Date Published: September 2019
Comments Due: November 18, 2019 (public comment period is CLOSED)
Email Questions to: hit_nccoe@nist.gov
, , , , , , , ,
Medical imaging plays an important role in diagnosing and treating patients. The system that that manages medical images is known as the Picture Archiving Communications System (PACS) and is nearly ubiquitous in healthcare environments. PACS fits within a highly complex healthcare delivery organization (HDO) environment that involves interfacing with a range of interconnected systems. This complexity may introduce or expose opportunities that allow for malicious actors to compromise the confidentiality, integrity and availability of the PACS ecosystem.
The NCCoE at NIST analyzed risk factors regarding the PACS ecosystem by using a risk assessment based on the NIST Cybersecurity Framework and other relevant standards. The NCCoE developed an example implementation that demonstrates how HDOs can use standards-based, commercially available cybersecurity technologies to better protect the PACS ecosystem.
The NCCoE's practice guide NIST SP 1800-24, Securing Picture Archiving Communications System, will help HDOs implement current cybersecurity standards and best practices to reduce their cybersecurity risk, while maintaining the performance and usability of PACS.
Access Control; Configuration Management; Contingency Planning; Identification and Authentication; Risk Assessment; System and Communications Protection; System and Information Integrity
Publication:
Draft SP 1800-24 files
Supplemental Material:
None available
Document History:
09/16/19: SP 1800-24 (Draft)
12/21/20: SP 1800-24 (Final)
Security and Privacy
access control; authentication; personally identifiable information; risk assessment; security programs & operations; vulnerability management
Technologies
cloud & virtualization; firewalls; hardware; storage
Applications
cybersecurity framework; Internet of Things
Laws and Regulations
Health Insurance Portability and Accountability Act
Sectors
healthcare