Seoul St. Mary's secures Korea's first PACS ISMS certification
Certification is valid from 1 July 2026, to 30 June 2029.
Seoul St. Mary's Hospital has become the first medical institution in South Korea to obtain Information Security Management System (ISMS) certification covering its Picture Archiving and Communication System (PACS).
The certification is valid from 1 July 2026, to 30 June 2029. The hospital said it strengthens enterprise-wide information security and prepares the institution for future digital healthcare regulations.
The certification process was led by the hospital's Information Security Team and Radiology Team, with support from security consulting firm Happy Soft and PACS provider Taeyoung Soft.
The review covered risk assessments, vulnerability testing, access controls, encryption, account management and security log management.
PACS manages medical imaging data from devices such as CT and MRI scanners and exchanges information with the hospital's electronic medical records (EMR) system.
The hospital said the platform requires connections with external organisations for medical information exchange, consultations and equipment maintenance, making it a key cybersecurity risk.
Following the certification, Seoul St. Mary's Hospital plans to strengthen its supply chain security, pursue ISO certification and expand its multi-network separation system to isolate administrative, internet, research and medical device networks.
The hospital said these measures will help secure AI- and cloud-based medical devices as their use increases.
Seoul St. Mary's Hospital also noted that it ranked first in South Korea's 2025 Medical Information Security Challenge, organised by the Ministry of Health and Welfare and related agencies.