How to Prepare for, Survive, and Recover From a Cybersecurity Attack: A Guide for Radiology Practices-<i>AJR</i> Expert Panel Narrative Review.

Desjardins, Benoit; Sammer, Marla B K; Towbin, Alexander J; Balthazar, Patricia; Staynings, Richard; Chen, Po-Hao · AJR Am J Roentgenol · 2026

expert_opinion · Level V

Where this comes from

Abstract

In an era of persistent and evolving cyberthreats that pose serious risks to patient safety, institutional integrity, and regulatory compliance, health care organizations, particularly radiology departments, must adopt a proactive stance toward cybersecurity. Radiology departments are particularly vulnerable to cyberattacks due to their dependence on digital imaging systems that often are legacy systems and insecure as well as their reliance on network connectivity and specialized software. This <i>AJR</i> Expert Panel Narrative Review offers a strategic road map for health care institutions to prepare for and survive cybersecurity attacks, with a focus on the unique vulnerabilities within medical imaging systems that radiology departments must address. Real-world threats, ranging from PACS network exploitation to DICOM data manipulation, ransomware disruptions, and the consequences of inaction, are examined. Emphasis is placed on practical defense mechanisms, including layered security architecture, regular vulnerability assessments, employee training, and incident response simulations. The insights are intended to inform a defense-in-depth strategy incorporating physical, technical, and administrative safeguards aligned with HIPAA and other regulatory standards. Overall, this guide for radiology practices seeks to align technical controls with operational resilience, to aid practices in detecting, containing, and recovering from cyber incidents with minimal disruption to patient care.

Medical subject headings