Connect with us

Tech Features

WHEN MEDICAL SCANS END UP ONLINE: THE QUIET RISK HOSPITALS CAN FIX FAST

Published

on

Attributed by Osama Alzoubi, Middle East and Africa VP at Phosphorus Cybersecurity

As Saudi Arabia races ahead in digital healthcare transformation, a quieter vulnerability lingers in the background: medical imaging systems that can be found – and sometimes accessed – directly from the public internet. Imaging infrastructure, diagnostic platforms, and hospital information systems are being modernized at speed improving outcomes, accelerating workflows, and bringing advanced clinical capabilities to more communities. But beneath this progress lies a quieter risk that rarely makes headlines: medical imaging systems being exposed on the public internet due to simple configuration errors.

Not a dramatic cyberattack. Not a threat actor breaching a firewall. Just avoidable misconfigurations that leave sensitive patient data reachable by anyone who knows where to look.

Medical imaging systems in Saudi Arabia face a persistent security challenge that differs from dramatic cyberattacks. Patient data exposure often occurs through configuration errors that leave systems accessible on the public internet. These technical oversights represent a significant vulnerability in healthcare’s digital infrastructure.

The Kingdom’s Personal Data Protection Law (PDPL) establishes strict requirements for handling health data. This legislation, modeled after international standards, mandates enhanced protection for medical information and imposes penalties for unauthorized disclosure. Hospitals must implement organizational and technical measures to prevent data exposure.

Radiology departments increasingly use digital platforms for case discussions and second opinions. Without proper configuration, these systems might allow unintended access to patient records. Teleradiology services, which expanded significantly during the pandemic, require secure transmission protocols to protect data during remote consultations.

When we hear about data breaches, we often imagine skilled hackers penetrating security systems. The reality is often simpler and more preventable. “Exposed” typically means a system is reachable from the public internet due to setup choices, not a sophisticated intrusion.

This happens in real-world healthcare settings for straightforward reasons: rushed deployments to meet clinical deadlines, vendor-supplied default configurations that were never changed, remote support access left open for convenience, and legacy systems that were connected to modern networks without proper security reviews.

The scale is significant. Research has identified over 1.2 million reachable devices and systems globally, including MRI scanners, X-ray systems, and related medical infrastructure. These are not theoretical vulnerabilities. They represent actual systems that can be found and accessed from anywhere with an Internet connection.

What gets exposed is more than images

Medical imaging files are not simply pictures. They carry identifiers and metadata that can connect scans directly to real people. Patient names, dates of birth, identification numbers, and clinical details often travel alongside the diagnostic images themselves.

This matters for several reasons. Beyond the obvious privacy violation, exposed patient imaging data creates risks of identity fraud, potential coercion or blackmail, serious reputational damage to healthcare institutions, and erosion of the trust patients place in their medical providers.

Security monitoring platforms have documented cases where exposed systems allowed direct access to both images and patient data—offering a level of detail that should never be open to anyone outside the clinical team.

Why this keeps repeating worldwide

Hospitals everywhere use similar device types and manage comparable data flows. The result is that the same setup mistakes appear repeatedly across different countries and healthcare systems. What starts as one hospital’s misconfiguration becomes everyone’s common failure mode.

The medical devices themselves often come with similar default settings. Imaging servers, picture archiving systems, and diagnostic viewers are deployed in comparable ways. When basic security steps are skipped during installation, the exposure follows a predictable pattern.

Health sector cybersecurity guidance from international authorities emphasizes the need for repeatable baseline controls precisely because these patterns recur. Reducing exposure requires not innovation, but consistent application of known protective measures.

Healthcare organizations face a common vulnerability pattern. A major healthcare provider addressed similar challenges across hundreds of hospitals, discovering that default passwords, vulnerable firmware, and device misconfigurations created entry points that threatened patient care and hospital operations across more than 500,000 connected medical and operational devices.

The Saudi-specific layer: connectivity at cluster scale

Saudi Arabia’s healthcare transformation includes the expansion of health clusters that connect multiple facilities into integrated networks. This approach improves care coordination and resource sharing, but it also means that one weak link can affect multiple sites.

National interoperability initiatives support the sharing of imaging and diagnostic reports across the healthcare system. The Saudi health ministry has established specifications for imaging data exchange through the national health information exchange platform, enabling providers to access patient scans regardless of where they were originally performed.

This connectivity is essential for modern healthcare delivery. It allows specialists to review scans remotely, supports second opinions, and ensures continuity of care when patients move between facilities. However, it also increases the need for consistent configuration rules and security standards across all connected sites.

When imaging systems within a cluster are not uniformly secured, the exposure risk multiplies. A misconfigured system in one facility can potentially provide access to data from across the entire cluster network.

A practical checklist hospitals can act on

Healthcare institutions can take concrete steps to reduce exposure risk. These are not theoretical recommendations but proven measures that address the most common vulnerabilities.

First, create a complete inventory. Every hospital should maintain a current list of what is connected to its network, including imaging devices, storage servers, viewing stations, web portals, and remote access tools. You cannot protect what you do not know exists.

Second, check external exposure. Verify that nothing sensitive is reachable from the public internet. This requires technical scanning from outside the hospital network to identify systems that respond to external queries. Many organizations discover exposures they did not realize existed.

Third, restrict remote access properly. Remote connections for maintenance and support should be tightly controlled, require strong authentication methods, and be removed entirely when no longer needed. Convenience should never override security when patient data is involved.

Fourth, implement safe setup procedures. Develop standard build guides for imaging systems, change all default passwords and settings, clearly document who owns each system, and establish responsibility for applying security patches and updates. Industry experience shows that default credentials remain one of the lowest barriers for attackers seeking entry into healthcare networks.

Fifth, conduct continuous checks. Exposure scanning should happen after any network changes, not just once annually. Healthcare networks evolve constantly, and new vulnerabilities can appear whenever systems are added or reconfigured.

These steps align with guidance from international cybersecurity authorities and health sector regulators, which emphasize reducing exposed services and strengthening baseline controls as priority actions for healthcare organizations.

The governance fix: make secure setup part of how clusters run

Individual hospital efforts are necessary but not sufficient. At the cluster level, governance structures must embed security into standard operations.

This begins with cluster-wide minimum standards for imaging systems and remote access. Every facility within a cluster should follow the same baseline security requirements, ensuring consistent protection regardless of which site a patient visits.

Clear ownership must be established for every system. Someone specific should be responsible for applying patches, approving access requests, and regularly checking for exposure. When accountability is diffuse, critical tasks get overlooked.

Procurement processes offer another leverage point. Purchase agreements should require vendors to provide secure default configurations, enable comprehensive logging capabilities, and commit to supported update cycles for the life of the equipment. Security should be a selection criterion, not an afterthought.

These governance approaches reflect sector framework guidance that encourages structured programs and repeatable controls rather than ad hoc responses to individual incidents.

Saudi Arabia has invested heavily in national cybersecurity frameworks and regulatory oversight across critical sectors, including healthcare. The foundation exists. The next step is ensuring those protections extend fully to the expanding ecosystem of IoT and IoMT devices — where simple configuration gaps can undermine otherwise sophisticated digital progress.

Prevent avoidable incidents

The goal is not perfection. Healthcare systems are complex, and some level of risk will always exist. The goal is removing the easiest path for data exposure: systems sitting openly on the public internet waiting to be found.

In connected healthcare, the quickest wins come from two simple principles: visibility and access control. Know what you have connected, and shut the doors that do not need to be open.

For Saudi Arabia’s health clusters, this represents an achievable objective. The infrastructure investments being made across the Kingdom’s healthcare sector create an opportunity to build security into expansion rather than retrofitting it later.

Medical imaging systems serve an essential clinical purpose. They should not also serve as unintended windows into patient data. With practical steps and consistent governance, hospitals can fix this quiet risk before it becomes a public incident.

In digital healthcare, exposure is rarely a mystery. It is usually a configuration. The question is not whether hospitals can fix it, but whether they will do so before patients pay the price.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Spotlight

Clarity Before Compute: Why AI Strategy Must Come Before Infrastructure

Published

on


Enterprise AI has entered a new phase. The conversation is no longer centred on whether organisations should invest in artificial intelligence, but on how they can transform that investment into measurable business value.

By: Mohammed Hilili – General Manager, Lenovo Gulf

Across the GCC, enterprises are moving beyond experimentation. Pilot projects are giving way to enterprise-wide deployments as organisations seek to integrate AI into customer experiences, business operations, software development, cybersecurity and decision-making. Yet despite growing investment, many AI initiatives continue to struggle to deliver the outcomes leadership teams expect.

In my experience, the reason is rarely the technology itself. More often, organisations begin with the wrong conversation.

Too many AI discussions start with infrastructure specifications, GPU availability or the latest foundation models. These are undoubtedly important decisions, but they are not the first ones organisations should make.

The first question is much simpler.

What business problem are we trying to solve?

Without a clear answer, AI initiatives often remain isolated demonstrations of technical capability rather than platforms capable of delivering sustainable business value.

From AI Pilots to Enterprise Platforms

Across industries, organisations have spent the past two years experimenting with generative AI. Many have successfully launched departmental pilots that demonstrate what AI can achieve within a controlled environment. The greater challenge now lies in scaling those experiments across the enterprise.

That transition requires far more than additional computing power. It demands clear governance, high-quality data, well-defined business objectives and an architecture capable of supporting continuous growth. Successful AI adoption is increasingly becoming an organisational transformation exercise rather than simply another technology deployment.

Business Strategy Before Infrastructure

I recently worked with a leading regional financial institution looking to strengthen its research and development capabilities through AI. The ambition was clear, but many practical questions remained unanswered.

How much computing capacity would the organisation require? Which GPU architecture would support both current and future workloads? How could the environment remain scalable as AI adoption expanded across the business?

These may appear to be technology questions. In reality, they are strategic business decisions with long-term operational consequences.

Instead of beginning with hardware selection, we started by understanding the organisation’s objectives. Together with the leadership team, we assessed AI readiness, identified priority business outcomes and defined what success would look like before discussing infrastructure.

Only after establishing that foundation did we determine the appropriate compute resources, architectural approach and deployment model required to support long-term growth.

The result was not simply a successful implementation but an AI platform capable of evolving alongside the organisation’s ambitions.

AI Readiness Extends Beyond Technology

Many organisations still view AI readiness primarily through the lens of infrastructure. In reality, readiness begins much earlier.

Leadership alignment, data quality, governance frameworks, cybersecurity, skills development and measurable business outcomes all influence whether an AI initiative succeeds or stalls. Infrastructure remains essential, but it should support strategy rather than define it.

The organisations achieving the strongest results are those treating AI as a long-term business capability rather than a series of disconnected technology projects.

Building for a Hybrid AI Future

Enterprise AI environments are also becoming increasingly hybrid. Certain workloads will remain on-premises to address latency, compliance or data sovereignty requirements, while others will leverage the scalability of public cloud environments.

This makes architectural flexibility increasingly important. Organisations need infrastructure strategies capable of supporting multiple deployment models while allowing AI workloads to evolve alongside changing business priorities.

Selecting technology is therefore no longer simply about purchasing hardware. It is about building an adaptable foundation capable of supporting continuous innovation over many years.

The GCC Opportunity

The GCC is uniquely positioned to accelerate enterprise AI adoption. Governments across the region continue investing heavily in digital transformation, sovereign AI capabilities and next-generation cloud infrastructure while strengthening regulatory frameworks around data governance and cybersecurity.

These investments provide organisations with an increasingly mature environment in which to deploy AI at scale. However, long-term success will depend less on access to technology than on the ability to align AI investments with clear operational priorities and measurable business outcomes.

As AI becomes embedded within core enterprise operations, leadership decisions made today will determine competitive advantage for years to come.

Why Clarity Still Comes Before Compute

Technology will continue evolving at remarkable speed. New AI models, specialised processors and deployment approaches will continue reshaping the enterprise landscape.

What will remain constant is the importance of making the right decisions before investing.

At Lenovo, this philosophy shapes how we work with customers. We believe AI is not simply a product to deploy, but an organisational capability that develops over time. By combining advisory expertise with infrastructure, lifecycle services and long-term planning, organisations can reduce uncertainty, optimise investment and build AI platforms that continue creating value as business needs evolve.

The organisations that lead in the AI era will not necessarily be those with the largest AI budgets or the most powerful infrastructure. They will be those that begin with business clarity, build the right foundations and scale with purpose.

Because in enterprise AI, infrastructure enables transformation—but clarity makes it possible.

Continue Reading

Tech Features

Why UAE organisations cannot afford to get their AI storage strategy wrong

Published

on

BY: Owais Mohammed, Regional Lead & Sales Director at WD for the Middle East, Africa, Turkey, and the Indian Subcontinent

The UAE’s ambition to become a global AI powerhouse is well established. Government investment is flowing, infrastructure is scaling, and organisations across every sector are accelerating their AI programs. But beneath the strategic announcements and the technology deployments, a fundamental question goes unanswered: is the data storage infrastructure underpinning all this built for what comes next?

For many organisations, the honest answer is: not yet. Storage is rarely the first conversation in an AI strategy discussion. It tends to be treated as a commodity decision made late in the planning cycle, long after the headline architecture choices like GPUs/CPUs have been made. That approach made sense in simpler times, but not in today’s data-driven AI economy.

The scale of what is coming

To understand why, organisations need to understand the sheer data volume that is coming their way. Global data creation is forecast to rise to 718.5 Zettabytes (ZB) through 2030 (IDC source: Market Forecast: IDC Global DataSphere Forecast, 2026-2030, June 2026, Doc #US53425426), more than tripling in five years.

AI is both a driver and a consumer of this growth. Every model trained, every inference run, every data pipeline operating continuously across a distributed architecture is generating and demanding access to data at a scale that earlier generations of infrastructure were not designed to support.

Businesses that will absorb this growth successfully are not those with the fastest individual components. They are those with architectures designed to handle volume, variety, and velocity simultaneously, at a cost that remains economically sustainable as scale increases. That is the storage strategy challenge that needs to be addressed upfront and not as an afterthought.

Why a single technology cannot solve it

A common mistake is to frame the storage decision as a technology choice: SSDs versus HDDs, flash versus spinning disk, performance versus capacity. The world’s most sophisticated storage operators, including hyperscalers and major cloud service providers, have already moved past this framing. They do not choose one technology. They deploy multiple of them, in a tiered architecture that places data on the medium best suited to its requirements.

The logic is straightforward. SSDs deliver the high IOPS and low latency that real-time, performance-critical applications demand. HDDs provide the massive capacity and cost efficiency required for the vast middle tier of active and warm data, and currently continue to represent approximately 63% of worldwide installed storage capacity through 2030. Tape generally handles archival, regulatory, and compliance workloads where retrieval times of hours or days are acceptable, representing just under 8% of worldwide installed cloud storage capacity in 2025.

These are not competing technologies. They are complementary ones, each serving a distinct purpose within a coherent architecture. The question is how each is deployed where it delivers the greatest value.

Making tiered architectures work in practice

Knowing that tiered storage is the right model and implementing it effectively are two different things. At the scale hyperscalers operate, where storage volumes are measured in hundreds of exabytes, manual allocation of data across tiers is neither practical nor efficient.  Nor can all data live on cost prohibitive flash. The mechanism that makes tiered architecture manageable is software-defined storage (SDS), which pools resources centrally and provisions capacity dynamically based on demand. Rather than pre-allocating fixed capacity to individual applications, SDS responds to where data needs to be, improving overall utilisation and reducing waste.

Together, tiered architecture and SDS provide the flexibility and economic efficiency that hyperscale environments depend on. But this model is not the exclusive preserve of the world’s largest operators. For emerging infrastructure providers, including Neoclouds that are expanding rapidly across the region, the same principles apply. Architecture decisions made today will determine whether future growth is economically sustainable or structurally constrained. The window to get this right is earlier than many organisations assume.

Innovation at the storage level

Architectural thinking also changes how storage technology itself must evolve. An organisation that understands its workloads, plans for data growth, and builds tiered infrastructure will eventually reach the limits of what current storage innovations can deliver. That is why, manufacturers like WD are approaching HDDs not only as a mature, reliable product but as a technology with significant headroom remaining to help increase capacity, lower power and cost effectively scale AI data. They are advancing recording technologies, exploring novel materials, and embedding intelligence at the drive level. The aim is not incremental improvement. It is expanding the boundary of what high-capacity storage can deliver for the architectures customers are building today and the workloads they will run tomorrow.

The leadership dimension

The organisations that navigate the AI era most effectively will not be those that simply procure the latest hardware. It will be those that understand the architectural decisions that determine long-term performance, cost and scale, ask better questions earlier in the planning process, and treat storage infrastructure strategy as a source of competitive advantage rather than a procurement exercise.

Storage sits at the foundation of every AI workload, every data pipeline, and every digital service an organisation delivers. Getting the architecture right is not a technical detail. It is a leadership decision. And in a market moving as quickly as the UAE’s, it is one that deserves to be made with the same rigour and strategic intent as any other.

Continue Reading

Tech Features

Beyond a Seat at the Table: How Emirati Women Are Leading the UAE’s Next Chapter

Published

on

Every year, Emirati Women’s Day offers a moment to pause and reflect on just how far Emirati women have come, and how much further their ambitions are taking them. Across artificial intelligence and technology, entrepreneurship, sustainability, industry and beyond, Emirati women are no longer simply entering these spaces, they are shaping them, leading critical decisions and setting new benchmarks for what is possible.

This progress has not happened by chance. It is the result of a national vision that has consistently placed women’s empowerment at the heart of the UAE’s development, widely regarded as the driving force behind the advancement of Emirati women. Together, these efforts have built an ecosystem of mentorship, opportunity and structural support that allows Emirati women to move beyond simply having a seat at the table to actively influencing the direction of entire industries.

This Emirati Women’s Day, we spoke to three Emirati women who are doing exactly that, each carving out space in fields as varied as AI infrastructure, entrepreneurship and industrial sustainability. Their stories reflect not only how far the journey has come, but also a shared sense of responsibility: to keep the doors open, and to inspire the next generation of Emirati women to walk through them with confidence.

Amal Almaamari, Program Director at Core42, (a G42 Company)

The UAE has created an environment where women are encouraged to pursue ambitious careers, take on meaningful responsibilities and contribute to sectors that are shaping the country’s future. As an Emirati woman working in AI, I see this opportunity firsthand. At Core42, I am able to contribute to the infrastructure and capabilities helping organizations adopt AI securely, at scale and with greater control over their data and technology.

What is particularly inspiring is seeing Emirati women increasingly take on roles across engineering, product development, strategy and leadership. The opportunities available today allow us not only to participate in the technology sector, but to build expertise, influence decisions and contribute to the UAE’s ambitions in AI and advanced technology.

Emirati Women’s Day is a celebration of that progress and the confidence the UAE continues to place in its women. It also reminds us of our responsibility to build on these opportunities and inspire the next generation of Emirati women to see technology as a field where they can grow, lead and make a lasting impact.

Amreen Iqbal, Founder and Creative Director of Piece of You

What stands out to me about building a business here is how much the UAE actively invests in women being part of its growth story. From mentorship networks to platforms that put Emirati entrepreneurs in front of the right audiences, the opportunities aren’t hypothetical, they’re structural. Piece of You exists because I had the confidence and support to take an idea and turn it into something real. On Emirati Women’s Day, I think about how many doors have opened for women in my generation that weren’t open before, and how many more are opening for the next one.

Hamda Al Shamsi, Admin Assistant at Geocycle Waste Recycling UAE at Holcim UAE

The UAE has created an environment where women are empowered to pursue their ambitions, develop their skills, and contribute meaningfully across every sector. Today, Emirati women are building careers in fields ranging from technology and engineering to sustainability, manufacturing, energy, and leadership.

As an Emirati woman and the only woman currently working at Geocycle UAE, I have personally experienced the importance of having the opportunity to step into a technical and industrial field and prove that there is a place for women in every sector.

For me, Emirati Women’s Day is a celebration of how far we have come, but also a reminder of the opportunities ahead. The support and vision of the UAE leadership, together with the efforts of Her Highness Sheikha Fatima bint Mubarak, have helped create a generation of Emirati women who are confident to pursue their goals and make a difference. I believe the next step is to continue encouraging young Emirati women to explore fields they may not traditionally consider. When women are given the opportunity to learn, lead, and contribute, they do not only build successful careers — they help build a stronger and more sustainable future for the UAE.

Continue Reading

Trending

Copyright © 2023 | The Integrator