Are DICOM Viewers Creating Security Risks in Hospitals?
Medical imaging technology relies on the DICOM standard to store, view, and share scans like X-rays, MRIs, and CTs. DICOM viewers online allow doctors convenient access to these images through web browsers. However, the WADO to STOW transition process in these viewers may unintentionally reduce security. We'll break down how hackers could leverage these DICOM transitions to infiltrate hospital systems. Understanding WADO and STOW First, let’s define the DICOM protocols involved: ● WADO : Web Access to DICOM Objects retrieves DICOM images, data, etc., from PACS through HTTP requests. ● STOW : DICOM Storage commits directly to PACS storage. WADO allows web access without exposure to the backend. STOW enables writing data straight into storage. The Problem Most DICOM viewers utilize both protocols. Images are fetched with WADO and then converted into STOW for display and manipulation. This transition opens a doorway that hackers could exploit. Atta