News | Cybersecurity | August 08, 2025

Researchers found that 1.2 million healthcare devices and systems were exposed online — risking exposure of patient records.

European Cybersecurity Firm Finds 1+ Million Healthcare Devices, Systems Exposed Online

Aug. 07, 2025 —- New research by European cybersecurity company Modat revealed more than 1.2 million internet-connected healthcare devices and systems are exposed and vulnerable to exploitation endangering patient data. The number one finding in the study showed there are more than 174,000 exposed systems in the United States (most results are across Europe, the USA, and the MENA). 

Research was conducted using Modat's unique internet scanning platform Modat Magnify.  Findings across more than 70 different types of medical devices and systems including: MRI, CT, X-rays, DICOM viewers, blood test systems, hospital management systems and other accessible medical systems. Reasons for Vulnerable Devices are misconfigurations and insecure management settings, default or weak passwords and unpatched vulnerabilities in firmware or software.

Researchers discovered many systems lacked even basic authentication. Some used factory-default or weak passwords like, “admin” or “123456.” In other cases, outdated or unpatched software left critical devices vulnerable to exploitation. These oversights compromise patient confidentiality and may open a path for cybercriminals to carry out fraud, extortion, or network infiltration.

One scan, for instance, exposed a patient’s chest and brain MRI results, with names and medical history. Records include highly sensitive PHI info and PII info. Researchers uncovered a range of other medical images: optician eye exams, dental X-rays, blood test results, detailed lung MRIs commonly used to aid patients suffering from lung cancer. 

Modat immediately reached to international partners Health-ISAC and Dutch CERT Z-CERT to initiate process of Responsible Disclosure as they will reach out to affected organizations to assist them in fixing these security breaches. 

The findings emphasize that cybersecurity in healthcare is an IT concern, and a matter of patient safety.

These systems should never be exposed to the internet in the first place. Soufian El Yadmani, Modat CEO stated, “The question we should be asking is, 'Why are there MRI scanners with internet connectivity that lack proper security measures?'”  

El Yadmani continued, "The primary risk is unnecessary network exposure. These medical systems should only be connected to secure, properly configured networks when there is a legitimate clinical need for remote access.” 

Recommendations include need for organizations to implement regular security assessments and maintain comprehensive asset inventories, continuous monitoring of network-connected devices is essential for identifying potential exposures, misconfigurations, or emerging vulnerabilities. 

Full blog post is available at http://bit.ly/4moChak  


Related Content

News | Archive Cloud Storage

Nov.18t, 2025 — Gradient Health recently announced its Atlas platform is now available on Google Cloud Marketplace ...

Time November 18, 2025
arrow
News | Radiology Imaging

Nov. 13, 2025 — Medical imaging AI company Avicenna.AI has launched AVI, a new platform that delivers AI results ...

Time November 13, 2025
arrow
News | Radiology Business

Nov. 12, 2025 — Siemens has announced plans to deconsolidate its remaining stake in Siemens Healthineers (currently ...

Time November 13, 2025
arrow
News | Artificial Intelligence

Nov. 6 — 2025, Gradient Health and DataFirst have announced a strategic partnership designed to bridge the gap between ...

Time November 12, 2025
arrow
News | Teleradiology

Nov. 4, 2025 — Virtual Radiologic (vRad) recently announced the successful commercialization of The vRad Platform — a ...

Time November 10, 2025
arrow
Feature | Archive Cloud Storage | Shujah Dasgupta, Vice President, CitiusTech

Almost two-thirds of health systems are already using (or plan to use) the cloud for storing and viewing medical images ...

Time October 30, 2025
arrow
News | Remote Viewing Systems

Sept. 2, 2025 — As American hospitals continue to grapple with an increasing shortage of specialized medical imaging ...

Time September 04, 2025
arrow
News | Advanced Visualization

July 28, 2025 — Frost & Sullivan has named Siemens Healthineers the 2025 North America Company of the Year in the ...

Time July 28, 2025
arrow
News | Radiology Imaging

July 25, 2025 — Data in recent staffing surveys from the American Society of Radiologic Technologists show that vacancy ...

Time July 25, 2025
arrow
News | Teleradiology

May 21, 2025 — Konica Minolta Healthcare Americas, Inc and NewVue have announced the introduction of Exa Teleradiology ...

Time May 21, 2025
arrow
Subscribe Now