Picture Archiving and Communication Systems

NJCCIC Data Breach Notification

Original Release Date: 12/2/2019

Summary

Researchers at Greenbone Networks discovered a data breach of Picture Archiving and Communication Systems (PACS) servers used globally by healthcare providers to store images of medical scans. It was found that 1.19 million data records from patients in several countries, including 786 million patients in the US, were freely available on the internet and may have included names, reasons for examination, dates of birth, Social Security numbers, and ID cards. Although most of the PACS servers have been taken offline and patient data is no longer accessible via the internet, there is an ongoing issue of PACS exposing patient data and failing to comply with proper controls, such as HIPAA.

New Jersey Cybersecurity & Communications Integration Cell

2 Schwarzkopf Dr, Ewing Township, NJ 08628

njccic@cyber.nj.gov

OUR COMMITMENT

The NJCCIC is a component organization within the New Jersey Office of Homeland Security and Preparedness. We are the State's one-stop-shop for cyber threat analysis, incident reporting, and information sharing and are committed to making New Jersey more resilient to cyber threats by spreading awareness and promoting the adoption of best practices.

Agency Seals of State of NJ, NJOHSP and NJCCIC

STAY CONNECTED:

View our Privacy Policy here.

View our Site Index here.