The Wayback Machine - https://web.archive.org/web/20220905193804/https://www.ajronline.org/doi/10.2214/AJR.19.21958

April 2020, VOLUME 214
NUMBER 4

Recommend & Share

April 2020, Volume 214, Number 4

FOCUS ON: Medical Physics and Informatics

Review

DICOM Images Have Been Hacked! Now What?

+ Affiliations:
1Department of Radiology, University of Pennsylvania, 3400 Spruce St, Philadelphia, PA 19104.

2Department of Software and Information Systems Engineering, Ben-Gurion University of the Negev, Beersheba, Israel.

3Institute for Information Security & Privacy, Georgia Institute of Technology, Atlanta, GA.

4Cybersecurity Laboratories, Cylera, New York, NY.

5Brainlab AG, Munich, Germany.

6Department of Biomedical Informatics. University of Arkansas for Medical Sciences, Little Rock, AR.

7Fairhaven Technologies, Maynard, MA.

Citation: American Journal of Roentgenology. 2020;214: 727-735. 10.2214/AJR.19.21958

ABSTRACT
Next section

Image

To listen to the podcast associated with this article, please select one of the following: iTunes, Google Play, or direct download.

OBJECTIVE. As health care moves into a new era of increasing information vulnerability, radiologists should understand that they may be using systems that are exposed to altered data or data that contain malicious elements. This article explains the vulnerabilities of DICOM images and discusses requirements to properly secure these images from cyberattacks.

CONCLUSION. There is an important need to properly secure DICOM images from attacks and tampering. The solutions described in this article will go a long way to achieving this goal.

Keywords: confidentiality, DICOM, encryption, integrity, mitigation, security, vulnerabilities

Nearly every day in the news, radiologists hear about the latest companies that have had their private data breached by hackers [1–3]. Exposure of such data to the world can lead to possible identity theft, fraud, and millions of dollars in litigation costs resulting from class action lawsuits by aggressive law firms and disgruntled victims of the breach. Many of these breaches involve medical records. In the past 10 years, almost 3000 breaches, each involving more than 500 medical records, have occurred in the United States, with these breaches mostly caused by hacking [4–7]. For example, the 2015 breach of Anthem, a U.S. medical insurance company, potentially exposed the medical records of 78 million Americans and led to a $115 million settlement [8].

Radiologists also hear about ransomware, which is software that hackers use to hold hostage the data of hospitals, companies, and local government until money is paid to recover access to the data. The city of Baltimore was recently victim of a ransomware attack, leading to massive disruption in daily municipal business [9]. In May and June of 2017, the ransomware Wannacry [10] and NotPetya [11] spread through thousands of institutions worldwide, including many hospitals, causing a total of $18 billion dollars in damages.

In June 2017, a U.S. government task force issued its report on the status of cybersecurity in health care in the United States [12]. The report revealed a critical situation, which showed a lack of security talent, legacy equipment, hasty connectivity resulting from meaningful use requirements [13], and an epidemic of vulnerabilities. Vulnerabilities were found in computers, networks, medical devices, and humans. Until recently, radiologic images had not yet been the target of any major attack, despite their known vulnerabilities [14]. Then, in March and April of 2019, two major exploits of the DICOM radiologic imaging standard were reported [15, 16]. These exploits serve to emphasize the importance of addressing security concerns with DICOM images.

In this article, we introduce radiologists to the basic elements of DICOM images and DICOM servers (e.g., PACS) used in radiology, discuss the basic elements of security, vulnerabilities, and attacks, and suggest solutions. This article was written by radiologists, top cybersecurity experts, and DICOM security leaders. The information technology (IT) issues are addressed at a technical level appropriate for the radiology community at large, so that this community is made aware of this new and growing era of digital warfare and its implications for their daily practice. Appendix 1 includes definitions of the technical terms used in the article. Although DICOM data are subject to the same general vulnerabilities as other types of data, this article strictly focuses on vulnerabilities limited to the nature of DICOM data and their transmission on networks. We will answer the following questions: What are the vulnerabilities of DICOM images? What is required for security? How much security is currently built into the DICOM standard? What security features are missing? What are the risks and potential attacks? How can we make DICOM more secure?

DICOM Standard
Previous sectionNext section

In the 1980s, the American College of Radiology and the National Electrical Manufacturers Association joined forces to develop a standard for radiologic image storage and transmission that enabled integration among imaging devices, data archives, PACS, workstations, printers, and other systems produced by multiple manufacturers. Early versions of the standard were released in 1983 and 1985 and have been continuously refined since then. This standard is called DICOM (Digital Imaging and Communications in Medicine) [17, 18]. DICOM specifies how images are transmitted on networks between devices and how images are stored on portable media such as CDs [17]. DICOM does not specify how images are stored internally within archives or devices. Some basic security features have been added to the standard, starting in 1999 [19].

The basic element of the DICOM standard is the DICOM object (Fig. 1), which typically represents an image. A DICOM object includes public and private imaging attributes, followed by pixel data [17]. The public attributes contain imaging device parameters (e.g., name of device, radiation dose, and tube voltage), imaging parameters (e.g., slice thickness and numbers of rows and columns), and patient parameters (e.g., name, age, sex, and identifiers). The public attributes can be understood by most devices. A DICOM object typically also includes manufacturer-specific private attributes.

figure
View larger version (196K)

Fig. 1 —DICOM standard. Schematic shows that DICOM object includes public and private attributes, followed by pixel imaging data. Stored format of attribute includes tag (n, m), data type, data length, and value. There are typically approximately 100–200 such DICOM attributes per image. DICOM message is how DICOM object is transmitted over network (data in motion). It includes commands (e.g., C-STORE, which translates to “store this object”) and DICOM object. DICOM file is how DICOM object is stored on media (data at rest). It includes 128-byte preamble, indicator DICM, and DICOM object. Preamble is usually empty but can be used by non-DICOM software to point to alternate non-DICOM versions of image.

DICOM objects are transmitted on networks (data in motion) as DICOM messages (Fig. 1), which comprise a DICOM command set and a DICOM object. The command set includes basic operations such as “store an image,” so devices can be instructed what to do with the DICOM object that they receive.

DICOM objects are stored on media (data at rest) as DICOM files (Fig. 1), which include a header and a DICOM object. The header includes a 128-byte preamble, the label DICM, and a few extra DICOM attributes. The preamble is usually empty and is used by non-DICOM software to help it read a DICOM image or provide a pointer to an alternative image. DICOM objects stored on PACS and archives may use the DICOM file standard or other storage standards.

DICOM servers (Fig. 2) are computers that run a DICOM service, which is software that enables the computer to send and receive DICOM images using a specific communication protocol defined in the DICOM standard. A server that does not run a DICOM service simply cannot receive DICOM images via the DICOM communication protocol. All imaging devices also have computers with DICOM client software that can send images to a DICOM server.

figure
View larger version (64K)

Fig. 2 —DICOM server. Schematic shows DICOM server, computers that can exchange and store DICOM objects. Server offers DICOM service, which is software that can send and receive DICOM messages. Such service runs via specific computer ports (i.e., communications channels). Two main unsecured DICOM services are known as acr-nema (port 104) and dicom (port 11112). These services can be queried by hackers. These services send and receive unencrypted DICOM messages that can be intercepted and read by hackers. Secured DICOM service is known as dicom-tls (port 2762), which uses Transport Layer Security (TLS) for negotiations, authentication, and encryption. This service cannot be queried by hackers because it uses strong authentication mechanisms. This service sends and receives encrypted DICOM messages that cannot be read by hackers. However, this is only true for manufacturers that have chosen to implement its strong authentication and encryption features. Arrows show direction of data transmission.

Basic Security Concepts
Previous sectionNext section

The main objectives of information security are known as the CIA triad. CIA is an acronym for confidentiality, integrity, and availability [20]. The main concepts discussed in the following sections are illustrated in Figure 3.

figure
View larger version (207K)

Fig. 3A —Illustration of main terms involved in confidentiality and integrity. Arrows show direction of data transmission.

A, Key is long number, generalization of password. Schematic shows examples of 1024-bit RSA (Rivest-Shamir-Adleman) private and public keys, as stored on computer. RSA is popular encryption algorithm used to protect web [35]. Certificate is endorsed copy of public key or electronic document containing public key and officially proving its ownership. It includes serial number, period of validity, user identification, public key, and identification and signature of certification authority. RSA public key inside this certificate is represented by modulo and exponent, which are alternate way to represent public key.

figure
View larger version (78K)

Fig. 3B —Illustration of main terms involved in confidentiality and integrity. Arrows show direction of data transmission.

B, Hash is fixed-size number generated by mathematic function. Hash is used to assess integrity. Schematic shows 160-bit hash produced by SHA-1 (Secure Hash Algorithm 1) hash function on random DICOM file. SHA-1 is popular hash function used by DICOM and most of web [36]. Digital signature is simply encrypted hash. It is used to assess integrity and for authentication. It indicates that owner of that public key encrypted that hash with his or her private key. Hash shown was encrypted by RSA algorithm to generate digital signature.

Confidentiality

Confidentiality is the assurance that information has not been disclosed to unauthorized entities. This is important given that radiologic images contain protected health information. Confidentiality is protected by encryption (Fig. 4), a mathematic transformation of data to make it unreadable to everyone except its intended recipient. Encryption involves an algorithm and one or more keys. A key is simply a long number, a generalization of the concept of a password. There are two types of encryption: symmetric and asymmetric. Symmetric encryption involves very fast algorithms and a single key shared between the source and recipient of the data. The same key is used for encryption and decryption. Involved parties must find a way to privately share that key before exchanging any encrypted data. Asymmetric encryption involves slower algorithms with two mathematically related keys: a private key kept by a user and a public key shared with the world. Either of the two keys is used for encryption, and the other key is used for decryption. To send confidential data securely to a recipient, the sender encrypts it with the public key of the recipient, and the recipient decrypts it with his or her private key. Symmetric encryption is thousands of times faster than asymmetric encryption.

figure
View larger version (39K)

Fig. 4A —Schematic of implementation of confidentiality by encryption, which involves use of keys for encrypting and decrypting data. Arrows show direction of data transmission.

A, Symmetric encryption involves single key used for both encryption and decryption. Sender has copy of key for encryption, and recipient has copy of same key for decryption. They must find way to privately share that key before exchanging any encrypted data.

figure
View larger version (41K)

Fig. 4B —Schematic of implementation of confidentiality by encryption, which involves use of keys for encrypting and decrypting data. Arrows show direction of data transmission.

B, Asymmetric encryption involves two mathematically related keys: private key that is not shared and public key that is easily shared with world. To securely send data to recipient, sender encrypts it with widely available recipient's public key and recipient decrypts it with his or her private key. Parties do not need to privately share key before exchanging any encrypted data as recipient's public key is widely available.

Integrity

Integrity is verification that data have not been altered and that no tampering of an image has occurred. Integrity is confirmed using digital signatures (Fig. 5), which are a combination of a mathematic transformation of data generating a fixed-size long number (i.e., a hash), followed by asymmetric encryption of that hash, which generates a digital signature. Any variations in the data result in a different hash, and any variation in the key used to encrypt it results in a different digital signature. When a sender transmits data to a recipient and the recipient wants to confirm the integrity of the data received, the sender applies the hash function to the data, and the resulting hash is encrypted with the sender's private key to produce a digital signature. This digital signature is transmitted to the recipient, who decrypts it using the sender's public key. The recipient also applies the same hash function to the data received. If the result is identical to the sender's decrypted digital signature, this confirms the integrity of the data.

figure
View larger version (81K)

Fig. 5 —Schematic of implementation of concepts of integrity and authenticity using digital signatures. Sender transmits DICOM object to recipient. Recipient would like to confirm integrity of received object. Sender applies hash function to object, and resulting hash (Hash1) is encrypted with sender's private key to generate digital signature. This digital signature is securely transmitted to recipient, who decrypts it using sender's public key. Recipient also applies same hash function to received DICOM object, producing hash (Hash2). If this hash is same as decrypted digital signature, this confirms integrity of DICOM object. Two different objects have only one chance in 2160 of producing same 160-bit hash illustrated in Figure 3. If hashes are same, digital signature also authenticates sender because sender's public key was correct key capable of decrypting digital signature. Certificates can also be used in tandem with digital signatures for authentication because they confirm whether sender really owns that specific public key. Arrows show directions of data transmission.

The concept of integrity also includes authentication, which is the assurance that information is from the source from which it claims to originate. Authentication uses a digital signature, often in tandem with a digital certificate, which is an endorsed version of the sender's public key from a central certifying authority. The digital signature proves that the owner of the public key is the true source of the data, and the certificate officially confirms who that owner is.

Availability

Availability is a guarantee of reliable access to the information by authorized people. For example, access to radiologic images can be blocked by ransomware. Availability is assured by multiple layers of system defenses established to prevent ransomware from taking over these systems and holding the data hostage and by redundancy (e.g., backups).

Security Features in the DICOM Standard
Previous sectionNext section

At present, DICOM has 32 working groups focusing of improving different aspects of the standard (e.g., Computed Tomography, Magnetic Resonance, 3D, Physics, Security, and others). DICOM working group 14 (WG-14) handles all aspects related to DICOM security, which are found in part 15 of the DICOM standard [17, 19]. Three main security features are currently included in the DICOM standard by WG-14: secure transmission, digital signatures, and security of DICOM files on media and in E-mails.

Secure Transmission

Protocols for secure transmission have been introduced in the DICOM standard. With time, nearly all have been retired, but one strong protocol remains: transport layer security (TLS) (Fig. 2). TLS involves a combination of slow, asymmetric encryption for negotiating the connection, authenticating the parties, and exchanging a shared key and fast symmetric encryption using the shared key for exchanging the DICOM messages [21]. Certificates for connection guarantee authentication of the involved parties. Encryption is used to maintain confidentiality, and encrypted hashes are used to maintain integrity. TLS was not developed by DICOM WG-14, but it is a standard that is widely used in Internet communications (often when “https://” is used).

Digital Signatures

Digital signatures described in the previous section have been introduced in the DICOM standard. They are computed for entire or partial DICOM objects to confirm their integrity and identify who created them. This has largely been ignored by manufacturers and has not been implemented.

Security of DICOM Files on Media and in E-Mails

Basic security for DICOM files on media and in e-mails has been introduced in the DICOM standard. This uses encryption of DICOM files and specifies the proper handling of keys. It has largely been ignored by manufacturers and not implemented.

Security features such as encryption and digital signatures require a system of keys and certificates that are difficult to manage and require substantial overhead and infrastructural complexity. These are the main reasons that such security features have not been implemented by manufacturers. A secure server containing the keys must be deployed, which will maintain the keys in perpetuity. Two sets of organizational problems need to be addressed: how to store, acquire, and recover keys and how to authenticate people requesting keys.

The DICOM standard never enforces security; it only provides for it. Manufacturers are free to implement parts of the standard as they see fit. Once implemented, these parts must be used to be effective. There are parts of DICOM that must be implemented, such as the low-level communications protocol. Most DICOM images contain no inherent security. Instead, they depend on the security of institutional networks and archives for protection from attacks. The security of these networks and archives can fail, opening the door to attacks on DICOM images.

Recent Attacks and Vulnerabilities
Previous sectionNext section

At the time of the writing of this article, four important attacks involving radiologic images had been reported in the literature: two of them were access attacks, and the other two were data injection attacks. Note that none of these attacks were performed by nefarious agents but, rather, involved reports of vulnerabilities and proof-of-concept attacks performed by security researchers.

Data Access Attacks

The networks of several hospitals are poorly protected and can be accessed from the outside [22]. In 2017, a group at Massachusetts General Hospital scanned the entire Internet address space (4 billion addresses) in 22 hours to identify unprotected DICOM servers (Pianykh OS, Radiological Society of North America 2017 annual meeting) [23]. They found 2782 unprotected servers across the globe, most of them located in the United States. Of these servers, 821 of these systems were open to a DICOM connection, and 750 were open to discovery of patient information.

In 2018, a researcher from the security company McAfee used an Internet scanning tool known as Shodan to find unprotected DICOM servers all over the world [24]. He found more than 1100 such servers directly connected to the Internet without any protection. Most of them were located in the United States. He was able to retrieve DICOM images and was even able to print a 3D model of someone's pelvic bones by using the accessed data.

Other Data Access Vulnerabilities

Even if a hospital network is well protected from the outside, a hacker can easily enter a hospital and connect a laptop to the hospital network via any standard Ethernet jack. From there, simple queries can be executed to retrieve DICOM files from DICOM servers and archives. Some hospitals restrict such queries to well-identified destinations associated with legitimate users using specific parameters, but these parameters are easy to spoof [25].

Data Injection Attacks

In March 2019, a security researcher showed how an attacker can use deep learning to automatically inject or remove abnormal findings on CT and MRI scans in DICOM messages during transfer from the scanner to the PACS [15] (Fig. 6). The attack used two deep neural networks: one for injection and the other for removal. The realism of the altered images fooled 99% of radiologists who reviewed the images. Although deep learning has been used in the past to generate fake videos and imagery, this was the first time it had been used in the medical domain to secretly tamper with 3D DICOM images.

figure
View larger version (247K)

Fig. 6A —Creation of fake lung nodules on DICOM images.

A, Original DICOM image (A) and modified DICOM image with fake lung nodules added (B) show result of hijacked transmission of DICOM messages between scanner and PACS. Deep learning was used to either add or remove lung nodules on DICOM images. Almost all radiologists who examined these tampered images were fooled by their altered content.

figure
View larger version (258K)

Fig. 6B —Creation of fake lung nodules on DICOM images.

B, Original DICOM image (A) and modified DICOM image with fake lung nodules added (B) show result of hijacked transmission of DICOM messages between scanner and PACS. Deep learning was used to either add or remove lung nodules on DICOM images. Almost all radiologists who examined these tampered images were fooled by their altered content.

In April 2019, a security researcher developed a technique to hide malware within DICOM files [16, 26–28] (Fig. 7). He did this by misusing the DICOM file preamble, which is used to make DICOM images understandable to non-DICOM imaging software [29]. The preamble is a useful feature, but it can be exploited. He created the PEDICOM hybrid format (with “PE” denoting a Windows portable executable file) by replacing the 128-byte preamble with a header capable of executing code and then replacing or creating private attributes in the DICOM file with malware code. The public attributes and the imaging data were untouched. The modified file behaved as a regular DICOM file; it could be read by a PACS and workstation, displaying its imaging data with no evidence of corruption. However, when executed from the Windows command prompt, malware code was executed, leading to compromise of the computer system.

figure
View larger version (331K)

Fig. 7 —Format of PE-DICOM file (with “PE” denoting Windows portable executable file) after injection with malware. Schematic shows formats of original DICOM file (left) and PE-DICOM file (right). In PE-DICOM file, 128-byte preamble is replaced by official DOS header at beginning of every PE file. This header points to actual malware code included in private attributes. Indicator DICM, public attributes, and image pixel data are untouched and are only shifted if necessary.

Other Data Injection Vulnerabilities

There are many additional injection vulnerabilities that can affect DICOM objects, DICOM files, and DICOM messages. Identity spoofing involves modification of the public attributes of a DICOM object to change the name and identifiers of a patient and send the file to the wrong record. A denial-of-service attack sends millions of DICOM messages to overwhelm a DICOM server, leading to denial of service. A buffer overflow sends corrupted DICOM messages to overfill the server memory space reserved to receive them, leading to potential well-known buffer overflow attacks [30] that can take full control of a workstation. Finally, there is CD autoload tampering, which modifies autoloading code on a CD with DICOM files to take over a computer when the CD is loaded on a computer in a physician's office.

Mitigations of Vulnerabilities
Previous sectionNext section

The recent DICOM attacks performed by security researchers are proofs of concept intended to alert the world about potential vulnerabilities before hackers start exploiting them on a large scale. To mitigate these vulnerabilities, all major players must do their part, from DICOM security leaders at the core of the DICOM world to radiologists as endpoint users and readers.

DICOM Security Leaders

DICOM WG-14 is well aware of the current vulnerabilities of DICOM messages and DICOM files and is tracking potential future vulnerabilities [31]. It meets monthly to review and triage security reports and suggested improvements, review work on corrections and improvements to the standard, and review work on educational material for implementers and users. Much of the work involves reviewing and adding security considerations for new features in the DICOM standard [32]. WG-14 is currently focusing on two major initiatives.

The first initiative involves management of keys and certificates. All current DICOM security features require keys and certificates to maintain confidentiality and integrity, and their management is a very complex task. This is the main limitation in the widespread adoption of those security features. WG-14 recently proposed using the automatic certificate management environment (ACME) protocol [33], which simplifies distribution and management of keys and certificates.

The second initiative involves management of network security. The National Security Agency proposed a series of milestones that should be met to make an unmanageable, insecure network more secure and more manageable. It is called the National Security Agency Manageable Network Plan [34]. WG-14 is working on adapting this plan for the DICOM standard.

Manufacturers

Some security features are already part of the DICOM standard, but most cannot be used because they have not been implemented by the manufacturers. Several tasks are required from the manufacturers.

The first task is to implement current DICOM security features. Secure transmission of DICOM messages has been implemented by some manufacturers and should be extended to all manufacturers. It is mostly implemented for transmission between institutions but should also be implemented for all internal network transmissions. Once WG-14's new features to handle keys and certificates (ACME) have been added to the DICOM standard, they should be used by manufacturers to help implement digital signatures for the integrity and encryption of media and e-mails for confidentiality.

The second task involves implementation of a creator digital signature. A creator digital signature public attribute already exists in the DICOM standard [17] and is to be filled by imaging modalities for a lifetime data integrity check. Once digital signatures are implemented, manufacturers must not only fill that field but must also implement systematic checks for these signatures by all receivers of images and issue warnings if the signature is either missing or cannot be verified.

The third task is to systematically wipe out undesired preambles from DICOM files to prevent execution of embedded malware. File deconstruction and reconstruction techniques have been proposed [14] as a solution. Preambles are always discarded when DICOM messages are transmitted on a network because DICOM messages have no preamble (Fig. 1), so only files stored on servers or media using nonstandard means need to have their preamble wiped out.

Finally, the implementation of DICOM image validators, which verify the internal consistency and bounds of DICOM objects, can help prevent buffer overflows injection and denial-of-service attacks.

Local Information Technology Experts

Local IT experts should continue to monitor their networks for suspicious activities and periodically review DICOM audit logs for suspicious access patterns. Local IT experts should focus on three important network security areas to mitigate DICOM vulnerabilities: user authentication, access control, and network and device visibility. User authentication involves the ability to accurately identify the user making a request. Multifactor authentication should be used extensively. Access control limits the activity of legitimate users. It does not eliminate the attacks but restricts the scope of the damage of an attack to the access allowed each user. In terms of network and device visibility, every internal network, DICOM server, and DICOM device should be invisible from the outside world. Limited access for DICOM data exchange with outside collaborators or vendors should be highly secured.

The combination of secure transmission, user authentication, and access control is very effective in reducing many data injection vulnerabilities and data access vulnerabilities. In addition to these two areas, the local IT team should set up the following controls to prevent specific injection attacks: rate limiters and the disabling of CD auto-loading. Rate limiters are server controls that are put in place to deal with runaway modalities that send too much data. Rate limiters put a maximum cap on how much data can be sent from a source on the network within a period. The same controls can be used to prevent denial-of-service attacks. Disabling autoloading of CDs on most hospital computers mitigates injections of malware from self-booting CDs.

Radiologists and Technologists

Radiologists and technologists occasionally face corrupted data, incomplete data, and issues of data origin. There are procedures in place to deal with such problems, and solutions are often provided by technologists or IT experts. The new injection vulnerabilities lead to the same kinds of problems, but they are perhaps multiplied by a factor of 10 or 100. Access controls, audit flags, and workflow alarms can already identify several of these problems, but radiologists must keep the CIA triad in mind.

First, it is important to maintain confidentiality. Any medical image on a laptop or CD should be encrypted or anonymized. One should never remotely view or transmit medical images on a public Wi-Fi network without the use of a virtual private network, which encrypts all communications.

Second, one must verify integrity. As health care moves into a new era of increasing information vulnerability, radiologists should understand that they may be using data that has been altered. If tampering of DICOM image pixels is suspected, it should be confirmed by using redundancy in datasets. Are the same findings present on coronal or sagittal reformatted sequences or on scout images? If tampering of DICOM image attributes is suspected, use any prior imaging and the medical history to determine whether the images belong to that patient and whether the imaging findings make sense.

Third, one must verify authenticity. Are the imaging data coming from a trusted source? Loading a CD from an unfamiliar source to read images on a local computer for a curbside consult is risky because the CD could have been tampered with, enabling it to autoexecute malware. Film libraries have computers that can safely extract DICOM images from CDs and load them into a PACS.

A major responsibility of radiologists and radiology administrators is to include available DICOM security measures in equipment specifications and purchase contracts. If users do not request security features, there is little incentive for manufacturers to include them.

Conclusion
Previous sectionNext section

Cyberattacks will pervade life in years to come, even more than they currently do. They have the power to quickly bring down entire hospitals, multinational corporations, cities, and even possibly countries. The present article, written by radiologists and top cybersecurity experts, provides an accessible introduction for radiologists to the main implications of cyberattacks as they relate to medical images. It also serves as a call to action, providing recommendations for each participant in the field to help mitigate the vulnerabilities from cyberattacks.

References
Previous sectionNext section
1. CBS News. Hackers are stealing millions of medical records—and selling them on the dark web. CBS News website. www.cbsnews.com/news/hackers-steal-medical-records-sell-them-on-dark-web/. Published February 14, 2019. Accessed July 2, 2019 [Google Scholar]
2. Schencker L. Hackers target health data: 82% of hospital tech experts reported ‘significant security incident' in last year. Chicago Tribune website. www.chicagotribune.com/business/ct-biz-hospital-data-breaches-20190307-story.html. Published March 8, 2019. Accessed July 2, 2019 [Google Scholar]
3. Coventry L, Branley D. Cybersecurity in healthcare: a narrative review of trends, threats and ways forward. Maturitas 2018; 113:48–52 [Google Scholar]
4. U.S. Department of Health and Human Services (HHS). Breach portal: notice to the secretary of HHS breach of unsecured protected health information. HHS website. ocrportal.hhs.gov/ocr/breach/breach_report.jsf. Accessed July 2, 2019 [Google Scholar]
5. Verizon Enterprise. 2018 Data breach investigations report. Verizon Enterprise website. enterprise.verizon.com/resources/reports/2018/DBIR_2018_Report.pdf. Published 2018. Accessed July 2, 2019 [Google Scholar]
6. Ronquillo JG, Winterholler JE, Cwikla K, Szymanski R, Levy C. Health IT, hacking, and cybersecurity: national trends in data breaches of protected health information. JAMIA Open 2018; 1:15–19 [Google Scholar]
7. HIPAA Journal. Healthcare data breach statistics. HIPAA Journal website. www.hipaajournal.com/healthcare-data-breach-statistics/. Accessed July 2, 2019 [Google Scholar]
8. [No authors listed]. HIPAA Journal. Court approves Anthem $115 million data breach settlement. HIPAA Journal website. www.hipaajournal.com/court-approves-anthem-115-million-data-breach-settlement/. Published August 20, 2018. Accessed July 2, 2019 [Google Scholar]
9. Chokshi N. Hackers are holding Baltimore hostage: how they struck and what's next. New York Times website. www.nytimes.com/2019/05/22/us/baltimore-ransomware.html. Published May 22, 2019. Accessed July 2, 2019 [Google Scholar]
10. Greenberg A. The Wannacry ransomware hackers made some real amateur mistakes. Wired website. www.wired.com/2017/05/wannacry-ransomware-hackers-made-real-amateur-mistakes/. Published May 15, 2017. Accessed July 2, 2019 [Google Scholar]
11. Greenberg A. The untold story of NotPetya, the most devastating cyberattack in history. Wired website. www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/. Published July 22, 2018. Accessed July 2, 2019 [Google Scholar]
12. Health Care Industry Cybersecurity Task Force. Report on improving cybersecurity in the health care industry. Public Health Emergency website. www.phe.gov/preparedness/planning/cybertf/documents/report2017.pdf. Published June 2017. Accessed July 2, 2019 [Google Scholar]
13. Morgan TA, Avrin DE, Carr CD, et al. Meaningful use for radiology: current status and future directions. Radiology 2013; 269:318–321 [Google Scholar]
14. Zaw NT, Soh K. DICOM: A ticking cybersecurity time-bomb in the healthcare industry. Healthcare Innovation website. www.athenadynamics.com/event/dicom-unknown-vulnerability-cyber-attacks-global-healthcare-industry. Published November 21, 2017. Accessed November 12, 2019 [Google Scholar]
15. Mirsky Y, Mahler T, Shelef I, Elovici Y. CT-GAN: malicious tampering of 3D medical imagery using deep learning. arXiv website. arxiv.org/abs/1901.03597. Revised June 6, 2019. Accessed July 2, 2019 [Google Scholar]
16. Picado Ortiz M. HIPAA-protected malware? Exploiting DICOM flaw to embed malware in CT/MRI imagery. Cylera Labs website. labs.cylera.com/2019/04/16/pe-dicom-medical-malware/. Published April 16, 2019. Accessed July 2, 2019 [Google Scholar]
17. DICOM Standard website. www.dicomstandard.org. Accessed July 2, 2019 [Google Scholar]
18. Bidgood WD Jr, Horii SC, Prior FW, Van Syckle DE. Understanding and using DICOM, the data interchange standard for biomedical imaging. J Am Med Inform Assoc 1997; 4:199–212 [Google Scholar]
19. DICOM Standard. DICOM supplement overview: complete list. DICOM Standard website. www.dicomstandard.org/News/ftsup/index.html. Accessed July 2, 2019 [Google Scholar]
20. U.S. Government Printing Office. Public Law 113-283: Federal Information Security Modernization Act of 2014. Govinfo.gov website. www.govinfo.gov/app/details/PLAW-113publ283/. Published December 18, 2014. Accessed July 2, 2019 [Google Scholar]
21. Dierks T, Rescorla E. The transport layer security (TLS) protocol: version 1.2. Internet Engineering Task Force website. tools.ietf.org/html/rfc5246. Published August 2008. Accessed July 2, 2019 [Google Scholar]
22. Zhou F, Wang J, Li B, Kim J. Security issues and possible solutions in PACS systems through public networks. Advanced Science and Technology Letters 79:118–123 [Google Scholar]
23. Stites M, Pianykh OS. How secure is your radiology department? Mapping digital radiology adoption and security worldwide. AJR 2016; 206:797–804 [Abstract] [Google Scholar]
24. Beek C. McAfee researchers find poor security exposes medical data to cybercriminals. McAfee website. securingtomorrow.mcafee.com/other-blogs/mcafee-labs/mcafee-researchers-find-poor-security-exposes-medical-data-to-cybercriminals/. Published March 11, 2018. Accessed July 2, 2019 [Google Scholar]
25. Tanase M. IP spoofing: an introduction. Symantec website. www.symantec.com/connect/articles/ipspoofing-introduction. Updated March 11, 2003. Accessed July 2, 2019 [Google Scholar]
26. National Institute of Standards and Technology (NIST). National vulnerability database: CVE-2019-11687 detail. NIST website. nvd.nist.gov/vuln/detail/CVE-2019-11687. Modified June 12, 2019. Accessed July 2, 2019 [Google Scholar]
27. DICOM. DICOM statement on reported malware vulnerability: DICOM security group provides user strategies to mitigate risk. www.dicomstandard.org/wp-content/uploads/2019/05/Press-Release-DICOM-128-Byte-Preamble-Posted1-2.pdf. Published May 6, 2019. Accessed July 2, 2019 [Google Scholar]
28. DICOM. DICOM FAQ response to 128-byte preamble vulnerability. DICOM website. www.dicomstandard.org/wp-content/uploads/2019/05/FAQ-DICOM-128-Byte-Preamble-Posted1-1.pdf. Published May 2019. Accessed July 2, 2019 [Google Scholar]
29. Clunie DA. Dual-personality DICOM-TIFF for whole slide images: a migration technique for legacy software. J Pathol Inform 2019; 10:12 [Google Scholar]
30. Weidman G. Penetration testing: a hands-on introduction to hacking. San Francisco, CA: No Starch Press, 2014 [Google Scholar]
31. DICOM Security Working Group 14. WG-14: security. DICOM Standard website. www.dicom-standard.org/wgs/wg-14/. Published March 10, 2003. Accessed July 2, 2019 [Google Scholar]
32. DICOM Working Group 14. Working group 14 minutes. National Electrical Manufacturers Association website. dicom.nema.org/Dicom/minutes/WG-14/. Updated 2014. Accessed July 2, 2019 [Google Scholar]
33. Tarbox LR, Horn R. Using the ACME protocol to distribute TLS certificates for securing DICOM® communications. cdn.ymaws.com/siim.org/resource/resmgr/siim2019/abstracts/BI_EI_New_Tech_Tarbox.pdf. Published 2019. Accessed July 2, 2019 [Google Scholar]
34. National Security Agency (NSA). Manageable network plan guide (version 4.0). NSA website. apps.nsa.gov/iaarchive/library/ia-guidance/security-configuration/networks/manageable-network-plan.cfm. Published December 1, 2015. Accessed July 2, 2019 [Google Scholar]
35. Menezes A, van Oorschot PC, Vanstone SA. Handbook of applied cryptography. Boca Raton, FL: CRC Press, 1996 [Google Scholar]
36. National Institute of Standards and Technology (NIST). Hash functions. NIST website. csrc.nist.gov/projects/hash-functions. Updated May 3, 2019. Accessed July 2, 2019 [Google Scholar]
APPENDIX 1: Definitions of Technical Terms
Address correspondence to B. Desjardins ().

Recommended Articles

DICOM Images Have Been Hacked! Now What?

Full Access
American Journal of Roentgenology. 2020;214:736-737. 10.2214/AJR.19.22620
Abstract | Full Text | PDF (543 KB) | PDF Plus (546 KB) 
Full Access, , ,
American Journal of Roentgenology. 2020;215:87-93. 10.2214/AJR.20.23034
Abstract | Full Text | PDF (705 KB) | PDF Plus (717 KB) | Supplemental Material 
Full Access
American Journal of Roentgenology. 2020;214:723-726. 10.2214/AJR.19.22000
Abstract | Full Text | PDF (572 KB) | PDF Plus (582 KB) 
Full Access, , , , , ,
American Journal of Roentgenology. 2020;214:738-746. 10.2214/AJR.19.21197
Abstract | Full Text | PDF (791 KB) | PDF Plus (827 KB) | Supplemental Material 
Full Access, , , , , ,
American Journal of Roentgenology. 2020;214:754-760. 10.2214/AJR.19.21794
Abstract | Full Text | PDF (736 KB) | PDF Plus (673 KB) 
Full Access, , , ,
American Journal of Roentgenology. 2020;214:853-861. 10.2214/AJR.19.22081
Abstract | Full Text | PDF (1422 KB) | PDF Plus (1198 KB)