Unencrypted SD Cards: Risk Evaluation for Traveling Echocardiography Techs

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Unencrypted SD Cards: Risk Evaluation for Traveling Echocardiography Techs

Kevin Henry

Risk Management

July 06, 2026

7 minutes read
Share this article
Unencrypted SD Cards: Risk Evaluation for Traveling Echocardiography Techs

Risks of Unencrypted SD Cards in Medical Imaging

When echocardiography studies are saved to unencrypted SD cards, anyone who finds or accesses the card can read its contents without a password. DICOM files often include patient identifiers in headers and, at times, burned-in text, creating immediate patient data privacy exposure.

Unencrypted SD cards increase the likelihood of unauthorized access, HIPAA violations, and data breaches. They also undermine medical imaging security by removing auditability—there is no way to prove who viewed, copied, or altered the data.

  • Confidentiality: PHI can be viewed or copied by unauthorized parties if a card is lost, stolen, or mishandled.
  • Integrity: Files can be tampered with or replaced, jeopardizing clinical decisions and legal defensibility.
  • Availability: Cards are prone to corruption, wear, and physical damage, risking data loss at critical moments.
  • Accountability: No access logs or user attribution exist for plain, removable media.

Vulnerabilities in Medical Imaging Devices

Many ultrasound and point-of-care imaging systems default to exporting exams in the clear to removable media. That design choice, combined with permissive file systems and legacy protocols, creates medical device vulnerabilities that follow you into the field.

  • Unencrypted exports: SD card writes occur without encryption, leaving PHI exposed at rest.
  • Legacy protocols: Devices may transmit or share images without modern transport protections unless explicitly configured.
  • Weak authentication: Default or shared credentials on export workflows can enable unauthorized access.
  • Outdated firmware: Missed patches open paths for exploitation and malware that can propagate via removable media.
  • Metadata leakage: DICOM headers store names, MRNs, and dates; “de-identified” exports can still leak data if burned-in text remains.
  • Illusory write-protect: SD card lock switches are host-enforced; they do not guarantee true read-only protection.

Exposed Medical Images Online

Imaging breaches are often traced to misconfigured systems rather than sophisticated attacks. Open or poorly secured PACS endpoints, cloud storage buckets, and ad-hoc file-sharing services can inadvertently expose studies to the public internet.

Traveling techs face extra risk because data frequently moves between organizations. Copying from an unencrypted SD card to a personal device synchronized to consumer cloud storage can unintentionally publish PHI. Internet-wide scanners and search engines can index misconfigurations quickly.

  • Common exposure paths: open remote access, public cloud buckets, unsecured file links, and unsanctioned sync tools.
  • Risk multiplier: repeated copies and unmanaged endpoints increase the attack surface and discovery likelihood.

Breaches Due to Unsecured Medical Images

Unsecured images can trigger reportable data breaches with costly remediation, reputational damage, and contractual fallout. For covered entities and their business associates, such incidents can lead to investigations and penalties for HIPAA violations.

  • Operational impact: incident response, imaging rescheduling, and rework to restore data integrity.
  • Regulatory exposure: required breach assessments and notifications if patient data privacy is compromised.
  • Patient harm: identity fraud, embarrassment, and loss of trust when sensitive cardiology data is exposed.

If you suspect a breach, stop using the media, report immediately to your privacy/security team, document chain of custody, and support containment (e.g., revoke access, quarantine devices, and preserve forensic artifacts).

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Risks of Physical Media in Data Transfer

Physical media are convenient but fragile. SD cards are small, easily misplaced, and susceptible to environmental damage. They also bypass many enterprise physical media security controls, especially during travel.

  • Loss and theft: cards slip from pockets, fall behind equipment, or disappear in transit bags.
  • Damage and corruption: ESD, moisture, or wear-leveling failures can render exams unreadable.
  • Malware pivoting: infected kiosks or unmanaged laptops can contaminate clinical endpoints.
  • Duplication risk: silent copying enables covert exfiltration and uncontrolled redistribution.
  • Residual data: deleted files may persist due to flash wear-leveling, complicating secure reuse.

Best Practices for Securing SD Cards

The safest approach is to avoid unencrypted removable media and use secured network transfers whenever possible. When SD cards are unavoidable, apply layered controls that combine encryption, handling discipline, and endpoint hardening.

  • Prefer secure transfer: upload directly to PACS/VNA via VPN or TLS-enabled workflows rather than exporting to removable media.
  • Encrypt at rest: use OS-native full-volume encryption for removable media (e.g., BitLocker To Go, encrypted APFS volumes, or LUKS). Choose hardware that supports strong cryptography and, when required, FIPS-validated implementations.
  • Strong passphrases and key handling: use unique, high-entropy passphrases; store them in approved enterprise password managers; never place keys on the same card as the data.
  • Data minimization: store only what is necessary for care coordination; avoid keeping secondary copies after confirmed ingestion into the destination system.
  • De-identification when feasible: use device or workstation tools to strip identifiers and verify that no burned-in PHI remains before sharing for non-treatment purposes.
  • Chain of custody: label media with unique IDs, log check-out/check-in, seal in tamper-evident pouches, and carry on your person rather than in checked luggage or unattended vehicles.
  • Read-only handling: enable the card’s lock switch during transport to reduce accidental writes; verify endpoints block autorun and scan removable media on insertion.
  • Sanitization and end-of-life: prefer crypto-erase (destroy encryption keys) for encrypted cards; if not encrypted from the start, use validated wipe tools and consider physical destruction when reuse is uncertain.
  • Endpoint hygiene: access SD content only on managed, patched systems with EDR, least-privilege accounts, and restricted cloud sync.

Compliance with HIPAA Regulations

HIPAA expects risk-based safeguards that protect confidentiality, integrity, and availability of ePHI. For traveling techs, that translates into disciplined workflows, approved tools, and documented controls aligned to your organization’s policies.

  • Administrative safeguards: complete risk assessments for removable media use, define acceptable-use policies, and ensure workforce training and sanctions for non-compliance.
  • Physical safeguards: maintain media control logs, secure storage during transit, and apply disposal/sanitization procedures before reuse.
  • Technical safeguards: encrypt ePHI at rest and in transit, enforce access controls, maintain audit trails, and deploy integrity and transmission protections.
  • Breach response: follow formal incident procedures and breach notification requirements if ePHI is compromised; properly encrypted data may qualify for safe-harbor treatment.
  • Third-party alignment: ensure business associate agreements are in place and that vendors handling imaging data meet equivalent medical imaging security standards.

In summary, unencrypted SD cards expose you and your patients to unnecessary risk. Replace ad-hoc media transfers with encrypted storage, strong physical media security controls, and policy-driven workflows to reduce the likelihood and impact of data breaches and HIPAA violations.

FAQs

What are the risks of using unencrypted SD cards in medical imaging?

They enable unauthorized access to DICOM studies and embedded identifiers if a card is lost, stolen, or mishandled. You also lose auditability, invite data tampering or corruption, and increase the chance of costly data breaches and HIPAA violations.

How can traveling echocardiography techs secure patient data on SD cards?

Use encrypted media by default, protected with strong passphrases managed through approved tools. Limit storage to the minimum necessary, transport cards in tamper-evident containers, maintain custody logs, and ingest to secured systems over VPN or TLS. Sanitize or crypto-erase media after confirmed upload.

What compliance standards apply to medical imaging data security?

HIPAA’s Security, Privacy, and Breach Notification Rules apply to ePHI in imaging. Implement administrative, physical, and technical safeguards, including encryption, access controls, audit logging, secure disposal, and documented incident response. Business associates must meet comparable protections.

Common issues include unencrypted exports to SD cards, legacy protocols without modern transport security, weak or shared credentials, outdated firmware, and PHI leakage via DICOM metadata or burned-in text. Write-protect switches are advisory only and should not be treated as a security control.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles