How to Perform a HIPAA Risk Assessment for a Radiation Oncology Planning Workstation Exporting CT Simulation Data

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Perform a HIPAA Risk Assessment for a Radiation Oncology Planning Workstation Exporting CT Simulation Data

Kevin Henry

HIPAA

July 19, 2026

8 minutes read
Share this article
How to Perform a HIPAA Risk Assessment for a Radiation Oncology Planning Workstation Exporting CT Simulation Data

HIPAA Risk Assessment Fundamentals

Purpose, scope, and key definitions

Your goal is to safeguard electronic protected health information (ePHI) generated during CT simulation and manipulated on a radiation oncology planning workstation. The HIPAA Security Rule requires administrative, technical, and physical safeguards tailored to your environment and risks. A formal risk assessment clarifies where ePHI lives, how it moves, and which controls lower the likelihood and impact of incidents.

Define the system boundary and assets

Start by mapping the boundary: the planning workstation, connected storage, local databases, operating system temp folders, DICOM listeners, user profiles, and any export paths. Include upstream sources (CT simulator, PACS) and downstream targets (treatment planning systems, oncology information systems, cloud archives). Catalog all ePHI elements, such as DICOM headers, RT structures, plan files, screenshots, and logs.

Methodology and deliverables

Use a structured approach: inventory assets, diagram data flows, identify threats and vulnerabilities, evaluate likelihood and impact, select risk mitigation strategies, and document residual risk. Keep a risk register, data flow diagrams, and a prioritized remediation plan. A security risk assessment (SRA) tool can streamline evidence collection and scoring, but your analysis and decisions remain paramount.

Risk rating and acceptance

Apply a simple, defendable model (for example, low/medium/high likelihood and impact). Focus on realistic scenarios like misdirected DICOM data transfer, unencrypted exports, or unauthorized workstation access. For each risk, assign an owner, a target completion date, and acceptance criteria to verify that the new control actually reduces exposure.

Radiation Oncology Workstation Environment

Typical architecture and trust boundaries

The planning workstation ingests CT simulation images via DICOM, processes them with contouring and planning software, and exports datasets to treatment planning or delivery systems. Trust boundaries exist between clinical networks, vendor remote support paths, and any research or teaching environments. Each boundary shift changes the threat profile and determines where you need additional controls.

ePHI touchpoints

ePHI resides in more places than the primary application. Expect copies in application caches, temporary directories, local databases, Windows page files, mapped shares, and exported media. Audit ancillary utilities—screen capture tools, PDF generators, or print queues—because they may create ePHI artifacts outside the main DICOM repositories.

People and processes

Roles include dosimetrists, physicists, therapists, and IT/biomed. Document who imports, reviews, approves, and exports CT simulation data. Note handoffs during shift changes and after-hours coverage, when access controls and logging are most likely to be bypassed or missed.

CT Simulation Data Handling

Map end‑to‑end data flows

Diagram each step: acquisition on the CT simulator, DICOM push or pull to the workstation, processing and contouring, plan generation, and outbound DICOM data transfer to downstream systems. Add alternate paths such as research de‑identification, teaching cases, second opinions, and off‑network vendors. For every step, record the source, destination, protocol, credentials, and storage location.

Controls for ingestion, processing, and export

Require authenticated associations for DICOM peers and restrict communications to approved AE Titles and IPs. Enforce encryption in transit where supported, and document any exceptions with compensating controls. During export, prevent writing ePHI to removable media unless policy, encryption, and custody tracking are in place. Use checksum or hash verification for integrity, and verify recipient identity before release.

Retention, de‑identification, and purging

Define retention aligned with clinical, legal, and research needs. Where disclosure is not required, apply DICOM de‑identification profiles and ensure no PHI appears in filenames or screenshots. Implement automated cache purging and secure wipe procedures for temporary directories to reduce residual ePHI exposure.

Risk Identification and Analysis

Common threats and vulnerabilities

High‑impact scenarios include misconfigured DICOM nodes sending data to the wrong destination, weak ePHI access controls on shared logins, unencrypted exports, ransomware on the workstation, and outdated operating systems or antivirus definitions. Physical risks include unattended sessions in semi‑public areas and improper disposal of failed drives or removable media.

Vulnerability assessment and likelihood/impact

Run a vulnerability assessment to detect missing patches, insecure services, weak ciphers, or default credentials. Pair each finding with a plausible threat actor—malware, insider misuse, external attacker, or vendor misuse—and rate likelihood and impact. Use evidence such as scan results, audit logs, and incident history to support your scoring.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Risk register examples

  • Unencrypted DICOM exports to removable media: high impact, medium likelihood; control with encryption and media custody logs.
  • Open DICOM listener accessible beyond clinical subnet: medium impact, medium likelihood; control with network segmentation and allowlists.
  • Shared user accounts on planning software: medium impact, high likelihood; control with unique IDs, MFA, and automatic logoff.
  • Outdated workstation OS: high impact, variable likelihood; control with patch management windows and application compatibility testing.

Implementing Administrative Safeguards

Policies, procedures, and oversight

Create clear policies for access provisioning, DICOM configuration changes, export approvals, removable media use, incident response, and secure disposal. Maintain business associate agreements where vendors store or process ePHI. Establish change control for software upgrades and DICOM node alterations, with pre‑deployment testing and rollback plans.

Training and workforce management

Train users on identifying ePHI, verifying recipients before export, recognizing phishing attempts, and reporting anomalies. Reinforce sanction policies for policy violations and reward positive behaviors. Provide just‑in‑time reminders within workflows, like export checklists and on‑screen prompts.

Contingency planning

Implement backup and disaster recovery for configurations, planning data, and metadata. Define downtime procedures to sustain care if the workstation is unavailable, and test recovery with table‑top exercises. Store recovery documentation where staff can access it during an outage.

Applying Technical and Physical Safeguards

Technical controls

Enforce ePHI access controls with unique user IDs, role‑based permissions, and, where feasible, multi‑factor authentication. Enable automatic logoff and screen locking. Encrypt data at rest with full‑disk encryption and in transit using TLS or secure tunneling for DICOM data transfer and remote support. Restrict DICOM peers to an allowlist and monitor associations.

System hardening and monitoring

Harden the workstation: remove unused services, apply timely patches, and limit local admin rights. Use endpoint protection and application allowlisting to reduce malware risk. Centralize audit logs for logins, exports, and configuration changes, and alert on anomalies such as bulk exports or after‑hours activity.

Media and peripheral controls

Disable or control USB ports and optical drives by policy and tooling. If media use is permitted, mandate encryption, custody tracking, and secure return or destruction. Implement secure wipe for retired drives and ensure service vendors follow documented media handling procedures.

Physical safeguards

Place the workstation in a controlled area with badge‑restricted access. Use privacy filters and automatic screen locks to prevent shoulder‑surfing. Secure cabling and storage, maintain visitor logs, and protect equipment from environmental hazards with appropriate controls and maintenance records.

Continuous Monitoring and Documentation

Operational monitoring and auditing

Define key indicators: number of exports, failed authentication attempts, new DICOM peer requests, and cache size trends. Review logs regularly, sample exported studies for correctness, and reconcile export authorizations with audit trails. Document findings and remediation actions.

Ongoing assessments and patching

Schedule recurring vulnerability assessments and configuration reviews. Track vendor bulletins and plan maintenance windows that respect clinical schedules. Re‑validate security after major software updates or workflow changes, and update the risk register accordingly.

Incident response and reporting

Build a playbook for containment, forensic preservation, notification, and post‑incident review. Pre‑assign roles, practice communications, and define decision points for system isolation versus clinical continuity. Capture lessons learned to refine policies and controls.

Documentation and accountability

Maintain a complete record set: risk assessment report, data flow diagrams, asset inventory, policies, training logs, BAAs, change records, and test evidence. Use your security risk assessment (SRA) tool outputs to show progress over time and to drive leadership decisions on budget and priorities.

Summary

By mapping data flows, rating risks, and applying targeted safeguards, you reduce the chance and impact of ePHI exposure while sustaining clinical efficiency. Keep evidence current, monitor continuously, and iterate your controls as workflows, systems, and threats evolve.

FAQs

What are the key risks to ePHI in radiation oncology workstations?

Top risks include misconfigured DICOM endpoints that send data to unintended recipients, unencrypted exports to removable media, shared or weak credentials, outdated software susceptible to malware, and residual ePHI in caches or temp folders. Physical exposure from unattended sessions and improper media disposal also elevates risk.

How does the HIPAA Security Rule apply to CT simulation data?

The HIPAA Security Rule requires administrative, technical, and physical safeguards proportionate to your risks. Because CT simulation datasets contain ePHI in DICOM headers and related files, you must control access, ensure integrity and availability, protect data in transit and at rest, maintain audit trails, and document policies, training, and contingency plans.

What tools can assist in conducting a HIPAA risk assessment?

A security risk assessment (SRA) tool can guide evidence collection, scoring, and reporting. Complement it with vulnerability assessment scanners, configuration baselines, log aggregation, and data flow diagramming utilities. Tools support the process, but your environment‑specific analysis and decisions determine effectiveness.

How often should a HIPAA risk assessment be updated?

Update at least annually and whenever significant changes occur—new DICOM peers, software upgrades, workflow shifts, or vendor engagements. Conduct interim reviews after incidents, audit findings, or major patches to confirm that risk levels and controls remain accurate and effective.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles