7 Numbers Every Imaging Director Should Know Before Renewing PACS Support

96% of health systems had an unplanned IT outage in the last 3 years. Seven real numbers imaging directors should check before renewing PACS support.

7 Numbers Every Imaging Director Should Know Before Renewing PACS Support

A managed PACS support renewal is usually decided on price and on whether last year felt bad. Neither is a measurement. The seven numbers below come from 2026 healthcare IT downtime research and industry breach data, and each one changes something specific about how a PACS support agreement should be written. Bring them to the renewal meeting and the conversation moves from impressions to evidence.

By Trisha Seal — September 11, 2026. RAD365 provides vendor-agnostic 24/7 managed PACS support — proactive monitoring, incident response, system administration, DICOM and network troubleshooting, patch coordination, migrations and vendor management — with engineers on shift nights, weekends and holidays across multi-vendor imaging estates.

96%

of healthcare institutions had at least one unplanned IT/EHR downtime in a recent three-year period

70%

of those institutions had at least one outage lasting 8+ hours

181

confirmed ransomware attacks against US healthcare organisations in 2024

$79k/hr

average cost of ransomware-driven downtime — roughly $1.9M per day

1. 96% — of health systems logged an unplanned IT outage in the past three years

2026 healthcare IT downtime research found that 96% of healthcare institutions experienced at least one unplanned IT or EHR downtime event within a recent three-year window. At that rate, downtime is not an exception to plan around; it is a normal operating condition to design for.

What it means for imaging directors: the useful question at renewal is not "will we have an outage" but "what does our agreement do when we do." Notably, most damaging imaging events are not total outages — a worklist that will not refresh, a viewer that loads studies without priors, a DICOM route silently failing to one destination. These halt clinical work while monitoring dashboards stay green.

What managed PACS support changes: monitoring scoped to imaging behaviour rather than to server heartbeat, so partial degradation registers as an incident. Ask your provider to show how many of last year's incidents were detected by monitoring versus reported by a radiologist. That ratio is the single most honest measure of a support arrangement.

2. 70% — of those institutions saw at least one outage stretch past 8 hours

Among affected institutions, 70% reported at least one event lasting eight hours or longer. Eight hours is the threshold where a department stops waiting and starts working around the failure: paper requisitions, hand-carried media, phoned results, and a reconciliation backlog that outlives the outage itself.

What it means: long outages are mostly a recovery-capability problem, not a failure-frequency problem. Two intervals decide the duration — time to detect and time to competent hands on the system.

What managed PACS support changes: continuous coverage compresses both. A degrading archive at 2 a.m. is caught as a warning rather than discovered at 8 a.m. as an outage, and an engineer already on shift starts diagnosis immediately rather than after someone is woken. A documented runbook and a distributed team also remove the single-expert dependency that stretches incidents when one person is unreachable. This is also the case for keeping interim PACS support available when in-house coverage lapses.

3. 181 — confirmed ransomware attacks against US healthcare organisations in 2024

181 confirmed ransomware attacks hit US healthcare organisations in 2024. Imaging is a high-value target within any health system: the archive holds large volumes of protected health information and the clinical dependency on it is immediate.

What it means: a support contract written purely around break-fix tickets is scoped for a different threat era. Security-driven outages follow a different path from technical failures — containment, forensics and staged restoration, measured in hours or days.

What managed PACS support changes: the agreement should name vulnerability and patch cadence for the imaging stack, tested archive backup and restore procedures, participation in the hospital's incident response plan, and a written imaging-specific recovery runbook. It should also name who coordinates the PACS vendor during a live incident, because that coordination role is where hours quietly disappear.

4. 33% — of breaches trace back to an exploited, unpatched vulnerability

Roughly a third of initial breach access industry-wide comes through an exploited, unpatched vulnerability. In imaging estates, deferred patching is rarely negligence — the PACS vendor has not certified the update, or the maintenance window collides with clinical volume, or the change owner is on leave.

What it means: the gap between exposure and impact is normally months, so the outage arrives long after the decision that caused it. Intentions to patch are not a control.

What managed PACS support changes: patching becomes a tracked programme rather than a backlog — relevant vulnerabilities prioritised, vendor certification status followed rather than waited on, windows agreed with the department in advance, and each cycle producing a record of what was applied and what remains outstanding with reasons. Ask to see that record before you renew. For estates running end-of-life components, this usually needs to run alongside a planned PACS migration rather than instead of one.

5. $79,000 per hour — the average cost of ransomware-driven downtime

Ransomware-driven downtime costs healthcare organisations approximately $79,000 per hour, or roughly $1.9 million per day. Set that against the 70% figure above and the arithmetic of a single eight-hour event becomes uncomfortable.

What it means: the renewal comparison is not this year's support price against last year's. It is the support price against the distribution of outcomes it changes. One avoided long incident can exceed an entire annual support line.

What managed PACS support changes: it moves spend from unpredictable incident cost to predictable recurring cost, and it shortens the incidents that do occur. Scope pricing against the actual estate — systems, sites, coverage hours, response commitments, breadth of administration — rather than against a published tier.

6. $208,600 — average direct revenue lost per downtime episode

The same 2026 research puts the average downtime episode at roughly $208,600 in direct lost revenue: missed appointments, diverted patients, cancelled and rescheduled studies. Imaging carries a large share of that exposure because imaging volume is schedule-dense and hard to recover once a day is lost.

What it means: the cost is concentrated in throughput, not in IT labour. A department that cannot scan or cannot read what it scanned loses the slot permanently.

What managed PACS support changes: proactive capacity and interface management prevents a meaningful share of the events that cost schedule time — storage exhaustion, interface backlogs, routing failures and certificate expiries are all predictable and all preventable with monitoring that watches trend rather than threshold. Where routing and connectivity between sites and destinations is the recurring weak point, dedicated DICOM gateway support addresses it directly.

7. $138,200 — average productivity cost per episode from manual workarounds

On top of lost revenue, the average episode costs about $138,200 in lost productivity as staff shift to manual workarounds. This is the number most often left out of a business case, because it does not appear on any invoice.

What it means: the cost continues after service is restored. Studies acquired during downtime have to be reconciled, failed routes re-sent, mismatched records corrected, and paper reconciled into the system — work that lands on the same people who absorbed the outage.

What managed PACS support changes: a defined post-incident process, executed by the partner rather than by department staff, covering reconciliation, route replay and record correction, with a written post-incident review that feeds the next prevention cycle. Judge a provider partly on what they do in the 48 hours after service is restored.

Three Support Models, Compared Against Those Numbers

DimensionIn-house onlyInterim / project-basedManaged PACS support
Coverage hoursBusiness hours plus on-call goodwillDefined engagement period24/7 including nights, weekends, holidays
Detection of degradationOften user-reportedVaries with scopeProactive monitoring with imaging-specific thresholds
Patch and vulnerability cadenceCompetes with daily ticketsPoint-in-time remediationTracked programme with documented cycles
Exposure to one departureHigh — single point of knowledgeTemporary cover onlyLow — team-based with documented runbooks
Multi-vendor estatesDepends on individual experienceUsually scoped to one systemVendor-agnostic across the estate
Cost behaviourFixed salary plus unbudgeted incident costProject fee per engagementPredictable recurring, scoped to the estate

Most organisations end up with a blend: hospital IT owns network, identity and security policy, and a managed PACS support partner owns the imaging-specific stack inside those controls. What matters is that the boundary is written down rather than assumed. The structure RAD365 uses for that division is set out in the PACS support framework.

What to Ask at Renewal

Six questions, all answerable from records if the service is real:

A provider who answers these from documentation is describing the service you actually received. One who answers from memory is describing the service they intended to deliver. Broader background on how these systems fit together sits in our overview of PACS in radiology, and day-to-day operational cover is covered under radiology IT support.

Frequently Asked Questions About Managed PACS Support and Renewals

Reading the Downtime Numbers

What actually counts as "downtime" when 96% of health systems report an outage in three years?

In the 2026 healthcare IT downtime research, downtime means an unplanned period in which a clinical system was unavailable or unusable for its intended purpose — not merely a server that stopped responding to a ping. For imaging that definition matters, because the most damaging PACS events are rarely total outages. A worklist that loads but does not refresh, a viewer that opens studies without priors, an archive that accepts images but stops sending them to the reading room, or a DICOM route that silently fails to one destination all halt clinical work while every dashboard stays green. When you benchmark your own environment against the 96% figure, count degraded-but-running events, because they dominate the real total and they are the ones in-house teams most often discover from a phone call rather than an alert.

Why did outages lasting more than 8 hours become so much more common industry-wide?

Three factors compound. First, the character of incidents changed: security events now account for a meaningful share of outages, and a suspected compromise triggers containment, forensics and staged restoration rather than a simple restart — that path is measured in hours or days, not minutes. Second, imaging estates got more interdependent, so a fault in storage, identity, virtualisation or the network surfaces as a PACS problem that takes longer to localise across teams and vendors. Third, staffing thinned: when one administrator covers an entire imaging estate, the clock starts running on availability, not just on repair. The 70% figure — the share of affected institutions reporting at least one outage past eight hours — is best read as a statement about recovery capability rather than about failure frequency.

Does the rise in ransomware attacks change what a PACS support contract should cover?

Substantially. With 181 confirmed ransomware attacks against US healthcare organisations in 2024, a support contract written purely around break-fix tickets is scoped for the wrong century. A current contract should specify vulnerability and patch management for the imaging stack with defined cadences, hardened and tested backup and restore procedures for the archive and its database, documented severity levels with response and escalation times that assume a security-driven event, participation in the hospital's incident response plan, and a written recovery runbook for the imaging estate specifically. It should also name who coordinates the PACS vendor during an incident, because during a live event that coordination role is where hours are usually lost.

How does an unpatched vulnerability turn into a PACS outage months later?

Roughly a third of initial breach access industry-wide traces to an exploited, unpatched vulnerability, and the delay between exposure and impact is normal rather than unusual. A patch is deferred because the PACS vendor has not yet certified it, or because the maintenance window collides with clinical volume, or because the one person who owns the change is on leave. The exposure persists quietly. Access is later obtained through that gap, often on an adjacent system, and the intruder moves laterally toward the file shares and databases the archive depends on. The visible failure — an archive that will not mount, a database that will not start — arrives long after the decision that caused it. This is why patch cadence, and evidence of it, belongs in the support contract rather than in someone's intentions.

What's the real cost difference between a short PACS blip and an 8-hour outage?

It is not linear. A brief interruption costs some rework and some frustration; clinical work usually absorbs it. An eight-hour outage crosses the threshold where the department switches to manual workarounds — paper requisitions, hand-carried media, phoned results — and that switch has its own cost independent of the technology. The 2026 healthcare IT downtime research puts the average downtime episode at roughly $208,600 in direct lost revenue from missed appointments and diverted patients, plus about $138,200 in lost productivity from staff working around the failure, with ransomware-driven downtime running near $79,000 per hour. Add the recovery tail — reconciling studies acquired during the outage, re-sending failed routes, correcting mismatched records — and the long incident is disproportionately more expensive than its duration suggests.

What Managed PACS Support Changes

How does 24/7 managed PACS support lower the odds of an 8-hour-plus outage?

By attacking the two intervals that make long outages long: time to detect and time to competent hands. Continuous monitoring of archive, database, storage, interface and routing health means a degrading condition is caught as a warning at 2 a.m. rather than as an outage at 8 a.m. — and most eight-hour events began several hours before anyone noticed. Then, because the covering team is on shift rather than on call, diagnosis starts immediately instead of after someone is woken and reaches a laptop. Documented runbooks and a distributed team also remove the single-expert dependency that stretches incidents when one person happens to be unreachable. None of this prevents every failure; it compresses the ones that occur into a much shorter window.

Does managed PACS support actually reduce ransomware exposure, or just clean up after an incident?

Both, and the preventive half is the more valuable one. On the preventive side, a managed model puts patch and vulnerability management for the imaging stack on a defined cadence with vendor certification tracked, keeps access reviews and service account hygiene current, monitors for the configuration drift that quietly reopens closed gaps, and verifies that archive backups actually restore rather than merely completing. Given that roughly a third of initial breach access comes through exploited unpatched vulnerabilities, that discipline addresses the most common route directly. On the response side, a managed partner brings a written imaging-specific recovery runbook and engineers who already know the estate, which is what shortens restoration when containment ends and rebuilding begins.

What's the difference between monitoring for uptime and monitoring for security?

Uptime monitoring asks whether the system is doing its job: is the archive accepting and serving studies, are interfaces passing messages, is storage within thresholds, is the worklist populating, are routes completing. Security monitoring asks whether something unauthorised is happening: unexpected authentication patterns, new outbound connections, configuration changes nobody requested, privilege escalation, unusual data movement. They surface different signals and require different tooling, and a PACS estate genuinely needs both. In most hospital arrangements the security operations centre owns the second discipline enterprise-wide while the managed PACS partner owns the first for imaging, feeds imaging-specific anomalies into the security team, and applies the remediation the imaging stack requires. What matters contractually is that neither party assumes the other is watching.

Can a managed PACS partner support more than one PACS vendor inside the same hospital network?

Yes, and for most networks it is the entire point. A typical estate already runs one PACS for radiology, another for cardiology, a separate VNA, modalities from a dozen manufacturers, and a mix of viewers accumulated through acquisitions. A vendor-agnostic managed model covers that estate from a single engagement, which gives the hospital one escalation path and one accountable team regardless of whose product is failing. It also removes the finger-pointing interval — the period in an incident where two vendors each conclude the fault lies with the other — because a single partner owns the diagnosis end to end and coordinates the vendors from the hospital's side of the table.

What happens to patch and vulnerability management under a managed model versus in-house?

In-house, patching is real work that competes with the day's tickets and usually loses, particularly when the PACS vendor has to certify each update and the maintenance window is difficult to schedule around clinical volume. Under a managed model it becomes a tracked, scheduled programme: vulnerabilities relevant to the imaging stack are identified and prioritised, vendor certification status is followed rather than waited on, changes are staged through a test environment where one exists, windows are agreed with the department in advance, and each cycle produces a record of what was applied and what remains outstanding with the reason. The substantive improvement is not speed — it is that deferred patches become a documented, reviewable list rather than an invisible accumulation.

Evaluating and Renewing a PACS Support Contract

What questions should be on the table at PACS support contract renewal, given rising outage numbers?

Ask for evidence rather than assurances. What was our actual measured uptime for each imaging component last year, and how was it measured? How many incidents did we log by severity, what was the mean and worst time to restore, and how many were detected by monitoring versus reported by a user? What is the patch and vulnerability posture for the imaging stack today, with a list of outstanding items and reasons? When was archive restoration last tested end to end, and what was the result? Who covers nights, weekends and holidays, by name or by rota, and what is the escalation path at 3 a.m.? Which components are explicitly excluded from the current agreement? A provider who cannot answer these from records is describing the service they intended to deliver rather than the one you received.

How is managed PACS support priced relative to the true cost of an outage?

Managed support is priced as a predictable recurring cost scoped to the estate — number and type of systems, sites, coverage hours, response commitments and scope of administration. The comparison that matters at renewal is not support cost versus the previous support cost; it is support cost versus the distribution of outcomes it changes. With ransomware-driven downtime running around $79,000 per hour, a typical episode costing roughly $208,600 in direct lost revenue plus about $138,200 in lost productivity, and 70% of affected institutions reporting at least one outage past eight hours, a single avoided long incident can dominate an annual support line. RAD365 scopes pricing against the specific estate rather than publishing rate figures, because a two-site imaging centre and a twelve-site network share almost nothing operationally.

What should a monthly PACS performance report actually show?

Enough for you to run the service rather than merely feel reassured about it. At minimum: availability by component with the measurement method stated; incidents by severity with detection source, time to acknowledge and time to restore; ticket volume by category with trend, so recurring root causes are visible; storage and capacity trajectory with a projected exhaustion date; interface and DICOM routing error rates by destination; patch and vulnerability status including what was applied and what remains outstanding with reasons; changes made to configuration; and backup and restore verification results. The most useful section is the one most reports omit — a short narrative of what changed this month and what the team is watching next month. A report that is only a green dashboard is a marketing artefact.

How long does it take to move from an in-house-only model to managed PACS support?

Typically a few weeks for a straightforward estate, longer where documentation is thin or the environment is highly customised. The work divides into discovery — inventorying systems, versions, interfaces, routing rules, storage, vendor contracts and support entitlements — followed by access provisioning under the hospital's own identity and security controls, monitoring deployment, runbook creation, and an agreed cutover of first-line responsibility with a defined support overlap. The pace-setting factor is almost always documentation quality. Estates where configuration lives only in one administrator's memory take longer, which is also precisely why they most need the transition. Interim support can stabilise operations in parallel where the current arrangement has already broken down.

Does a managed PACS support model replace a hospital's IT department?

No, and any proposal that implies otherwise should be treated cautiously. Managed PACS support is a specialised layer that operates alongside hospital IT, not in place of it. The hospital retains ownership of its network, identity, security policy, change control and clinical governance; the managed partner works inside those controls to keep the imaging-specific stack healthy — archive, viewers, DICOM routing, interfaces, modality connectivity and vendor coordination. Well-scoped engagements draw the boundary explicitly in the contract, name the escalation path in both directions, and hold a joint review often enough that the seam between the two teams stays visible rather than becoming the place incidents fall into.

Scope and Fit

Does managed PACS support include radiology reading or interpretation services?

No. Managed PACS support is systems, IT and infrastructure work only — monitoring, incident response, system administration, DICOM and network troubleshooting, patch and vulnerability management, capacity planning, migrations and vendor coordination. It does not include reading, interpreting or reporting on imaging studies in any form, and no part of a managed PACS engagement involves a clinical opinion about a study. RAD365 operates a separate Preliminary Reads service line for human patients in the USA, which is a distinct engagement with a distinct scope; it is not bundled into, implied by, or delivered under a managed PACS support contract. Keeping the two cleanly separated is deliberate, because they answer different problems and carry entirely different governance.

Is managed PACS support only practical for large hospital networks, or does it fit smaller imaging centres too?

It often fits smaller organisations better, because the economics are more favourable at the small end. A large network can usually justify several dedicated imaging informatics staff; a two- or three-site imaging centre generally cannot justify even one, yet it runs the same archive, the same interfaces, the same routing complexity and the same security exposure. Managed support gives that organisation continuous coverage and specialist depth at a fraction of a single salaried post, and removes the risk of having no coverage whatsoever when one person is unavailable. Scope and price should scale with the estate — number of systems, sites, modalities and coverage hours — rather than being sold as a single tier.

What's typically excluded from a managed PACS support contract?

Exclusions are where renewals go wrong, so read them before the price. Commonly outside scope: the PACS vendor's own software licences, maintenance fees and version upgrades, which the hospital continues to hold directly; hardware purchase and physical replacement, though coordination is usually included; enterprise network, identity and endpoint infrastructure owned by hospital IT; clinical workflow decisions and protocol design; and large discrete projects such as a full platform migration or data centre relocation, which are typically scoped and priced separately from ongoing support. Ambiguity most often clusters around after-hours response times, the number of named contacts, and whether project work draws down from the retainer. Pin those three down in writing, and most renewal disputes never arise.

Bring these seven numbers to your next renewal

A RAD365 PACS engineer will review your current coverage, monitoring, patch position, documentation and vendor mix, and show you where an eight-hour outage would start. Systems and infrastructure support only. No obligation.

Request a PACS support review →

Related Resources