The Line Item Most PACS Contracts Leave Out — And What It Costs When It Surfaces

Imaging devices are the highest-risk connected systems in a hospital. What managed PACS support covers, what downtime really costs, and the clause most contracts miss.

The Line Item Most PACS Contracts Leave Out — And What It Costs When It Surfaces

Every managed PACS evaluation covers the same ground: uptime percentages, response targets, escalation paths, cost per site. There is one category that almost never appears as a line item in the contract or in the budget conversation, and it is the one with the widest gap between what hospitals assume is covered and what actually is — imaging systems as a cybersecurity attack surface. CT, MRI and X-ray devices are named by healthcare security researchers as the highest-risk connected device category on a hospital network, and managed PACS services either address that or quietly leave it to nobody.

$5,300–$9,000/min

healthcare IT downtime cost industry-wide, per NETSCOUT healthcare downtime research; up to $17,244/min for unplanned outages involving patient data

~$300,000/yr

revenue a medium-sized (~200-bed) hospital can lose to imaging system outages alone (AuntMinnie imaging-industry analysis)

14%

of healthcare IT security teams describe themselves as fully staffed; 77% of organisations report IT staffing shortages (2026 healthcare IT security workforce survey)

136 hospitals

affected across 19 states in the 2026 Ascension Health ransomware incident, which took diagnostic imaging access down alongside EHR and pharmacy

The category nobody puts in the contract

Healthcare cybersecurity researchers rank imaging devices — CT, MRI, X-ray — as the highest-risk connected device category in a hospital, and ransomware operators target them accordingly. The reason is structural rather than incidental. Modalities run long-lived embedded operating systems that cannot be patched on a normal IT cadence. They are clinically critical, so they are almost never taken offline for maintenance. They handle patient data. They are networked to the archive, frequently to the RIS or EHR, and often to the manufacturer for remote service. High value, high availability requirement, low patch tolerance — that is the profile.

Now compare that to a typical support contract, which is written around availability of the archive and the viewer. It commits to noticing when something stops responding. It says nothing about who was authenticated to the modality overnight, whether a version with published vulnerabilities is still running, or who picks up the phone if the imaging estate has to be isolated during a hospital-wide event.

Ascension: what a real event does to imaging

The 2026 Ascension Health ransomware incident is the clearest available illustration, and the useful detail is not the headline scale but the mechanism. The incident affected 136 hospitals across 19 states and contributed to a reported $1.8 billion operating loss for the fiscal year. Diagnostic imaging access went down alongside the EHR and pharmacy systems — not because imaging was the entry point, but because it shared authentication, network paths and dependencies with the systems that were compromised.

That is the part worth carrying into your own planning. PACS availability is a function of the whole network's security posture. Directory services, the order feed, patient identity, shared storage, the network fabric — compromise any of them and imaging stops working with the archive perfectly intact. Recovery planning that assumes imaging survives because imaging was not targeted is planning for the wrong event. The dependency map matters, which is why the connectivity layer described on the DICOM gateway page is a security question as much as an integration one.

Stat callout

At NETSCOUT's conservative figure of $5,300 per minute, a single eight-hour unplanned outage costs roughly $2.5 million industry-wide-average. At the imaging-specific end, AuntMinnie's analysis finds a small site running ~40 studies/day loses around $1,200 in one 8-hour outage — and a 200-bed hospital close to $300,000 a year to imaging outages alone.

Two numbers that are not comparable

Support budgets frequently get set by comparing planned maintenance downtime against a security incident as if they were the same unit. They are not:

Dimension Planned maintenance window Unplanned security incident
TimingChosen low-volume windowWhenever the attacker chooses
Revenue effectDeferred — patients rebookedDestroyed — slots lost, patients diverted
DurationKnown in advanceDays to weeks, depending on preparation
Additional costsStaff overtimeForensics, notification, legal, regulatory
Data integrity riskNone if procedure followedIdentity, priors and study linkage all at risk

Where PACS support meets security in practice

This is the point where the Tier B question — what basic PACS support should already include — stops being a separate conversation. The controls that reduce security exposure are largely the same operational disciplines that reduce downtime:

The coverage tiers and escalation structure that make those disciplines contractual rather than aspirational are set out on the PACS support framework page, and the broader estate context — modality connectivity, routing and image exchange — on the radiology IT support page.

A note on scope, since it is frequently blurred in this market: RAD365 does not read or interpret images. Our work is keeping the systems that deliver images to readers running, integrated and secure. That distinction matters when you are assessing who is accountable for what during an incident.

The staffing reality behind all of it

The 2026 healthcare IT security workforce survey found 77% of healthcare organisations reporting IT staffing shortages, and only 14% of healthcare IT security teams describing themselves as fully staffed. Imaging-specific security expertise is worse served than that headline suggests, because it falls in the gap between clinical engineering, who own the devices, and IT security, who own the network. In most hospitals it is nobody's named responsibility. That is the actual reason the line item is missing from the contract: not that anyone decided against it, but that no single team was ever asked to price it. The same gap shows up on the general PACS in radiology operations side, where ownership evaporates precisely at the boundaries between systems.

Five questions to ask before your next renewal

  1. Which alerts reach a human at 3am, and are any of them security events rather than availability events?
  2. Is patch and version status reported monthly without being asked for, including for end-of-life components?
  3. Is incident-response coordination in scope during a hospital-wide cyber event, or only day-to-day operations?
  4. How do the provider's own engineers connect — multi-factor, individually attributed, session-logged and available to you for audit?
  5. When was restoration last rehearsed, and what was the measured time to core imaging function?

No Tier C long-tail subsection is included in this piece: the adjacent terms tested for this run — "managed pacs services", "pacs support cost" and "24/7 pacs support" — all returned no tracked search volume, and inventing a subsection around a keyword nobody searches would not serve the reader.

About the author

Trisha Seal writes on radiology operations and imaging IT for RAD365. RAD365 is a physician-owned operations partner providing managed and outsourced PACS support — 24/7 imaging engineers, vendor-agnostic coverage across mixed and hybrid estates, interface-level ownership, patch and access governance, and written SLAs. RAD365's scope is systems, infrastructure and PACS operations support.

Review your imaging estate's exposure

Talk to a RAD365 PACS engineer about patch status, access governance, segmentation and monitoring coverage across your imaging systems.

Talk to a PACS engineer →

Managed PACS, downtime cost and imaging security: frequently asked questions

Why Imaging Systems Are a Target

Why are imaging devices like CT and MRI scanners considered high-risk targets in hospital cybersecurity?

Healthcare cybersecurity researchers consistently name imaging devices — CT, MRI and X-ray — as the highest-risk connected device category on a hospital network. The reasons are structural: they run long-lived embedded operating systems that cannot be patched on a normal IT cadence, they are clinically critical so they are rarely taken offline, they hold and transmit patient data, and they are networked to the archive and often to the manufacturer for remote service. That combination — high value, high availability requirement, low patch tolerance — is precisely the profile attackers look for.

What did the Ascension Health ransomware incident show about imaging-system exposure during a hospital-wide attack?

The 2026 Ascension ransomware incident affected 136 hospitals across 19 states and knocked out access to diagnostic imaging alongside the EHR and pharmacy systems, with the organisation reporting a $1.8 billion operating loss for that fiscal year. The operational lesson is scope: imaging was not the entry point, but it went down with everything else because it shared network paths, authentication and dependencies with the systems that were compromised. Imaging availability is a function of the whole network's security posture, not just the PACS server's.

Can a ransomware attack elsewhere on the hospital network take down PACS even if PACS wasn't the entry point?

Routinely, and this is the single most under-appreciated point in imaging IT risk. PACS depends on directory services for authentication, on the RIS or EHR for orders and patient identity, on shared storage and on the network fabric itself. Compromise any of those and imaging stops functioning even if the archive is untouched, and it may be deliberately taken offline as a containment measure. Recovery planning has to assume PACS is affected whether or not it was targeted.

Is a legacy or end-of-life PACS more vulnerable, and can it still be protected without an immediate replacement?

Yes to both. A version the manufacturer no longer patches accumulates known, published vulnerabilities that never get closed, which is an escalating risk rather than a static one. It can still be operated safely for a defined period using compensating controls — strict network segmentation, tightly restricted access, hardened jump-host administration, enhanced monitoring on that segment and a tested recovery path — but those controls need to be someone's explicit job, and the replacement path should be planned rather than indefinitely deferred.

How does network segmentation between imaging devices and the rest of the hospital network reduce risk?

Segmentation limits blast radius. If modalities sit on a restricted segment that only permits the specific DICOM and service traffic they legitimately need, a compromise elsewhere on the hospital network cannot move laterally into the imaging estate, and a compromised modality cannot reach the wider network. It does not prevent an incident; it converts a hospital-wide event into a contained one, and it is one of the highest-value controls relative to cost in imaging environments.

What Managed PACS Support Actually Prevents

Does managed PACS support include cybersecurity monitoring, or is that always a separate service?

It varies by provider and it is worth pinning down in the coverage schedule rather than assuming. Some managed PACS contracts cover only availability monitoring — is the service responding — while others include security-relevant monitoring of the imaging estate: authentication anomalies, unexpected outbound connections from modalities, configuration drift, patch status and integrity of the archive. The two are sold under similar language and are not the same service. Ask which alerts the provider actually receives and acts on.

How does patching and version management affect whether a PACS environment is exposed?

Most successful intrusions exploit known vulnerabilities for which patches already exist. Imaging estates are especially exposed because patching a modality or an archive requires clinical scheduling, vendor validation and downtime windows, so it slips. Managed support changes this from an ad hoc activity into a tracked programme: a maintained inventory of versions, a documented patch cadence with vendor-validated releases, and a record of what is deliberately unpatched and what compensating control covers it.

What access controls should a managed PACS provider enforce to limit breach exposure?

Named individual accounts with no shared administrative credentials, multi-factor authentication on all remote administrative access, role-based permissions scoped to actual duties, prompt deprovisioning tied to your HR leaver process, session logging for every administrative action, and time-limited elevation rather than standing privilege. Vendor and manufacturer remote-service access needs the same treatment — it is a frequent gap, because it is often configured once at installation and never reviewed.

How does 24/7 monitoring shorten the window between compromise and detection?

Detection time is the variable that most determines total cost. An anomaly that surfaces at 2am and is investigated at 2:05am is a contained incident; the same anomaly first noticed when staff arrive is seven hours of unimpeded activity. Continuous monitoring with a human on the other end of the alert compresses that interval, which matters more in imaging than most application estates because modalities operate unattended overnight and nobody is watching them.

Does managed PACS support include incident-response coordination during a cyber event, or only day-to-day operations?

Check the contract, because this is commonly excluded and rarely highlighted. During an event you need someone who knows the imaging estate participating in the response — advising on safe isolation of modalities, preserving archive integrity, sequencing restoration so identity and prior-study linkage survive, and coordinating with manufacturers. If that is not in scope, your incident response team will be making imaging decisions without imaging expertise at the worst possible moment.

The Real Dollar Numbers

How much does a single hour of unplanned PACS downtime actually cost a mid-sized hospital?

NETSCOUT's healthcare downtime research puts healthcare IT downtime at roughly $5,300 to $9,000 per minute industry-wide, with some analyses of unplanned outages involving patient data running as high as $17,244 per minute. Even at the conservative end of that range an hour is a six-figure number. Imaging-specific analysis published by AuntMinnie is more modest and more concrete: a medium-sized 200-bed hospital can lose close to $300,000 annually to imaging system outages alone.

What's the financial difference between planned maintenance downtime and an unplanned security incident?

Planned downtime is scheduled into low-volume windows, patients are rebooked rather than lost, staff are rostered accordingly and the revenue is deferred rather than destroyed. An unplanned incident destroys the slot, diverts the patient, idles paid staff, delays claims, consumes leadership time and — in a security event — adds forensics, notification, legal and regulatory costs that have nothing to do with imaging throughput. The per-hour figures are not comparable, and quoting one against the other is how support budgets get set wrong.

Why do healthcare IT teams report being understaffed specifically for security work?

A 2026 healthcare IT security workforce survey found 77% of healthcare organisations reporting IT staffing shortages, with only 14% of healthcare IT security teams describing themselves as fully staffed. Security specialists command salaries that compete with sectors outside healthcare, the work is 24/7 by nature, and in most hospitals imaging-specific security expertise sits in nobody's job description — it falls between the clinical engineering team who own the devices and the IT security team who own the network.

How does the cost of investing in monitored, secure managed PACS support compare to the cost of a single incident?

Take the conservative end of NETSCOUT's range, apply it to a single unplanned day, and the number typically exceeds an annual managed support contract for a mid-sized estate. Add the AuntMinnie finding that a 200-bed hospital can lose close to $300,000 a year to imaging outages alone and the arithmetic stops being a judgement call. The honest framing is not support-versus-no-support; it is a predictable annual line item against an unpredictable one that arrives without warning.

Getting Ahead Of It

What's a realistic recovery timeline after a PACS-affecting security incident?

It depends almost entirely on preparation rather than on the attack. With tested, isolated backups, documented restoration sequencing and a rehearsed downtime procedure, core imaging can often be back in a matter of days with a staged return of full function. Without those, recovery runs into weeks, because the sequence has to be worked out live: restore identity and orders before images, validate prior-study linkage, reconcile studies acquired during the outage, and re-establish routing. Ask any prospective partner when they last rehearsed it, not whether they have a plan.

What should a hospital ask a PACS support vendor about the vendor's own security posture?

How its engineers connect to your environment and whether that access is multi-factor and individually attributed; whether administrative sessions are logged and available to you; how it vets and offboards staff; how it segregates one client environment from another; its own incident notification commitment and timeframe; and whether it has been subject to an incident and what changed afterwards. A remote support provider is a privileged path into your estate — it should be assessed like one.

What certifications or attestations indicate a PACS support provider takes security seriously?

SOC 2 Type II is the most informative for an ongoing service because it tests operating effectiveness over a period rather than design at a point in time. HITRUST and ISO 27001 are meaningful signals. For US healthcare, a signed business associate agreement with documented HIPAA safeguards is table stakes, not a differentiator. Always ask for the scope statement — certifications frequently cover a subset of the organisation, and the subset may not be the team touching your imaging estate.

What questions reveal whether a '24/7 PACS support' claim actually includes security monitoring, versus just uptime monitoring?

Ask what specific alerts reach a human at 3am, and whether any of them are security events rather than availability events. Ask for an example of a security-relevant alert actioned in the last quarter. Ask whether patch status and configuration drift are reported monthly without being requested. Ask who is contractually accountable if a known vulnerability goes unpatched for six months. Uptime monitoring answers whether the service responded; it says nothing about who was logged into it.

Related reading