Medical imaging environments process millions of files daily across interconnected systems that were designed for speed and interoperability, not security. Icelandic cybersecurity firm Varist is moving to address that gap with the introduction of its DICOM Detection Engine, a specialized malware detection system built for the file formats and protocols that define modern radiology and health record infrastructure.


HotSpot Take

Varist, a cybersecurity firm headquartered in Reykjavik, Iceland, has launched the DICOM Detection Engine, a specialized malware detection system targeting the file formats and protocols used in picture archiving and communication systems (PACS), electronic health records (EHR), and radiology information systems (RIS). The engine provides real-time scanning of DICOM, HL7, and FHIR files, full-file scanning up to 3GB, and predictive payload detection for zero-day threats. All processing occurs locally to support HIPAA compliance and cyber insurance requirements. The launch addresses a documented and growing cybersecurity gap: as of late 2025, researchers found that fewer than one percent of exposed DICOM servers use TLS encryption.


A Known Vulnerability, Now Under New Pressure

The DICOM standard (Digital Imaging and Communications in Medicine) has served as the backbone of medical imaging interoperability for decades, enabling X-rays, CT and PET scans, MRIs, and ultrasounds to move seamlessly across systems and sites. That ubiquity is also its vulnerability. Security researchers and government agencies have documented for years that DICOM’s open architecture, combined with healthcare’s historically under-resourced security programs, creates an attack surface that conventional tools are poorly equipped to defend.

The scale of exposure is substantial. A Forescout Technologies honeypot study from 2024 recorded more than 1.6 million simulated attacks on healthcare environments over 12 months, with approximately 23,000 interactions specifically targeting DICOM protocols. A separate TrendAI analysis of Shodan scanning data from late 2025 found that only 0.14% of exposed DICOM servers use TLS encryption, and that 99.56% accepted connections without application entity title validation. That same analysis identified 44% of exposed servers running identical software versions, meaning a single unpatched vulnerability could propagate across hundreds of targets simultaneously.

“32% of DICOM and PACS workstations contained at least one critical unpatched vulnerability, while 20% carried known exploited vulnerabilities actively used by major ransomware groups.” (Source: Trellix research report, January 2026)

The threat landscape has since intensified. CISA issued an advisory in 2026 warning of a high-severity vulnerability in the widely used Grassroots DICOM library (tracked as CVE-2026-3650) that could allow remote attackers to crash hospital imaging systems without access credentials using specially crafted DICOM files. According to a Trellix research report published in January 2026, 32% of DICOM and PACS workstations contained at least one critical unpatched vulnerability, and 20% carried known exploited vulnerabilities actively used by major ransomware groups.

What the DICOM Detection Engine Does

Data flow diagram depicting Varist's threat detection scanner

Varist AI-Scale Threat Detection Scanner block diagram (image courtesy of Varist).

Varist is a European cybersecurity company headquartered in Reykjavik, Iceland, with technology that, according to the company, currently protects more than five billion mailboxes worldwide. The company launched its core Hybrid Detection Engine in February 2026, and the DICOM Detection Engine represents the healthcare-specific extension of that platform.

The DICOM Detection Engine provides dedicated scanning for three formats central to PACS and EHR infrastructure: DICOM, HL7, and FHIR. Among its distinguishing capabilities is hyperscale DICOM header analysis, which looks for headers that have been modified to turn imaging files into executables capable of delivering malicious payloads, a documented attack vector in which DICOM’s 128-byte preamble field can be used to embed executable code.

The system also supports full-file scanning for large medical images, including MRI files up to 3GB, covering regions of the file that conventional scanners typically skip. Predictive payload detection simulates the behavior of suspicious files to enable zero-day detection of novel DICOM exploits not yet cataloged in signature databases.

“A picture is worth a thousand words, especially when lives depend on it, and threat actors may be looking to use that to their advantage.” — Siggi Petursson, CTO, Varist

“A picture is worth a thousand words, especially when lives depend on it, and threat actors may be looking to use that to their advantage,” said Siggi Petursson, CTO of Varist. “Varist’s specialized detection for healthcare environments finds new self-evolving threats designed to evade detection by conventional systems, without adding delays or compromising patients’ care and privacy.”

On the performance side, Varist states that each instance of its Hybrid Detection Engine processes approximately 500 files per second, analyzes suspicious files in under 9 milliseconds (claiming this is 1,000 times faster than conventional sandboxes), and maintains a false positive rate below 0.001%. The architecture scales horizontally to support large multi-site networks and multi-cloud deployments.

Privacy Architecture and Compliance Alignment

A notable design decision is Varist’s on-premise processing model. Files are scanned and analyzed locally without being uploaded to public cloud infrastructure, which the company positions as aligning with HIPAA compliance requirements and the data sovereignty provisions of cyber insurance policies. For health systems operating in regulated environments with strict controls on where patient data can travel, this architecture addresses a friction point that cloud-based scanning services can create.

This design also positions Varist as an OEM integration partner rather than a stand-alone endpoint tool. Healthcare organizations and cybersecurity platform vendors can embed the detection engine within existing infrastructure, which the company states can be accomplished in hours rather than days or weeks.

A Security Gap the PACS Market Has Not Filled

The launch raises a legitimate question for health systems evaluating their imaging security posture: are the PACS vendors they rely on providing adequate protection against DICOM-specific threats?

The short answer, based on publicly available information, is that DICOM-specific malware detection is not a standard feature of leading PACS platforms. The PACS market is dominated by vendors including Sectra, which has held the top KLAS ranking for radiology PACS for more than a decade, alongside Agfa HealthCare, Fujifilm, Merge by Merative, and others. These platforms compete primarily on image management, workflow efficiency, AI integration, and interoperability. Sectra, notably, has a separate cybersecurity division focused on secure communications infrastructure, but that expertise is not the same as in-line DICOM malware scanning within the imaging workflow itself.

The DICOM standard’s own security documentation acknowledges the gap directly, recommending that healthcare delivery organizations scan DICOM files with anti-virus software before import and disable file execution when reading physical media. This guidance implicitly acknowledges that the standard does not natively enforce these controls. NIST’s Cybersecurity Practice Guide for PACS (SP 1800-24) similarly identifies PACS as a high-value, high-complexity target and recommends layered security controls beyond what PACS vendors typically provide out of the box.

Prior high-profile incidents illustrate the downstream risk. In a 2021 HHS Health Sector Cybersecurity Coordination Center advisory, federal authorities warned that known vulnerabilities in PACS systems could allow attackers to install malicious code through the DICOM protocol, manipulate medical diagnoses, falsify scans, and move laterally through connected clinical systems undetected. SimonMed Imaging, one of the largest medical imaging providers in the United States with more than 170 facilities across 10 states, disclosed a breach in early 2025 stemming from a security incident at a third-party vendor.

The Broader Context: AI-Powered Threats Change the Calculus

What distinguishes the Varist announcement from earlier PACS security advisories is its explicit focus on AI-generated malware. The company describes a threat category in which artificial intelligence is used by attackers to automate, scale, and customize cyberattacks, and in some cases to generate malware that rewrites its own code during execution to evade signature-based detection. This self-evolving malware class renders signature databases, the foundation of conventional antivirus scanning, increasingly insufficient as a primary defense.

Healthcare IT predictions published by Health IT Today for 2026 framed this shift precisely: by 2026, the speed of AI-enhanced cyberattacks was expected to outpace traditional cybersecurity defenses and human-led detection capabilities, requiring a shift toward autonomous or semi-autonomous AI-powered security responses. Medical imaging environments, with their high imaging volumes, legacy operating systems, and consistent DICOM file streams, represent an environment where that calculus has particular urgency.

Varist’s approach, combining static file scanning with real-time behavioral simulation, is designed to address threats that have not yet been cataloged, which is the defining characteristic of AI-generated attack variants. Whether that capability translates into meaningful adoption within healthcare will depend on how readily the engine integrates with existing PACS and cybersecurity vendor ecosystems, and on whether health system security teams have both the awareness and budget to treat DICOM-layer protection as a distinct procurement category.

Prior HealthTech HotSpot coverage of PACS infrastructure investment trends, including the cloud-native PACS adoption trajectory across teleradiology and multi-site health systems, provides useful context: as imaging environments move to cloud and hybrid architectures, the number of internet-accessible DICOM nodes expands along with them, broadening the surface that purpose-built detection tools like Varist’s would need to cover.


— This original article was created with AI support.


Subscribe to Our Newsletter

We keep your data private and share your data only with third parties that make this service possible. See our Privacy Policy for more information.