DICOM is no longer evolving only through incremental updates to image storage.
For imaging leaders, the most consequential developments now connect interoperability, real-time exchange, security, and the growing range of clinical data moving through imaging environments.
The latest dicom news points to a more connected standard.
Work is underway on DICOMweb live streaming and terminology that better aligns with modern REST-based services. These items remain part of an active standards process. Teams should distinguish proposals and public-comment material from changes already incorporated into the standard. The DICOM Standard news page provides the current source for that status.
That distinction matters when planning interfaces, viewer upgrades, and PACS governance.
The interoperability work offers a useful starting point for understanding changes in the way imaging systems exchange studies and live data.
Teams should define what must be validated before a change reaches production workflows.
What the latest DICOM news says about interoperability
The current DICOM news cycle points to a standard that is being refined for modern exchange, not replaced by a single new protocol. The DICOM Standard news page describes ongoing progress from base standard meetings. It also lists work that affects how imaging systems describe, transmit, and expose data. For imaging leaders, the important distinction is status. A supplement or change proposal signals work under review. A finalized addition is part of the standard that vendors can implement against.
One notable proposal is Supplement 256, which addresses live streaming through DICOMweb. If adopted and implemented, this work could give systems a more consistent way to represent and exchange streaming imaging content through web-based services. It should not be treated as evidence that every PACS, viewer, or modality supports live streaming today. Teams evaluating this capability should ask vendors which DICOMweb services and transfer behaviors are supported now. Which are roadmap items, and how the implementation handles authentication, latency, and auditability.
The same news coverage lists Change Proposal 1735, which would add DICOMweb to the DICOM glossary. And Change Proposal 2584, which would harmonize definitions and references for REST and RESTful. These are terminology and reference updates rather than announcements of a new clinical workflow. Clearer language still matters. Procurement teams, integration architects, and developers often use those terms when comparing APIs, documenting interfaces, or writing conformance statements. A more consistent vocabulary can reduce ambiguity, but it does not by itself make two systems interoperable.
That is why implementation detail remains the practical test. A hospital should validate supported services, information object definitions, transfer syntaxes, metadata behavior, error handling, and identity controls in a representative workflow. It should also distinguish standards conformance from a vendor’s completed product integration. The DICOM Standard page is the right place to monitor proposals and their status, while a vendor conformance statement and technical test remain necessary before a purchasing decision.
For a closer look at the operational side, see Teleray’s DICOM data ingestion via API. It provides implementation context for moving from a standards discussion to a controlled ingestion design. Broader health-data exchange also involves standards outside DICOM, including the FHIR interoperability standards used for clinical and administrative data.
Sources: DICOM Standard news and change proposals.
Why DICOM security news belongs in the PACS roadmap
DICOM security developments are not separate from PACS planning. They affect how imaging data is signed, stored, transmitted, and exchanged across scanners, workstations, archives, and connected clinical systems. The DICOM Standard’s current work includes updates to digital signatures and media storage security, with an emphasis on supporting modern algorithms while preserving backward compatibility. The same work responds to increasingly prominent privacy and security requirements across regions, including GDPR and US FDA cybersecurity guidance. The DICOM Standard news page identifies these items as standards work and public-comment activity, not automatically as final requirements for every deployed system.
That distinction matters when an imaging team turns dicom news into a technical plan. Proposed signature changes include deprecating legacy algorithms such as SHA-1, adding members of the SHA-3 family, upgrading certificates to X.509 Version 3, and introducing elliptic-curve digital signature profiles. These developments should prompt an inventory of which modalities, PACS components, viewers, gateways, and media workflows support current cryptographic profiles. They do not justify an unsupported claim that every existing DICOM object is insecure or that a proposal is already mandatory.
Use reported exposure findings to prioritize verification
A May 2026 HIPAA Journal report described a TrendAI analysis based on Shodan scanning data from November and December 2025. The analysis identified 3,627 internet-accessible DICOM servers in more than 100 countries. The report also stated that only 0.14% of the exposed servers used TLS encryption, while 99.56% accepted connections without AE Title validation. These are reported scan findings, not a measurement of every PACS environment. They are still useful signals for deciding what to verify in a risk assessment.
For a PACS roadmap, the practical response is evidence gathering: confirm whether DICOM endpoints are reachable from the public internet. Document permitted application entities, review TLS configuration and cipher-suite support, and verify that firewall rules restrict traffic to known sources. The DICOM Standard news page also lists a change proposal concerning TLS 1.2 cipher-suite language. Which reinforces the need to review both protocol settings and vendor support rather than treating a TLS checkbox as sufficient.
Patch governance belongs in the same review. The HIPAA Journal report described significant patch deficiencies among analyzed servers, including unpatched critical vulnerabilities. Teams should map each DICOM service to an owner, version, maintenance window, backup and recovery plan, and exception record. They should also test de-identification, audit logging, access controls, and incident response for workflows that carry protected health information in both pixel data and metadata.
For organizations formalizing this work, Teleray’s healthcare cybersecurity compliance guidance provides a relevant reference point. The goal is not to react to every headline with a platform replacement. It is to make security status visible in PACS governance, so standards changes, vendor advisories, network findings, and remediation evidence are reviewed as part of ordinary imaging operations.
What imaging leaders should know about current DICOM vulnerabilities
One recent advisory illustrates why DICOM security requires attention beyond the network perimeter. CISA identified a memory leak in Grassroots DICOM (GDCM) version 3.2.2. The issue occurs when the library parses malformed DICOM files containing non-standard value representation types in the file metadata. A carefully crafted file can consume substantial memory during a single read operation, creating a resource-depletion and denial-of-service risk. The advisory rates the vulnerability high, with a CVSS score of 7.5. CISA’s advisory provides the affected-version and vulnerability details.
This does not mean every PACS or viewer is exposed. GDCM is a library, and the practical question for an imaging organization is whether an affected version is embedded in a system that receives. Parses, converts, previews, or routes DICOM files. Imaging leaders should ask vendors and internal application owners where GDCM is used, which versions are deployed, and whether untrusted files can reach those components. Include gateways, research tools, modality workstations, de-identification utilities, and interfaces that may sit outside the core PACS inventory.
Turn the advisory into a controlled response
Start by recording the advisory and its CVE in the organization’s vulnerability-management workflow. Confirm the software bill of materials or obtain a version statement from each relevant supplier. Then follow the vendor or maintainer’s remediation guidance, apply an available update through change control, and validate that DICOM ingestion and routing still work as expected. If a supported fix is not yet available, reduce exposure while the issue is investigated. Restrict unnecessary file-processing paths, segment affected services, monitor resource consumption, and prevent unauthenticated internet access to DICOM endpoints.
Remote access deserves the same discipline. CISA recommends using secure methods such as a current VPN when remote access is required. While noting that VPN products can also contain vulnerabilities and must be kept updated. That guidance is not a substitute for identity controls, least-privilege access, MFA, logging, and network segmentation. A remote specialist collaboration workflow should preserve those controls rather than create a side channel around them. A documented review of healthcare cybersecurity compliance can help align technical safeguards with operational and regulatory responsibilities.
How DICOM developments are expanding beyond traditional radiology
DICOM development is increasingly addressing data types and workflows that do not fit the traditional model of a radiology image moving between a modality and a PACS. The DICOM Standard news page lists work involving microscopy annotations, biomedical waveforms, and related exchange mechanisms. These items should be read as standards work and proposals at different stages, not as a single completed product release. For imaging and IT leaders, the practical question is how new object types could affect governance, storage, validation, and clinical workflow design.
Microscopy brings annotations into the imaging record
Microscopy is one clear example. DICOM added a Microscopy Bulk Simple Annotation SOP Class and Information Object Definition to encode machine-generated and human-generated vector graphics annotations for slide microscopy imaging. Separately, Supplement 255 describes bulk enhanced annotations for microscopy before public comment. Together, these developments point to a more structured way to keep regions of interest, measurements. And other annotation data associated with the underlying slide rather than leaving them in disconnected tools or proprietary exports. See the DICOM Standard news updates for the status of the relevant work.
The workflow implication is not simply a need for more storage. Organizations should define which annotations are clinical records, which are research artifacts, and how each is attributed, versioned, reviewed, and retained. Governance teams should also test whether viewers, archives, downstream analytics, and exchange partners preserve the relationship between a slide and its annotations. Machine-generated marks require additional provenance and review controls so that an annotation is not mistaken for an independently verified clinical finding.
Waveform compression extends DICOM’s reach
DICOM waveform work addresses another boundary. Supplement 253 proposes an encapsulation mechanism for compressed waveform data, analogous to the way compressed pixel data is encapsulated. The work includes transfer syntaxes for both lossless and lossy compressed waveforms. The referenced T.261 format covers ECG, EEG, EMG, PPG, and other general waveform data. With support for lossy, near-lossless, and lossless compression, plus metadata, indexing for rapid access, and independent channel decoding.
For operational teams, compression choices should be tied to the intended use. A diagnostic or regulated workflow may require lossless or near-lossless handling, while a lower-bandwidth review workflow may have different requirements. Before adding waveform objects to an enterprise archive, teams should validate transfer syntax support across acquisition systems, viewers, gateways, and long-term storage. They should also document whether metadata, channel relationships, timestamps, and provenance remain intact after conversion or routing.
Digital pathology requires workflow discipline
Digital pathology makes the governance issue concrete. Dicom Systems reported that Moffitt Cancer Center partnered with it to strengthen digital pathology infrastructure. The same company reported processing 124 billion medical images across 547.9 million studies in 2025, illustrating the scale at which cross-specialty imaging infrastructure may operate. Those figures are a vendor-reported benchmark, not a universal industry total. But they reinforce the need to plan for volume, access controls, indexing, and lifecycle management across more than radiology alone.
As DICOM news expands into microscopy, waveforms, and pathology, interoperability remains only one part of the design. Each new object type needs explicit ownership, validation rules, retention policies, and workflow testing before it becomes part of routine clinical operations.
How DICOM news affects viewers, exchange, and workflow design
For imaging leaders, the practical value of DICOM news is not limited to tracking standards activity. Each development can affect how a team selects viewers, routes studies, retrieves priors, manages worklists, and supports collaboration across sites. The right response is to test whether the current environment can accommodate the relevant data and workflow. Rather than assuming that a proposed change is already a production requirement.
Evaluate the viewer as part of the clinical workflow
Viewer decisions should account for more than whether a system opens a DICOM file. Teams should review modality coverage, transfer syntax support, hanging protocols, prior-study access, annotation tools, and the way a viewer fits into the interpretation workflow. Teleray states that its platform supports DICOM 3.0 and standard transfer syntaxes across CT, MRI, X-ray, ultrasound, mammography, fluoroscopy, and PET/CT modalities. Its diagnostic viewer is described as FDA 510(k)-cleared for primary diagnostic interpretation. That wording indicates clearance for the stated use. It does not mean FDA endorsement, and it does not replace a health system’s own validation, governance, or clinical judgment. See the guide to DICOM viewer capabilities for buyer-focused considerations.
Design exchange around routing, retrieval, and worklists
As imaging data moves between modalities, PACS environments, specialists, and partner organizations, workflow design should make each handoff explicit. Ask how studies are routed, how users perform Query/Retrieve, how Modality Worklist information is synchronized, and where de-identification occurs when data is used for education, research, or collaboration. Teleray lists configurable routing, C-FIND, C-MOVE, C-GET Query/Retrieve, Modality Worklist integration, and study anonymization or de-identification among its DICOM functions. These capabilities should be tested against actual accessioning, correction, exception, and reconciliation scenarios, not just a successful test study.
A PACS review should also consider access to priors, storage behavior, and resilience. Teleray describes cloud PACS capabilities including lossless compression, prior-study comparison, multi-site sharing, and disaster recovery. Those features influence reading continuity and collaboration, but the operational details still require validation against retention policies, recovery objectives, network conditions, and local governance. The overview of PACS imaging workflows provides useful background for that assessment.
Plan for collaboration without separating it from control
Current DICOM developments also make it important to distinguish image exchange from real-time clinical collaboration. Teleray Live is described as supporting real-time modality streaming, multi-modality workflows, remote control, annotation, pointing, and recording. In practice, teams should define who can view or interact with a modality, what is recorded. How identity and authorization are established, and how the session fits into the clinical record. A workflow that supports remote specialist participation still needs clear escalation, consent, privacy, and audit procedures. For a broader view of the movement from acquisition through storage and collaboration, review Teleray’s guide to medical image collaboration.
A practical DICOM news checklist for imaging and IT teams
News about DICOM standards, security advisories, and interoperability matters only when it leads to a controlled review of your environment. Use this checklist to move from headline to evidence without treating a proposal or vendor announcement as an immediate production requirement.
| Review area | Questions to verify | Evidence to retain |
|---|---|---|
| Standards status | Is it final, under public comment, proposed, or advisory? | Source, date, item number, and owner |
| Security exposure | Which versions, endpoints, libraries, or gateways are affected? | Inventory match, mitigation, and test result |
| Workflow impact | Do routing, viewing, priors, and integrations still work? | Representative study test and escalation record |
- Confirm the status of the change. Record whether the item is a published standard, a supplement under public comment, a change proposal, a security advisory, or a vendor release. Review the source, publication date, affected services, and implementation notes. This distinction prevents teams from redesigning interfaces around work that is still being evaluated.
- Map vulnerabilities to actual components. Check the advisory against PACS servers, DICOM gateways, viewers, modality connectors, libraries, and cloud services in your inventory. Identify the affected version, exposure path, owner, and available remediation. Include file parsing and import services, not only internet-facing systems. A vulnerability in a DICOM dependency may affect a workflow even when the application is not branded as a DICOM product.
- Review TLS and AE Title controls. Confirm where DICOM traffic uses TLS, which versions and cipher suites are permitted, and how certificates are issued and rotated. Verify that each Association Request is validated against an approved AE Title, calling AE, called AE, source address, and network segment. Document exceptions rather than allowing informal device-to-device trust. The review should align with your broader healthcare cybersecurity compliance program.
- Trace integrations end to end. For each affected workflow, document the message and data path across DICOM, HL7 v2.x, FHIR R4, SMART on FHIR, web services, or file interfaces. Teleray supports these integration methods and reports connections with more than 250 EMR and EHR systems. Use that capability as a checklist for interface coverage, not as a substitute for testing the specific source and destination. Review the relevant FHIR interoperability standards alongside your interface specifications.
- Verify identity, access, and auditability. Confirm MFA, role-based access control, SSO, encryption, and audit logging for systems that store, exchange, or display studies. Teleray documents AES-256 encryption at rest, TLS 1.3 in transit, MFA, RBAC, SSO, and audit logging. Check that logs capture authentication, study access, exports, configuration changes, and administrative actions, then confirm that the responsible team can review and retain them.
- Test the clinical workflow in a controlled setting. Validate Query/Retrieve, routing, worklist behavior, viewer display, prior-study comparison, and remote collaboration with representative studies and modalities. Include failure cases such as delayed delivery, missing metadata, unsupported transfer syntax, and a rejected connection. Review the result in the context of your PACS imaging workflows. The objective is dependable operation and clear escalation, not a claim about clinical outcomes.
What should imaging leaders watch next in DICOM news?
A useful monitoring framework separates standards activity from security advisories, vendor changes, and local validation. The DICOM Standard news page tracks progress from base-standard meetings and identifies items that may still be under discussion. Treat a supplement or change proposal as an input to review, not as a requirement that is already final. For example, current entries include work on digital signatures and media storage security, as well as proposed wording for TLS 1.2 cipher suites. Those items warrant technical assessment, but not an automatic production change.
Review public-comment and standards items
Assign an owner to review new DICOM supplements, change proposals, and public-comment notices on a defined schedule. Record the item number, status, affected services, and a short impact statement. Ask whether the proposal touches your transfer syntaxes, DICOMweb endpoints, certificates, archive policies, or modality workflows. When the public-comment period closes, update the record with the final disposition and any vendor commitments. This creates a traceable distinction between watching an issue and adopting it.
Pair security monitoring with product evidence
Security review should combine CISA and CVE notices with release notes from PACS, viewer, gateway, and modality vendors. A CISA advisory identified a memory leak in Grassroots DICOM 3.2.2 that can be triggered by malformed metadata and lead to resource depletion or denial of service. CISA rated the issue high severity with a CVSS score of 7.5 and recommends defensive measures, including current VPN software when remote access is necessary. See the CISA advisory for affected-version and mitigation details. Your review record should capture exposure, compensating controls, patch availability, test results, and the accountable owner.
Test interoperability, then document the cadence
Do not rely on release notes alone. Re-test representative studies across modalities, PACS, viewers, DICOMweb services, and downstream integrations after material changes. Include malformed-file handling, authentication, TLS negotiation, routing, and audit events where relevant. A practical cadence is monthly monitoring for standards and security notices. Triage newly published critical advisories each week. Run a quarterly interoperability review with imaging, IT, security, and clinical operations. Adjust the frequency to your risk profile, but keep the evidence: notice reviewed, systems affected, decision made, test performed, and next review date.
Frequently Asked Questions
Is DICOM still relevant as imaging systems move toward web APIs?
Yes. DICOM remains the common language for medical images, metadata, and communication between modalities, workstations, and PACS. Current standards work is extending that foundation through DICOMweb, live-streaming proposals, and clearer REST terminology rather than replacing DICOM outright. The DICOM Standard news page tracks these developments.
How can healthcare organizations secure DICOM servers?
Start by keeping servers off the public internet wherever possible, isolating them behind firewalls, enforcing AE Title validation, applying vendor patches, and requiring encrypted transport. A 2025 scan identified 3,627 internet-accessible DICOM servers in more than 100 countries. Only 0.14% of the exposed servers used TLS, and 99.56% accepted connections without AE Title validation, according to the reported analysis.
What should imaging teams check when a DICOM vulnerability is announced?
Identify every affected library, viewer, gateway, and PACS component in the environment, then confirm the installed version with the vendor. Review whether untrusted files can reach the component, apply the recommended update or mitigation, and monitor logs for abnormal resource use. For example, CISA described a GDCM memory leak triggered by malformed DICOM metadata that could cause resource depletion and denial of service, with a CVSS score of 7.5. See the CISA advisory.
Does DICOM support more than radiology images?
Yes. Recent DICOM work includes microscopy annotations, waveform compression, and support for signals such as ECG, EEG, EMG, and PPG. Imaging leaders should assess how these data types affect storage, viewing, exchange, retention, and access controls before adding them to production workflows. The DICOM news and standards updates distinguish proposals from items already incorporated into the standard.
Schedule a demo with Teleray
Imaging leaders need a clear view of how interoperability, security, viewers, and workflow fit together in practice. A focused discussion can help your team evaluate the right questions for its current environment and priorities.


