Protect the PACS boundary

Security that understands the content inside DICOM communication.

DICOM Application Firewall operates inside an existing imaging network as a controlled entry point to the PACS. It accepts the incoming association, reads the DICOM object, applies policy, and forwards only permitted content.

Protection can be based on the source, requested operation, image type, dataset structure, tag values, or privacy rules. Every decision becomes part of a clear audit trail.

InspectEnforceAudit
Security capabilities

Control who connects, what they send, and what reaches the archive.

DICOM-aware policy adds a security layer beyond network ports and addresses.

01

Association control

Authorize calling and called AE titles and restrict the DICOM operations each source may perform.

02

Dataset inspection

Validate object structure, required tags, image type, and permitted data before forwarding.

03

Privacy transformation

Remove or replace sensitive attributes according to the destination and intended workflow.

04

Audit and response

Record allowed, blocked, transformed, and quarantined activity with a clear reason.

Protected ingest

Terminate, inspect, enforce, then forward.

The PACS receives a new, policy-compliant DICOM association instead of the unchecked source connection.

DICOM sourceAssociation + objectInspectIdentity + structure + tagsEnforce policyAllow + transform + blockPACS / VNAPermitted content
Security value

Put a DICOM-aware control point in front of the archive.

Application-layer visibility

Make security decisions using DICOM meaning, not only network information.

Cleaner archive input

Stop malformed, unauthorized, or policy-breaking content before storage.

Accountable movement

Maintain an audit record of every decision at the PACS boundary.

Protect the PACS at the DICOM layer.

Discuss association control, content inspection, privacy rules, and audit requirements.

Discuss DICOM Firewall