H-ISAC TLP White HC3 Sector Alert: Picture Archiving Communication Systems (PACS) Vulnerabilities

On June 29, 2021, HC3:Sector Alert Report: 202106291300 was released regarding Picture Archiving Communication Systems (PACS); which are widely used by hospitals, research institutions, clinics and small healthcare practices for sharing patient data and medical images. In 2019, researchers disclosed a vulnerability in these systems that demonstrated potential issues with exposed patient data. These systems, which can be easily identified and compromised by hackers over the Internet, can provide unauthorized access and expose patient records. There continues to be several unpatched PACS servers visible and HC3 is recommending entities patch their systems immediately. Healthcare organizations are advised to review their inventory to determine if they are

For help with Cybersecurity and Risk Advisory Services exclusively for AHA members, contact:

John Riggi

Senior Advisor for Cybersecurity and Risk, AHA

jriggi@aha.org

(O) +1 202 626 2272