Legacy PACS Support Security and Access Checklist
Use this concise legacy PACS checklist to review segmentation, credentials, logging, backups, patch constraints, and compensating controls.
By Trisha Seal — October 1, 2026. Practical guidance for hospital imaging operations.
Legacy PACS security starts with knowing what the hospital cannot safely change and strengthening the controls around it. HHS advises organizations to identify legacy systems and account for their risks in security management.
Network and Exposure
- Place the PACS in an appropriately segmented zone.
- Restrict inbound and outbound communication to documented needs.
- Remove direct internet exposure and review remote-access paths.
- Maintain an accurate asset and dependency inventory.
Identity and Privileged Access
- Assign administrative accounts to named owners.
- Disable unused accounts and rotate shared credentials where feasible.
- Protect remote access with strong authentication.
- Document emergency access and review its use.
Logging and Monitoring
- Collect available system, access, interface, and security logs.
- Monitor failed transfers, unusual access, capacity, and service health.
- Define who reviews alerts and how incidents escalate through the PACS Support Framework.
Backups and Recovery
- Verify backup completion and separation from the production environment.
- Test restore procedures and record results.
- Maintain a PACS outage runbook that works without the primary system.
Patch Constraints and Compensating Controls
Record unsupported components, the reason a patch cannot be applied, the risk owner, and controls such as segmentation, application allowlisting, restricted access, or enhanced monitoring. Set a review date and connect unresolved risk to a replacement plan.
RAD365 can help operate and document PACS controls; it does not perform clinical reading or interpretation.
Sources
HHS OCR, Securing Your Legacy · NIST SP 1800-24
Related Reading
Frequently Asked Questions
Common Questions
What is a compensating control?
It is an alternative safeguard used when the preferred control, such as a vendor patch, is not feasible.
Should a legacy PACS have internet access?
Direct exposure should be avoided; communication should be restricted to documented operational needs and approved remote-access paths.
Are shared administrator accounts acceptable?
Named accounts are preferable. Where a shared account cannot be removed, tightly control, rotate, monitor, and document its use.
What should backup testing prove?
It should prove that required images and data can be restored within the hospital’s recovery expectations.
How often should legacy risk be reviewed?
Set a recurring review based on organizational policy and reassess after incidents, material changes, or new threat information.