Legacy PACS Support Security and Access Checklist

Use this concise legacy PACS checklist to review segmentation, credentials, logging, backups, patch constraints, and compensating controls.

Legacy PACS Support Security and Access Checklist

By Trisha Seal — October 1, 2026. Practical guidance for hospital imaging operations.

Legacy PACS security starts with knowing what the hospital cannot safely change and strengthening the controls around it. HHS advises organizations to identify legacy systems and account for their risks in security management.

Network and Exposure

Identity and Privileged Access

Logging and Monitoring

Backups and Recovery

Patch Constraints and Compensating Controls

Record unsupported components, the reason a patch cannot be applied, the risk owner, and controls such as segmentation, application allowlisting, restricted access, or enhanced monitoring. Set a review date and connect unresolved risk to a replacement plan.

RAD365 can help operate and document PACS controls; it does not perform clinical reading or interpretation.

Sources

HHS OCR, Securing Your Legacy · NIST SP 1800-24

Related Reading

Frequently Asked Questions

Common Questions

What is a compensating control?

It is an alternative safeguard used when the preferred control, such as a vendor patch, is not feasible.

Should a legacy PACS have internet access?

Direct exposure should be avoided; communication should be restricted to documented operational needs and approved remote-access paths.

Are shared administrator accounts acceptable?

Named accounts are preferable. Where a shared account cannot be removed, tightly control, rotate, monitor, and document its use.

What should backup testing prove?

It should prove that required images and data can be restored within the hospital’s recovery expectations.

How often should legacy risk be reviewed?

Set a recurring review based on organizational policy and reassess after incidents, material changes, or new threat information.