Exposed DICOM Servers Increase Risk of PHI Theft and Ransomware Attacks

Healthcare organizations are exposing patient data through improperly secured DICOM servers that are accessible through the public internet, according to a Trend Micro TrendAI analysis that identified thousands of exposed servers across more than 100 countries.

The report stated the Shodan.io scanning data collected between November and December 2025 listed 3,627 internet-facing DICOM servers in over 100 countries. The United States accounted for 1,189 of the exposed systems, representing 33% of the total servers identified in the analysis.

DICOM, which stands for Digital Imaging and Communications in Medicine, is the standard used to capture, store, process, transmit, and display medical imaging data from systems such as X-rays, MRI scans, CT scans, and ultrasound devices. DICOM files contain imaging data and metadata that may include protected health information (PHI). DICOM files may contain patient full names, dates of birth, medical record numbers, Social Security numbers, diagnosis codes, procedure details, and physician information. The medical images themselves may also reveal sensitive health conditions.

TrendAI reported that many exposed servers lacked basic security controls, such as TLS encryption and AE Title Validation. Only 0.14% of the internet-facing DICOM servers identified in the analysis used TLS encryption, while 99.56% of exposed DICOM servers do not implement AE Title validation.

TrendAI identified exposed servers in 334 organizations, which included 231 healthcare entities such as hospitals, clinics, laboratories, imaging centers, and radiology centers.

Many of the exposed servers were Picture Archiving and Communication Systems or workstations that serve as gateways to imaging equipment. HIPAA-covered entities use the systems to communicate with MRI systems, X-ray equipment, CT scanners, PET-CT scanners, and mammography units. The analysis did not identify medical imaging devices that were directly exposed to the internet, although the report stated that the exposed servers likely communicate with those systems internally.

The analysis also identified patch management deficiencies on exposed systems. Multiple servers contained unpatched vulnerabilities, including CVE-2019-1010228, CVE-2022-2119, CVE-2022-2120, and CVE-2025-0896.

TrendAI found that 44% of the exposed servers clustered into groups using identical software. The report stated that a single exploitable vulnerability could affect hundreds of systems operating the same software configuration.

The analysis stated that exposed DICOM servers increase the risk of patient data theft, image manipulation, lateral movement inside healthcare networks, and ransomware attacks. TrendAI stated that DICOM servers should be isolated and protected by firewalls to avoid unauthorized access.

The report stated that healthcare organizations, cloud providers, and DICOM software vendors share responsibility for addressing the security weaknesses identified in the analysis. TrendAI stated that security controls for DICOM environments, such as TLS encryption or HIPAA encryption (in the case of healthcare entities), should be treated as required protections rather than optional features.

Image credit: metamorworks, AdobeStock

Twitter Facebook LinkedIn Reddit Copy link Link copied to clipboard
Photo of author

Posted by

John Blacksmith

John Blacksmith is a journalist with several years experience in both print and online publications. John has specialised in Information technology in the healthcare sector and in particular in healthcare data security and privacy. His focus on healthcare data means he has specialist knowledge of the HIPAA regulations. John has a degree in journalism and many years experience.
Twitter
LinkedIn