, are needed because it may be necessary to replace contaminated hardware as well as reinstall software. 

The expert provided his audience with a comprehensive list on how to prepare: ‘Bring every potentially impacted leadership team into the same room to hear the consequences that radiology network downtime would cause. Get feedback. Develop and play simulation exercises. Compare simulated downtime events for discrepancies with downtime plans. Make corrections.’ 

'Recovery may be very piecemeal. System restoration versus system recovery are different. Predefine which clinical systems are restored first. Improvised work introduces errors which need to be identified. Reports and images have to be reconciled, and critical findings may have to be added manually. All this needs to be planned for. Educate, educate, educate. Practice simulations regularly and repeatedly', Prof. Whitfill concluded. 


Profiles: 

Po-Hao Chen, MD, is Vice Chair of Artificial Intelligence and Medical Director for Enterprise Radiology Informatics at the Enterprise Diagnostics Institute of Cleveland Clinic in Ohio, USA. He chairs SIIM's security subcommittee and is the lead author of the ACR/SIIM white paper on protecting radiology data and devices against cybersecurity threats. 

Benoît Desjardins, MD, PhD, is Professor of Radiology at the Centre Hospitalier de l'Université de Montréal (CHUM) in Quebec, Canada, and Professor of Radiology and Medicine at the University of Pennsylvania, USA. 

Reza Forghani, MD, PhD, is Chief Medical Information Officer for Imaging at AdventHealth, a large US non-profit healthcare system with 57 hospital campuses in nine states. A neuroradiologist and medical AI expert, he also serves as Chief of Imaging Informatics at AdventHealth Medical Group Central Florida Division. 

James T. Whitfill, MD, is Professor of Medicine at the John Shufeldt School of Medicine and Medical Engineering of Arizona State University in Phoenix, USA. He is also Senior Vice President and Chief Transformation Officer at HonorHealth, a non-profit Arizona-based health system. 


References: 

  1. Annual report NIS Directive incidents 2024. CG Publication. August 2025. https://ec.europa.eu/newsroom/repository/document/2025-31/Annual_Report_NISD_Security_Incidents_2024_lLl8Yt8at5UKGOymYgsc0rxZrpQ_118680.pdf 
  2. Goodger S, Kuiper E. From ransomware to statecraft: Protecting EU healthcare in the new threat landscape. Policy Brief. European Policy Centre. 21 November 2025. https://d1xp398qalq39s.cloudfront.net/uploads/ckeditor/2025/11/21/healthcybersecurity-policybrief-21112025.pdf 
  3. Federal Bureau of Investigation. Internet Crime Complaint Center. Internet Crime Report 2025. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf 
  4. Chen P-H, Desjardins B, Strassner B, Forghani R, et al. Protecting Radiology Data and Devices Against Cyber Security Threats: a Joint White Paper of the ACR and Society for Imaging Informatics and Medicine. J Am Coll Radiol 2025;22:1160-1172. (Open Access) 

03.09.2026

Related articles

Photo

Article • Imaging informatics meeting

SIIM 2020: Glancing back at 40 years and ahead to the future

40 years ago, anticipating the huge impact of computers in radiology, a group of visionaries formed the Radiology Information System Consortium (RISC). In 1989, RISC created the Society for Computer…

Photo

Article •

Think thin, go big

To meet the high demands of today’s radiological environment, a PACS must provide far more than archiving, controlling and distribution of electronic data. Post processing and upgradable network…

Photo

News • Data protection

Imaging IT platform clears cybersecurity bar

Agfa HealthCare has renewed its HITRUST i1 Certification for the second consecutive year, confirming strong cybersecurity controls for its Enterprise Imaging platform.

Related products

Subscribe to Newsletter