Skip to content

Radiology imaging platform operations

The part of the job that starts the day the contract is signed: bringing a modality online, decoding the error a technologist just read to you over the phone, running the exception desk, working through an archive outage, defining a service level that can actually be measured, and modelling what five years of studies really costs.

Companion sheet Ops & economics axis DICOM edition PS3 2026c Prices: us-east-1, Sep 2026

Read this with the architecture atlas This sheet deliberately does not re-explain DICOM parts, DIMSE versus DICOMweb, transfer syntaxes, IHE profile maturity, PACS versus VNA, viewer tiers, de-identification profiles, or the build-versus-buy scorecard. Those live in The Radiology Imaging Software Stack, which answers what the system is made of. This one answers who runs it, what breaks, what you are on the hook for, and what it costs. Where a topic appears in both, the atlas has the structural version and this sheet has the operational one.

00 The card you keep open

Eight things an on-call engineer or an imaging operations lead looks up under pressure. Everything here is verified against the primary source named on the tile.

Registered ports 104 / 11112 / 2762

IANA registers acr-nema on 104, dicom on 11112, dicom-tls on 2762 and dicom-iscl on 2761. If a firewall ticket names only 104, it will not cover a modern deployment.

Association rejected 1 / 1 / 7

Result 1 (permanent), Source 1 (service-user), Reason 7 = called AE title not recognized. Reason 3 = calling AE title not recognized. Those two account for most day-one failures. Standard PS3.8 9.3.4

C-STORE failed A7xx / A9xx / Cxxx

A7xx = refused, out of resources (their disk or queue). A9xx = data set does not match SOP class (your object). Cxxx = cannot understand (parse failure). Standard PS3.4 Table B.2-1

C-STORE succeeded with B000 coercion

The receiver rewrote your attributes, usually demographics pulled from its own worklist. A success you should treat as an event: silent coercion is how a wrong patient identity becomes permanent.

C-MOVE failed A801 / A702

A801 = move destination unknown: the archive has no entry for your destination AE. A702 = unable to perform sub-operations, which usually means the archive cannot open a connection back to your destination. Standard PS3.4 C.4.2

Worklist required matching keys AE + date + modality

Scheduled Station AE Title (0040,0001) is single-value matching only; Scheduled Procedure Step Start Date/Time (0040,0002)/(0040,0003) accept ranges; Modality (0008,0060), Patient's Name and Patient ID are also required matching keys. An empty worklist is nearly always one of these. Standard PS3.4 Table K.6-1

Clock skew budget < 1 s median

The IHE Consistent Time profile specifies synchronisation to a median error under one second, over NTP. Audit correlation, TAT clocks, and "which correction happened first" all depend on it. IHE ITI

Retention floors, US 5 yr / 5–10 yr

Hospital medical records: at least 5 years (42 CFR 482.24(b)(1)). Mammography: the longest of 5 years, 10 years if no further mammograms are performed at the facility, or the state period (21 CFR 900.12(c)(4)). State law and payer contracts routinely exceed both. Regulatory

Scope, stated once This is a systems-operations reference for people running imaging infrastructure. It is not clinical guidance, not legal advice, and not a compliance programme. Regulatory citations name the rule and its jurisdiction so you can check it; they do not tell you whether it applies to your organisation. Verify against the primary sources in section 13 before acting.

01 The modality floor

Every operational surprise downstream starts at a device someone else owns, configured by someone who has left, and used at 02:00 by a technologist who will not read your release notes. The atlas treats acquisition as one stratum. Here it is a per-device operating profile: what the thing emits, what drives its object count, and the specific way it fails you.

Operating profiles by modality

Instance count, not gigabytes, is the operational variable. Per-object charges, index writes, queue depth, transfer duration, viewer load time, and migration wall-clock all scale with the number of objects. Sizes vary too much to state as facts; the atlas has the short list of figures that are actually citable, and the honest advice is to measure your own archive.

Table 1.1 — Per-modality operating profile. SOP Class names are from PS3.4 Annex B / PS3.3 Standard; failure modes are recurring field patterns Common practice
ModalityTypically emitsWhat drives object countThe failure it causes most often
CR / DXComputed Radiography Image Storage; Digital X-Ray Image Storage — For Presentation and For Processing are separate SOP Classes.Number of projections; typically single digits per study.The device sends both For Presentation and For Processing. The archive doubles, hanging protocols pick the unprocessed object, and nobody notices for a quarter. Decide per device which one you accept, and enforce it at ingestion.
CTCT Image Storage; Enhanced CT Image Storage (multi-frame).Coverage ÷ slice thickness, multiplied by every reconstruction kernel, window, and derived series the protocol produces.Reconstructions arrive minutes apart on separate associations. The study looks complete, gets assigned, and a fourth series lands after the read starts. You need an explicit completeness rule (see below), not a guess.
MRMR Image Storage; Enhanced MR Image Storage; derived maps as separate series.Sequence count; derived series (ADC, subtraction, MIP) added by the console or a post-processing station.Free-text Series Description differs per scanner and per protocol revision, so hanging protocols silently stop matching after a scanner software upgrade. Treat protocol names as a versioned configuration item.
USUltrasound Image Storage; Ultrasound Multi-frame Image Storage.Number of stills plus cine loops; a loop is one large multi-frame object, not many small ones.Lossy compression is applied on the device before you ever see the object, so your "we only store lossless" policy was already violated upstream. Cine playback also depends on frame-time attributes the device may omit.
MGDigital Mammography X-Ray Image Storage, For Presentation and For Processing.Views per breast; priors are fetched in pairs and compared, so retrieval load is at least double the read count.Missing or wrong laterality and view codes break the hanging protocol that the entire reading workflow depends on. Mammography retention rules are also longer than your default (21 CFR 900.12(c)(4)).
MG / DBTBreast Tomosynthesis Image Storage, usually alongside a synthesised 2D image.Reconstructed slice count per view, plus the projection set if the site retains it.The single largest object volume per study of any routine exam. It is the study type that first exposes an undersized ingest pipe, a slow viewer, or a per-object storage bill.
XA / RFX-Ray Angiographic Image Storage; X-Ray Radiofluoroscopic Image Storage; X-Ray Radiation Dose SR.Runs per procedure; each run is a multi-frame object.Dose reports are structured reports, not images. Pipelines built for pixels drop them, and the dose registry submission you promised quietly stops.
NM / PTNuclear Medicine Image Storage; Positron Emission Tomography Image Storage.Detector, phase, and gate dimensions; PET studies pair with a CT series for attenuation correction.Quantitative display (SUV) depends on decay, dose, and timing attributes. Lose or re-derive them in a transcode and the numbers on screen are wrong while the images look fine.
IO / dentalIntra-Oral X-Ray Image Storage; panoramic units often emit DX.Per-tooth or per-quadrant exposures; high study count, low bytes.Sensor software written for a single-practice server writes non-conformant or missing identifiers, and tooth numbering has no DICOM home, so it arrives in a free-text field you must parse.
CBCTUsually CT Image Storage, whatever the marketing name of the device.Field of view and voxel size.Modality and body-part attributes do not describe what the device is, so routing rules, worklists, and reporting templates keyed on Modality send it to the wrong queue.
SCSecondary Capture Image Storage; Encapsulated PDF; Encapsulated CDA.Ad hoc: screenshots, scanned paper, exported reports.Burned-in demographics in the pixel data. Every de-identification and sharing workflow has to treat these as a separate class of object, and Burned In Annotation (0028,0301) is frequently absent or wrong.
SR / KO / PRBasic Text, Enhanced, and Comprehensive SR; Key Object Selection Document; Grayscale Softcopy Presentation State.One per report, selection, or saved annotation.These are the objects that carry measurements, key images, and annotations. If a migration or export path only moves image SOP Classes, the clinical work product is what you leave behind.
SMVL Whole Slide Microscopy Image Storage.Tiles per level across a pyramid; orders of magnitude beyond radiology per slide.Digital pathology shares the standard and almost none of the operating assumptions. Do not fold it into a radiology archive plan without sizing it separately.
Recommendation — define "study complete" as a written rule per modality Three mechanisms exist and each fails differently. MPPS COMPLETED is the intended signal and the only one grounded in the standard, but plenty of devices never send it. Instance count from the order works where the RIS knows the expected series, which it usually does not for CT and MR. A quiet timer (no new object for n minutes) is the common fallback and is a guess with a clinical consequence: too short and studies are read incomplete, too long and turnaround-time clocks start late. Pick one per modality, write down the value, and make premature-completion an alarmed event rather than a discovery.

Discontinued procedure steps, decoded

When a modality abandons a procedure step it can say why, using a coded reason from CID 9301. Most platforms store the code and never act on it. Each one implies a different queue, and several are identity-safety events rather than scheduling noise.

Table 1.2 — CID 9301 Modality PPS Discontinuation Reason, complete, with the operational consequence Standard PS3.16 Consequence column: recommendation
CodeMeaningWhat operations must do with it
110500Doctor canceled procedureClose the order, stop the turnaround clock, and suppress the "study never arrived" alert. Billing and the ordering system both need the cancellation.
110501Equipment failureDevice health event, not a workflow event. Repeated codes from one AE title are your earliest signal of a failing detector or console before the site opens a ticket.
110502Incorrect procedure orderedRoute to the order-correction queue. A new order is required; do not let the technologist "fix" it by selecting a different worklist entry mid-exam.
110503Patient allergic to media/contrastClinical event with a safety record attached. Your platform's job is to preserve it, surface it on any repeat order, and not silently drop it during reconciliation.
110504Patient diedStop all automated communication for that patient immediately: portal notifications, reminder messages, and result callbacks. This is the code that makes an unfiltered notification engine indefensible.
110505Patient refused to continue procedurePartial study exists and may still be interpretable. It must reach a radiologist flagged as partial, never as a completed exam.
110506Patient taken for treatment or surgeryExpect a resumption or a repeat later the same day. Duplicate-detection needs to tolerate two partial studies for one order.
110507Patient did not arriveHighest-volume code in most estates. Auto-close the worklist entry after a defined window, or the worklist fills with ghosts and technologists start scrolling past real entries.
110508Patient pregnantSafety hold. Requires an order review, not a reschedule.
110509Change of procedure for correct chargingFinancial reconciliation, not clinical. The images may be perfectly valid under a different procedure code.
110510Duplicate orderFeed it back to the ordering system. Repeated duplicates from one site is an integration defect, not user error.
110511Nursing unit cancelSame handling as 110500, different source. Track separately: the split tells you where scheduling breaks down.
110512Incorrect side orderedWrong-side is a never-event category in surgery and a serious defect here. Alarm it; do not let it be silently corrected at the console.
110513Discontinued for unspecified reasonThe default a device sends when its UI offers no list. A rising share of 110513 means your reason codes are decorative and the data is not usable for anything.
110514Incorrect worklist entry selectedThe identity event. Images were acquired under another patient's demographics. This must trigger the wrong-patient correction path (rejection, correction, downstream propagation) and be counted as a safety metric, not a support ticket.
110515Patient condition prevented continuingPartial study, clinically urgent context. It usually should be read faster than a normal exam, not slower.
110516Equipment changeThe same procedure will resume on a different AE title. Your completeness rule and duplicate detection must survive a study arriving from two devices.
95384003Injection site extravasation (SNOMED CT)Adverse event. Preserve the association with the study and the contrast record.
292094009Radiopharmaceutical adverse reaction (SNOMED CT)Adverse event with reporting obligations that vary by jurisdiction. Do not let it exist only as a discarded procedure step.
Anti-pattern — storing discontinuation reasons and routing none of them A platform that persists CID 9301 codes but treats every discontinued step identically has all the evidence of a wrong-patient acquisition, a failing detector, and a deceased patient still receiving portal reminders, and acts on none of it. The codes are cheap to capture and worthless until something branches on them.

02 Commissioning a site or a modality

Onboarding is the operation you will perform most often and the one most likely to be improvised. Everything here is a form or a sequence, because the failure mode of onboarding is not difficulty, it is that step 9 was skipped and nobody can prove it.

The site survey, collected before anything is configured

Every field below has cost someone a go-live. Collect them in writing, from the site, before a firewall ticket is raised.

Network and access

  • Public egress IP and whether it is static. Dynamic IPs make source allowlisting a recurring outage.
  • Outbound port policy, and who approves changes. Naming 104 only is a classic day-one block.
  • Whether the clinic network sits behind carrier-grade NAT or a shared practice-group firewall.
  • Whether inbound connections are possible at all — this decides push versus pull architecture for the whole site.
  • Available upstream bandwidth at the time of day the site actually scans, not the advertised rate.
  • Who is on site with physical access to the gateway, and their hours.

Devices and identity

  • Per device: manufacturer, model, software version, AE title, IP, listening port, and the conformance statement.
  • AE titles in use elsewhere in the estate — collisions are common and produce baffling misrouting.
  • Which system is the source of truth for patient or owner identity at this site.
  • Whether the site has a RIS or PIMS that can supply a worklist, or whether identity is typed at the console.
  • Existing archive, if any, and whether historical studies are in scope for migration.
  • Time source of every device, and whether the site has a working NTP path.

Workflow and people

  • Who submits studies, who interprets, who receives the report, and who fixes an identity error.
  • Operating hours, after-hours volume, and what the site expects to happen at 03:00.
  • Report delivery destinations: EHR or PIMS interface, portal, email, fax, printer.
  • Named site contact for exceptions, and their escalation backup.
  • Training status of each technologist on worklist selection, which is the single highest-leverage control against wrong-patient studies.

Obligations you are inheriting

  • Retention period the site is contractually or legally bound to, and who told you.
  • Whether mammography is in scope, which changes retention and hanging requirements.
  • Jurisdiction of the site and of your storage, which is not always the same country.
  • Any existing business associate agreement, data processing agreement, or equivalent.
  • What the site was promised by sales that is not in the statement of work.

The bring-up sequence

Fourteen steps, in order, each with a pass criterion you can point at. Tick boxes persist in this browser only.

Commissioning run sheet 0 of 14 complete
  1. Assign the AE title, IP, and port on both sides and record them in the configuration system of record. AE Title is a 16-byte identifier, not a credential — treat allowlisting as a routing convenience, never as authentication.
    Pass: both sides configured from the same written record, no AE title reused anywhere in the estate.
  2. Firewall rules in both directions if you use C-MOVE, outbound only if you use push plus DICOMweb. Confirm with a raw TCP connection before involving DICOM at all.
    Pass: TCP connect succeeds from the device subnet, not from the engineer's laptop on a different VLAN.
  3. In both directions if both directions will be used. An echo that works one way proves nothing about the other.
    Pass: echo succeeds from the device and from the archive, logged with timestamps on both.
  4. Point the device and the gateway at a working NTP source. The IHE Consistent Time profile specifies a median error under one second.
    Pass: device clock within one second of the archive's, verified after a reboot, not just after configuration.
  5. Run a modality worklist C-FIND with the exact keys the device will send: Scheduled Station AE Title, start date, modality. Compare against what the device actually queries, captured from the wire, not from its manual.
    Pass: a scheduled test order appears on the device screen, selected by the technologist, not typed.
  6. A real acquisition, not a synthetic file, from the console the technologist will use. Synthetic objects hide exactly the encodings that break.
    Pass: C-STORE status 0000 for every instance, and the instance count on the archive equals the count on the device.
  7. Compare the stored object's identity attributes against what left the device. Status B000 means the receiver rewrote them.
    Pass: either no coercion, or coercion is intended, documented, and logged as an event you can query later.
  8. If the device supports the Storage Commitment Push Model (N-ACTION out, N-EVENT-REPORT back), exercise it. The reverse association is a separate firewall path and fails independently of the store.
    Pass: commitment returns success, and a deliberately unsupported object returns a documented failure reason rather than silence.
  9. Start a step, complete one, and discontinue one with a reason code. Confirm your platform branches on the reason (Table 1.2), rather than storing it.
    Pass: IN PROGRESS, COMPLETED, and DISCONTINUED all land, and the discontinued one appears in the queue you expect.
  10. If you transcode or compress on ingest, verify the stored object against the original: pixel data, photometric interpretation, and the attributes that record what was done to it.
    Pass: a documented comparison, per SOP Class this device emits, not per file format in general.
  11. Diagnostic, clinical review, and customer-facing. Each has a different decoder and a different tolerance for missing attributes.
    Pass: correct window level, correct orientation and laterality, correct series ordering, cine plays at the right rate.
  12. Retrieve an older study for the same patient, from the tier it will actually live in. A prior retrieved from hot storage during testing proves nothing about the archive tier.
    Pass: prior loads within the target the reading workflow assumes, measured from cold, with the retrieval charge recorded.
  13. Pull the upstream connection mid-study. The gateway must buffer, resume, and not duplicate. This is the test that most often fails and the one most often skipped.
    Pass: after reconnection the archive holds exactly one complete copy, and the buffer's capacity in hours is a number you know.
  14. Interpret the test study, sign the report, and confirm delivery to every configured destination, including the fax or printer nobody remembers.
    Pass: the site contact confirms receipt in their own system, in writing, before go-live is declared.
Anti-pattern — go-live on a synthetic test object A hand-built or downloaded sample study exercises your parser and nothing else. It does not carry the device's real transfer syntax, private attributes, series naming, burned-in text, or the number of instances that will expose your queue. Commission on a real acquisition from the console that will be used in production, or expect to commission twice.

03 The triage board

The signature tool on this page. Type a status code, a reject reason, or a symptom in plain words. Everything is filtered live, so A801, worklist, and black all land somewhere useful.

Dispatch — symptom, probe, cause, fix
SignalSymptomProbe firstMost likely cause and fix
1 / 1 / 7Association rejected immediately; nothing is transferred.Read the reject PDU: result, source, reason.Called AE title not recognized. The AE title you are calling is not configured on the receiver, or differs by case, a trailing space, or a character beyond 16 bytes. Compare the two configurations character by character rather than reading them aloud.
1 / 1 / 3Association rejected; the receiver logs an unknown peer.Same PDU, reason field.Calling AE title not recognized. The receiver allowlists source AE titles and yours is missing, usually because the device was replaced and the new console shipped with a different default.
1 / 1 / 2Rejected before any negotiation.Reject PDU reason 2 with source 1.Application context name not supported. Rare, and almost always a non-DICOM service answering on the port. Confirm you are talking to what you think you are.
2 / 3 / 1Intermittent rejections under load; retries succeed.Reject PDU with result 2 (transient), source 3.Temporary congestion. The receiver is at its concurrent-association limit. Fix the sender's parallelism and backoff before raising the receiver's limit, or you move the failure into its queue.
2 / 3 / 2Same, but persistent at a fixed concurrency.Reject reason 2, source 3.Local limit exceeded. A configured association cap. Raise it deliberately with the memory cost calculated, or serialise the sender.
Echo OK, store failsC-ECHO succeeds, C-STORE fails at once with no status.Look for a rejected presentation context in the association-accept.The receiver did not accept the SOP Class or the transfer syntax the device offered. Read section N.5 of the receiver's conformance statement and compare against what the device sends. Echo negotiates only the Verification SOP Class, so it proves connectivity and nothing about content.
A7xxStores fail across all devices at once.C-STORE status begins A7.Refused: out of resources. The receiver, not you: disk, quota, queue depth, or a stuck consumer. Check the archive's own alarms before touching a modality.
A9xx / B007One device or one exam type fails; others are fine.C-STORE status A9 or warning B007.Data set does not match SOP Class. The object's contents disagree with the SOP Class UID it claims. Capture the failing object and diff it against a working one from the same device before escalating to the vendor.
CxxxA subset of instances fails, reproducibly.C-STORE status begins C.Cannot understand. Parse failure at the receiver. Keep the raw object: this is the one class of failure where the artefact is the entire ticket, and it is routinely deleted by a retry loop.
B000Everything "succeeds", but stored demographics differ from the console.C-STORE warning B000 in the response.Coercion of data elements. The receiver rewrote attributes, typically identity, from its own worklist. Decide whether coercion is policy. If it is, log every coerced attribute; if it is not, turn it off. Undocumented coercion turns a mis-selected worklist entry into a permanent record.
B006Objects store but something is missing later.C-STORE warning B006.Elements discarded. The receiver dropped attributes it did not want, often private ones carrying measurements or reconstruction parameters. Ask which, in writing, and check whether your AI or quantitative workflow needed them.
A801C-MOVE fails instantly.C-MOVE status A801.Move destination unknown. The archive has no configuration entry for your destination AE title. C-MOVE requires the SCP to know the destination in advance; this is the structural reason many platforms move to C-GET or DICOMweb retrieval.
A702C-MOVE accepts, then fails part-way.C-MOVE status A702, plus the sub-operation counters.Unable to perform sub-operations. Usually the archive cannot open a connection back to the destination: a firewall that permits outbound only, or a destination that is not listening. Check the direction of the second connection, not the first.
B000 on C-MOVERetrieval "succeeded" with fewer images than expected.Warning B000 with failed sub-operation count above zero.Sub-operations complete, one or more failures. A partial retrieval reported as a warning. If your code treats anything that is not a failure as success, you have silently delivered incomplete studies to a reading workstation.
A701Query fails before any match is returned.C-MOVE or C-FIND status A701.Out of resources, unable to calculate number of matches. The query is too broad for the archive to plan. Constrain by date range and level rather than retrying.
Empty worklistThe device shows no scheduled procedures, but orders exist.Capture the device's actual C-FIND request from the wire.A required matching key does not match: Scheduled Station AE Title (single-value matching only), the start date range format, or the Modality code. Devices often send an AE title that differs from their calling AE title, and the fix is in the order feed, not the network.
Wrong patientA study is filed under another patient's name.Look for MPPS reason 110514 and for a coercion warning at ingest.An incorrect worklist entry was selected at the console. This is an identity-safety event: reject the objects through the change-management path, correct, propagate to everything that already received them, and count it. It is never a support-desk edit.
Never completesStudy sits at "in progress" forever; the reading queue never receives it.Compare arrival timestamps of the last series against your completeness rule.No MPPS COMPLETED arrived and the quiet timer never expired because a trickle of objects kept resetting it, or a reconstruction landed after the window closed. Completeness must be a stated rule per modality, with premature and stalled completion both alarmed.
Transfer stallsTransfers stop mid-study and never resume.Check the association timeout and the sender's queue depth.The association hit an inactivity timeout, or the device's outbound queue was purged on reboot. Devices are not durable queues. If your architecture assumes the modality will retry, verify that assumption per device before you depend on it.
TLS handshakeConnection resets during handshake on the secure port.openssl s_client -connect host:2762Certificate chain, trusted CA, hostname mismatch, or an expired certificate. On appliances, a wrong clock also breaks validity checks — which is one more reason step 4 of commissioning is not optional.
Black imagesObjects arrive and index correctly; the viewer shows black or inverted.Inspect transfer syntax, Photometric Interpretation, and the window attributes.The viewer cannot decode that transfer syntax, or window centre and width are absent and its default is wrong, or MONOCHROME1 is being rendered as MONOCHROME2. This is a rendering fault, not a transfer fault: the bytes are fine.
Priors missingCurrent study loads; the comparison does not.Check the patient identifier and issuer on both studies, then the storage tier.Either identity (the prior is under a different identifier or issuer and was never linked) or economics (the prior is in an archive tier whose retrieval latency exceeds the reader's patience). Both look identical to the radiologist and have completely different fixes.
Duplicate studiesTwo identical studies with the same Study Instance UID.Compare arrival paths and source AE titles.Two gateways or two routing rules sent the same objects. Idempotency at ingest must be keyed on SOP Instance UID; if it is keyed on filename or arrival order, duplicates are inevitable.
Split studiesOne acquisition appears as two studies for the same patient and time.Compare Study Instance UIDs and acquisition times.The device regenerated the Study Instance UID on resend, or two devices contributed to one procedure. This one requires a merge with an audit trail, not a delete-and-resend.
Audit disorderEvents appear out of order across systems; corrections seem to precede the errors.Compare timestamps across three nodes for one known transaction.Clock skew. The IHE Consistent Time target is a median error under one second. Without it, no incident reconstruction and no "which write won" question can be answered.
Commitment silenceStorage commitment requests are sent and nothing ever comes back.Check whether the SCP can open an association back to the SCU.The N-EVENT-REPORT arrives on a separate association from the SCP to the SCU, so it needs its own firewall path and a listener. Silence is not success: without the notification you have no evidence the archive accepted responsibility.
Commitment 0110 / 0112Commitment returns a failure list.Read the failure reason per instance.0110 processing failure, 0112 no such SOP instance, 0119 class/instance conflict, 0122 referenced SOP class not supported, 0131 duplicate transaction UID, 0213 resource limitation. 0112 in particular means the archive never received what you think you sent.
Preliminary foreverThe report is signed but the EHR still shows it as preliminary.Inspect OBR-25 and OBX-11 on the outbound message.The result status never advanced to F. HL7 v2 table 0123 defines P preliminary, F final, C corrected final, M corrected not final, X order cancelled; table 0085 adds A amended, C correction, W wrong patient, and U status change to final without retransmission. Sending an addendum with the original status is the most common variant of this bug.
Delivery blackholeReports leave your system and the site says they never arrived.Check the acknowledgement, not the send.An interface that logs "sent" without checking the application acknowledgement will lose messages silently for months. Every delivery channel needs a positive receipt and an unacknowledged-message queue with an age alarm.

The five commands worth memorising

DCMTK 3.6 syntax, verified against the tool documentation. These are diagnostics, not a production integration path.

# 1. Is anything listening, and does it accept my AE title?
echoscu -v -aet MY_AE -aec THEIR_AE 10.20.30.40 11112

# 2. What does the worklist actually return for the keys the device sends?
#    Sequence keys use the path syntax: (0040,0100)[0].Attribute
findscu -v -W -aet MY_AE -aec THEIR_AE 10.20.30.40 11112 \
  -k "(0040,0100)[0].Modality=CT" \
  -k "(0040,0100)[0].ScheduledStationAETitle=CT_SCANNER_1" \
  -k "(0040,0100)[0].ScheduledProcedureStepStartDate=20260905" \
  -k "PatientName=" -k "PatientID=" -k "AccessionNumber="

# 3. Send a real study and watch every status code come back
storescu -v --scan-directories --recurse -aet MY_AE -aec THEIR_AE \
  10.20.30.40 11112 /studies/case-0001/

# 4. Pull a study back to a named destination (A801 lives here)
movescu -v --study --move DEST_AE --port 11113 -aet MY_AE -aec THEIR_AE \
  10.20.30.40 11112 -k "QueryRetrieveLevel=STUDY" \
  -k "StudyInstanceUID=1.2.840.113619.2.55.3.12345"

# 5. Is the TLS problem the certificate, the chain, or the clock?
openssl s_client -connect 10.20.30.40:2762 -showcerts < /dev/null
Recommendation — what to capture before you escalate A vendor ticket without these is a week of round trips: the exact UTC timestamp and both AE titles; the association-accept showing which presentation contexts were accepted; the full status code with the related fields (0000,0901) and (0000,0902); the offending SOP Instance UID and, where you may retain it, the object itself; whether it reproduces on one device, one exam type, or everything; and the last configuration change on either side. Make that list the required fields of your escalation form, and the round trips stop.

04 The exception desk

Every imaging platform runs a human loop that nobody put in the architecture diagram. Its throughput determines how many studies reach a radiologist, and its authority limits determine whether a support agent can quietly destroy a clinical record. Design it deliberately or inherit it by accident.

The queues, and what each one is really measuring

Table 4.1 — Exception queues, entry conditions, and the age at which each becomes clinically material. Age targets are planning anchors to argue about, not standards. Product decision
QueueEnters whenResolved byAges badly because
Unmatched studyImages arrive with no corresponding order or worklist entry.Match to an order, or create an unscheduled case with a documented identity source.The study is invisible to the reading queue while it waits. This queue's age is undiagnosed patient time.
Orphan orderAn order exists and no images arrived within the expected window.Confirm cancellation (often MPPS 110507), or chase the site.Silence looks identical to a cancelled exam and a failed gateway. Without this queue, a site whose connectivity died on Friday is discovered on Monday.
Demographic mismatchStudy identity disagrees with the order's on name, identifier, date of birth, or accession.Reconcile against the declared source of truth, or reject and correct.Reading a study filed under the wrong identity is the highest-severity failure this platform can produce.
Duplicate / splitSame Study Instance UID twice, or one procedure under two UIDs.Deduplicate on SOP Instance UID; merge with an audit record.A split study means the radiologist sees half the exam and does not know it.
Incomplete studyCompleteness rule not satisfied within its window.Chase the missing series, or release as partial with an explicit flag.Silently releasing an incomplete study is worse than holding it, and holding it forever is worse than releasing a flagged partial.
Failed ingestNon-zero C-STORE status, transcode failure, or validation rejection.Fix and re-send, with the original object retained.Retry loops delete the evidence. Failed-ingest items must be immutable until a human closes them.
Stalled deliveryReport sent, no application acknowledgement received.Re-deliver, or fall back to a secondary channel.The report exists, the clinician does not have it, and every dashboard shows green.
Past turnaroundAn assigned study exceeds its target read time.Reassign, escalate, or renegotiate the target.This is the queue customers see. It is also the one most often gamed by redefining when the clock starts.
Correction propagationAn identity or content correction has been made and one or more downstream recipients have not been updated.Re-issue to every recipient, with confirmation.A corrected record upstream and an uncorrected copy downstream is a worse state than the original error, because now two systems disagree and both look authoritative.
Automated-analysis failureAn AI or post-processing job errored, timed out, or produced an unusable result.Re-run, or mark unavailable for that study.A quietly missing result reads as a negative finding to anyone who assumed the tool ran.

Authority limits: who may do what

The reason to write this down is not process hygiene. It is that "support can merge patients" and "support cannot merge patients" are two different products with different risk profiles, and most organisations have never decided which one they are.

Table 4.2 — A defensible default authority matrix. Adjust it, but decide it explicitly. Recommendation
ActionSupport tier 1Imaging operationsEngineeringRequires clinical sign-off
Read study metadata, view audit historyYesYesYesNo
Re-send a report to a configured destinationYesYesYesNo
Re-queue a failed ingest or deliveryYesYesYesNo
Correct a typographic demographic error on an unread studyNoYesYesNo
Reassign a study to another radiologistNoYesYesNo
Merge two patient recordsNoYes, dual controlNoYes
Move a study between patients (wrong-patient correction)NoYes, dual controlNoYes
Reject or retire imaging objectsNoYes, dual controlNoYes
Amend or retract a signed reportNoNoNoYes, radiologist only
Delete imaging objects permanentlyNoNoNoPolicy exception, named approver, recorded
Direct database editNoNoBreak-glass only, recorded and reviewedYes
Anti-pattern — the support tool with a delete button Support tooling built by copying the administrative interface gives a tier 1 agent, at 03:00, under customer pressure, the ability to perform an irreversible clinical-record change with no second pair of eyes. Support tooling should be able to see almost everything and change very little; every destructive capability belongs behind dual control and an audit record that names both people.
Recommendation — the operating rhythm Continuously: unmatched studies and demographic mismatches, because they block reads. Every shift: failed ingest, stalled delivery, past-turnaround, and the aged tail of every other queue. Daily: orphan orders per site, which is your connectivity canary; correction-propagation backlog; discontinuation-reason mix, watching for a rise in 110513 or any 110514 at all. Weekly: queue-age trend per site and per device, so you can name the two sites generating a third of the work. Monthly: the exceptions that recurred, converted into either a configuration change or a product change — a queue that never shrinks is a defect being staffed rather than fixed.

05 Degraded operations

Imaging degrades in pieces. The archive can be down while acquisition continues; reporting can be up while delivery is dead. A single "system down" runbook is useless because the correct human behaviour differs completely per component, and the expensive part is almost never the outage — it is the catch-up.

Regulatory context — the contingency plan standard For US HIPAA covered entities and business associates, 45 CFR §164.308(a)(7) requires a contingency plan with three required implementation specifications — a data backup plan ("create and maintain retrievable exact copies of electronic protected health information"), a disaster recovery plan ("restore any loss of data"), and an emergency mode operation plan ("enable continuation of critical business processes for protection of the security of electronic protected health information while operating in emergency mode") — plus two addressable ones: testing and revision procedures, and an applications and data criticality analysis. The table below is one way to produce the criticality analysis and the emergency mode procedures as an artefact rather than a paragraph.

Failure modes and the manual fallback

Table 5.1 — What still works, what the humans do instead, and what it costs you afterwards. Recommendation
What is downStill worksManual fallbackCatch-up work created
Upstream link at one siteAcquisition, local review on the modality, the gateway's buffer.Keep scanning. The gateway buffers and forwards on reconnection. Urgent cases go by a pre-agreed alternate route.A burst on reconnection that can exceed the ingest rate. Size the buffer in hours and rate-limit the drain, or the recovery causes the next incident.
Ingest pipelineAcquisition, existing archive reads, reporting on already-ingested studies.Modalities hold and retry — but only those that actually queue. Confirm per device rather than assuming.Reconciliation of anything that retried into a partially-processed state. Idempotency on SOP Instance UID is what makes this survivable.
Archive / repositoryAcquisition and buffering. Nothing downstream.Full downtime procedure: paper or local-worklist tracking, hand-carried media for urgent cases.Every study acquired during the window has to be ingested and reconciled, in order, with duplicates detected. This is the most expensive catch-up in the list.
Metadata index (objects intact)Objects are safe; nothing is findable.Treat as a full archive outage for users.Index rebuild time, which almost nobody has measured at production object counts. Measure it, then decide whether that number is acceptable, because it is your true recovery time.
Worklist / order feedEverything except scheduled acquisition.Technologists type identity at the console.Every typed study becomes an unscheduled case needing reconciliation, and typed identity is the leading cause of demographic mismatch. Expect the exception desk load to spike for days, not hours.
Diagnostic viewerIngest, archive, reporting engine.Fall back to the secondary viewer, if you have licensed and tested one. Most organisations discover here that they have not.Little data catch-up, large turnaround-time debt. This is the outage that most damages the customer relationship per minute.
Reporting / dictationEverything up to interpretation.Dictate to an offline recorder or type into a plain document, then transcribe in.Reports created outside the system must be reconciled to the correct study and re-issued through the normal delivery path with the correct status.
Report deliveryEverything. Reports are signed and correct, and nobody receives them.Phone and secondary channel for anything urgent; hold the rest in the retry queue.Bulk re-delivery, with duplicate suppression at the recipient, and correct result status so a re-send is not read as a new finding.
Identity source (EHR / PIMS)Imaging, in isolation.Local identifiers, quarantined for later reconciliation.The hardest catch-up of all: locally-created identities must be merged against the authoritative source afterwards, and merges are irreversible in practice.
Automated analysisEverything else.Read without it, explicitly.Almost none — provided the absence is visible. The danger is a workflow where "no finding shown" and "the tool did not run" look the same.

The downtime kit

  • A printed contact tree that does not depend on the systems that are down, including the site contacts.
  • The current site and device inventory, offline: AE titles, IPs, ports, owners.
  • A stated read-only mode, if the platform has one, and the exact conditions for entering and leaving it.
  • The urgent-case alternate route, agreed with each site in advance and tested, not invented during the incident.
  • A downtime log template: what was acquired, when, by whom, under which identity.
  • The catch-up order of operations, written down before it is needed.
  • Named authority to declare downtime and to declare it over. These are different decisions and both are frequently nobody's.

Catch-up, in order

  1. Stop new work into the affected path before draining, or you will chase a moving target.
  2. Ingest the backlog with rate limiting, oldest first, so turnaround clocks recover in the order patients waited.
  3. Deduplicate on SOP Instance UID before anything is assigned for reading.
  4. Reconcile identity for everything acquired without a worklist, against the authoritative source, before release.
  5. Release to the reading queue only after completeness is confirmed per study.
  6. Re-deliver reports, with correct status codes so a re-send is not mistaken for a new or corrected result.
  7. Reconcile the downtime log against the system: anything in the log with no matching study is the incident's real damage.
  8. Record the actual recovery time against the target, and correct the target if reality disagrees with it.
Anti-pattern — a recovery plan that has never been run at production scale Restore drills on a sample dataset validate the procedure and none of the durations. The numbers that matter are index rebuild time at your object count, bulk ingest rate during a drain, and per-object retrieval fees when the archive tier is involved. All three are measurable in an afternoon and all three are routinely first measured during the incident.

06 Service levels that survive contact with a customer

Most imaging service levels are written as a single availability percentage, which is the one number that can be simultaneously true and useless. The read path and the write path fail independently; a platform that accepts studies perfectly while nobody can open one is at 100% by that measure.

The indicator menu

Table 6.1 — Candidate SLIs. Measurement point is the part that matters: an indicator measured at the wrong boundary excludes exactly the failure the customer notices. Targets are starting anchors for negotiation. Product decision
IndicatorMeasured from → toAnchor targetWhy this boundary
Ingest acceptanceAssociation close at the gateway → object durably stored and indexed.p95 under 2 minMeasured from the archive's own receipt, it hides gateway queueing, which is where backlogs actually live.
Study availabilityLast instance received → study visible and openable in the worklist.p95 under 5 minThis is the customer's definition of "the study is here". Index lag lives entirely inside it.
Completeness detectionLast instance received → study marked complete.Stated per modalityNot a performance metric but a correctness one: publish the value per modality so nobody has to guess whether an exam is finished.
Hot retrievalViewer request → first image rendered, current study.p95 under 2 sServer-side time alone excludes the decode and the network, which is most of what the radiologist experiences.
Prior retrievalRequest → prior displayable, from the tier it really lives in.p95 under 10 sThe quiet killer. If priors come from an archive tier, this number is set by your storage-class choice, not your code.
Worklist availabilitySuccessful worklist load, measured by synthetic probe.99.9% monthlySeparate from the archive. Radiologists cannot start work without it even when every image is retrievable.
Report deliverySignature → positive acknowledgement from each destination.99.5% within 15 minAcknowledgement, not transmission. Anything measured at send-time cannot detect a black hole.
Exception queue ageItem created → item resolved.p95 under one shiftThe only indicator that measures the human loop. Without it, understaffing the desk is invisible on every dashboard.
Correction propagationCorrection applied → all downstream recipients confirmed updated.p95 under 1 hourMeasures the state nobody watches: upstream fixed, downstream stale.
Turnaround timeDefined event → report signed. See the trap below.Per priority classThe headline clinical metric and the most contested definition on this page.
The turnaround-time clock trap Four defensible start events produce four different numbers from identical work. Order placed includes scheduling and patient arrival, so it measures the health system, not you. Study complete is the fairest measure of the platform plus the reading service, and depends entirely on your completeness rule, which means changing that rule silently changes your headline metric. Assigned to a radiologist measures the radiologist only and hides every minute a study spent unassigned. Radiologist opened it measures dictation speed and nothing else. Agree the start event, the stop event, the exclusions, and the priority classes in writing, and treat any change to the completeness rule as a change to the service level, because it is.

What suppliers will rarely sign, and the substitute

  • End-to-end turnaround when they do not control acquisition or reading. Substitute: their segment, measured at their boundary, with the boundary named.
  • Prior retrieval latency from archive tiers. Substitute: a published latency per storage class plus a maximum, with the retrieval fee stated.
  • Index rebuild time. Substitute: a tested figure at your object count, refreshed annually, in writing.
  • Bulk export throughput. Substitute: objects per hour achieved in a real customer migration, with the per-object charge named. A supplier who cannot produce one has never migrated a customer out.
  • Correctness of any kind. Nobody signs a defect-rate SLA. Substitute: severity definitions, response times per severity, and a root-cause commitment with a deadline.

Remedies that mean something

  • Service credits are compensation, not remedy. A month of credits does not restore a week of turnaround debt.
  • Tie repeated breach to a termination right and to data egress on defined terms, which is the only leverage that survives a bad relationship.
  • Require a root-cause analysis with a deadline for each severity-1 event, delivered whether or not credits apply.
  • Require notice of maintenance windows in the customer's local time, and count unannounced maintenance as unplanned downtime.
  • Make the measurement method contractual, including the probe location. Two honest parties measuring at different boundaries will disagree forever.
Anti-pattern — one availability number for the whole platform A single monthly percentage lets a platform report 99.95% during a month in which priors were unretrievable for two working days, because the archive answered every request — slowly, and from a tier nobody budgeted for. Publish availability per path: ingest, worklist, current-study retrieval, prior retrieval, reporting, delivery.

07 What five years actually costs

Storage price per gigabyte is the number everyone models and the one that decides least. This section is a working model with the arithmetic exposed, so you can put your own measurements in and get a defensible answer out — and then discover, as the worked example does, that the storage bill is a rounding error next to the people.

What this model covers, and what it deliberately does not In scope: object-storage capacity across two tiers, per-object write and read charges, archive retrieval fees, egress to viewers, one-time egress at exit, and platform operations staffing. Out of scope, and usually larger: PACS or VNA licensing, viewer seats, radiologist fees, compute and database, network circuits and VPN, gateway hardware per site, security and compliance programme, migration-in cost, and the dual-run period during any migration. Add those separately. This model exists to size the part people think dominates and to show that it does not.

Rates, dated and sourced

Table 7.1 — Default rates: Amazon S3, US East (N. Virginia), September 2026. Substitute your provider's current published rates; every one of these is an input below. Vendor-published
LineRateOperational note
Hot storage (S3 Standard, first 50 TB)$0.023 / GB-monthWhere the current-study working set must live.
Archive storage (Glacier Instant Retrieval)$0.004 / GB-monthMillisecond retrieval, but with a per-GB retrieval fee and a 90-day minimum storage duration. Correct or delete an object inside 90 days and you still pay the balance.
Archive data retrieval$0.03 / GBSeven and a half times the monthly storage rate. Retrieve an object once a month and the tier is costing you money, not saving it.
Write requests (PUT/COPY/POST/LIST)$0.005 / 1,000Charged per object, so this line scales with instance count. A thin-slice CT study can be thousands of PUTs.
Read requests (GET)$0.0004 / 1,000Small per request, large across a prior-fetch workload measured in instances.
Egress to internet (first 10 TB/month)$0.09 / GBApplies to browser-based viewing and to the day you leave. Both.
Other minimum durations30 / 90 / 180 daysStandard-IA 30, Glacier Flexible 90, Deep Archive 180. Early-deletion penalties interact badly with correction and retention workflows.

The model

Month m from 0 to 59. Studies grow geometrically. Data accumulates with no expiry inside the window when retention exceeds five years. Objects newer than the hot window sit in hot storage, everything older in the archive tier, and each is stored r times. Writes are charged per instance per replica; reads and archive retrievals are charged against the studies actually retrieved.

Volume

Measure the first three from your own archive. Instance count drives request charges and migration wall-clock more than gigabytes do.

Storage shape

Replicas multiply storage and writes, not retrievals. A cross-region copy is the cheapest line in this whole model.

Access and charges
People

Ingest monitoring, the exception desk, site onboarding, on-call. Not radiologists, not engineering, not support beyond tier 2.

Five-year projection
Studies ingested
—
Archive at month 60
—
Storage capacity
—
Write requests
—
Read requests
—
Archive retrieval
—
Egress to viewers
—
Infrastructure subtotal
—
Operations staffing
—
Five-year total
—
Cost per study
—
Infrastructure per study
—
One-time egress to exit
—
Staffing share of total
—

Values persist in this browser only.

The worked example, all the way to a number

Using the defaults above — 12,000 studies a month growing 12% a year, 120 MB and 900 instances per study, two copies, three months hot then Glacier Instant Retrieval, 3% of the archive retrieved monthly with 60% of that egressed, and 3.5 FTE at $135,000 loaded:

Recommendation — what this model is actually telling you Three conclusions survive almost any plausible change to the inputs. First: negotiating the per-gigabyte rate is close to pointless; reducing exception-desk load by one FTE saves more than the entire five-year storage bill. Second: instance count is the cost driver you can control, and it is set by acquisition protocols you may not own. Third: exit cost is real, one-time, and never in the business case — model it on day one, because it is also the number that quietly determines how much leverage you have at renewal.
Anti-pattern — the archive tier chosen from the storage rate alone Glacier Instant Retrieval stores at $0.004/GB-month and returns data at $0.03/GB. An object retrieved once a month costs more in retrieval than it does in storage, and the 90-day minimum storage duration means a study corrected or deleted at day 30 is billed for 90. Tier placement is a workflow decision about how often priors are read and how often objects change — the price list is an input to it, not the decision.

08 Operating models and who is actually responsible

The sourcing decision picks components. The operating model decides who answers the phone at 03:00, and those are different questions with different answers. A team can buy every component and still own every operational obligation on this page.

Table 8.1 — Five operating models against the obligations that do not disappear. You = the product organisation; Site = the clinic or hospital; Sup = supplier or operating partner; Split = genuinely shared and therefore the row to negotiate first. Recommendation
ObligationSoftware platform onlyHosted PACSTeleradiology serviceEmbedded in an EHR / PIMSPlatform + outsourced operations
Modality commissioningSiteSplitYouSplitSup
Gateway health and bufferingSiteYouYouYouSup
Identity source of truthSiteSiteSplitHost systemSite
Exception deskSiteSplitYouSplitSup, to your standard
Wrong-patient correctionSiteSplitYouSplitSplit — never fully delegate
Study completeness ruleYouYouYouYouYou
Turnaround-time commitmentNoneNoneYouNoneSplit
Critical-result communicationSiteSiteYouSiteYou
Diagnostic viewing conditionsSiteSiteYouSiteYou
Retention and legal holdSiteSplitSplitHost systemYou
24-hour technical supportYouYouYouSplitSup
Downtime declarationSiteYouYouSplitYou
Archive integrity and recoverySiteYouYouYouSplit — you must be able to verify
Bulk export on exitYouYouYouYouYou, contractually

The three rows that decide the model

  • Wrong-patient correction. Whoever holds this holds clinical risk. It is the one obligation that should never be wholly outsourced, whatever the contract says, because you cannot delegate the consequence.
  • Downtime declaration. If nobody is named, the answer during an incident is "everyone, eventually, after an hour of discussion".
  • Bulk export. The only row that is identical in every column. If you cannot get your objects out at a demonstrated rate, the operating model is decorative.

Delegation tests before signing an operations partner

  • Can you observe their queues directly, or only their monthly report? A partner you can only audit retrospectively is a partner you cannot manage.
  • Do they operate to your written authority matrix, including dual control on merges?
  • Whose audit trail records their actions — yours, or theirs?
  • What happens to in-flight exceptions on the day the contract ends?
  • Can you take the function back in-house within one notice period, and have you written down how?

09 Human and veterinary operations are not the same job

The standard is shared; almost nothing about running the service is. Veterinary imaging is not human imaging with looser rules, and treating it as a configuration flag on a human platform produces a system that is wrong in both directions.

Table 9.1 — Operational differences that change the product, not the branding. Standard for the DICOM attributes; common practice for the workflow observations.
DimensionHuman healthVeterinaryWhat it changes operationally
Who the patient isThe person, with a durable identifier issued by an assigning authority.The animal, usually identified through its owner and clinic. Patient's Name (0010,0010) frequently carries an owner-plus-animal convention with no standard form.Deduplication and prior-matching cannot rely on a stable identifier. Two clinics in the same group will encode "Rex Alvarez" three different ways.
Extra required attributesNone specific.Patient Species Description (0010,2201) and Code Sequence (0010,2202); Patient Breed Description (0010,2292) and Code Sequence (0010,2293); Breed Registration Sequence (0010,2294).Species is clinically load-bearing: it drives reference ranges, hanging protocols, and which radiologist can read the case. If it arrives as free text, it will arrive as free text forever.
Decision-makerThe patient or a legal representative.Responsible Person (0010,2297), Responsible Person Role (0010,2298) with defined terms including OWNER and VETERINARIAN, and Responsible Organization (0010,2299).Report delivery and consent route to a party the standard models explicitly. Ignoring these attributes means rebuilding them badly in your own schema.
Ordering contextEHR order with an accession number, an ordering provider, and an encounter.A PIMS request, or often a consultation request with no order at all.Where there is no order, every study is an unscheduled case and the exception desk is the primary workflow rather than the fallback.
Species rangeOne.Small animal, equine, exotic, production animal — different body parts, positioning, sizes, and reading expertise.Routing rules keyed on Modality and body part are insufficient. Equine distal limb and feline thorax are different services sharing one SOP Class.
RetentionUS hospitals: at least 5 years (42 CFR 482.24(b)(1)). Mammography: the longest of 5 years, 10 years absent further mammograms, or the state period (21 CFR 900.12(c)(4)).Set by state veterinary practice acts and board rules, which vary substantially by state and are not harmonised with human rules.Retention becomes per-jurisdiction configuration, not a global constant. Get it in writing from the customer, per state.
Privacy regimeHIPAA and equivalents apply to protected health information.Animal records are generally not protected health information; owner contact details are still personal data under general privacy law.Do not claim HIPAA where it does not apply, and do not assume the absence of HIPAA means the absence of obligations. The owner's data is still regulated.
Who readsCredentialled radiologists, with privileges by facility.Board-certified veterinary radiologists, in a much smaller pool, often reading across many clinics.Assignment, capacity planning, and after-hours cover are constrained by a scarce reader pool. Queue design matters more than in a large human practice.
Who pays and who receivesPayer, provider, and patient are distinct parties.The clinic is the customer, the owner is the payer, and the referring veterinarian may be a third party.Report distribution has three audiences with different needs, and the portal you build for the owner is a different product from the one you build for the clinic.
Recommendation — one core, two domain layers Share study, series, instance, workflow state, audit, and storage. Do not share the identity model. Human identity assumes an assigning authority and a durable identifier; veterinary identity assumes an owner relationship, a clinic, and a species. Forcing one schema to cover both produces fields that are optional in theory and required in practice, which is how a veterinary study ends up with a blank species and a human study ends up with a "responsible person".

10 The operations readiness memo

A fill-in artefact for the review before go-live, or the one you should have run before signing. Every blank is a question this page argues you cannot leave open. Edit it here and copy it out; it saves in this browser only.

11 Common mistakes and anti-patterns

Fourteen failures that are operational rather than architectural. Each one has a healthy-looking architecture diagram behind it.

1 — Treating a green dashboard as evidence the clinical path works

Component health checks answer "is the process running". They do not answer "can a radiologist open today's chest CT with its priors". Run a synthetic transaction end to end on a schedule: push a known study, retrieve it, render it headlessly, generate and deliver a report to a test destination, and alarm on the whole path. Every incident in this page's tables is invisible to component-level monitoring.

2 — A retry loop that deletes the failing object

Cxxx and A9xx failures are diagnosable only from the artefact. A pipeline that retries three times and drops the object has converted a solvable vendor ticket into an unreproducible anecdote. Quarantine failed objects immutably, subject to your retention and privacy rules, and make the quarantine a queue with an owner.

3 — Assuming the modality is a durable queue

Some devices retry indefinitely, some hold a shallow queue, some drop everything on reboot. Which one each of your devices is, is a fact you can only learn by pulling the link during commissioning (step 13). Architectures that assume "the modality will resend" fail silently on the devices that will not.

4 — Silent attribute coercion

Status B000 means the receiver rewrote your data. Coercion is sometimes correct policy, but undocumented coercion means an incorrectly-selected worklist entry is written into the permanent record with no trace of what the device actually sent. If you coerce, log every changed attribute with both values; if you do not, alarm on B000.

5 — Support tooling with production-grade destructive power

See the authority matrix in Table 4.2. Merges, moves, rejections, and deletions belong behind dual control with a named second approver. A tier 1 agent should be able to see nearly everything and change almost nothing.

6 — A completeness rule that is a timeout nobody wrote down

The value exists — it is in someone's configuration file. If it is not published per modality, then changing it silently changes turnaround-time reporting, the rate of incomplete reads, and your headline service level, all at once and without a change record.

7 — Measuring delivery at send time

An interface that logs "message transmitted" and never inspects the acknowledgement will lose reports for months while every dashboard stays green. Every delivery channel needs positive receipt and an unacknowledged queue with an age alarm. This is the single most common way a correct report fails to reach a clinician.

8 — Correcting upstream and forgetting downstream

A corrected identity in your archive plus an uncorrected copy in the EHR, the portal, the referring practice's system, and last night's export is worse than the original error: two systems now disagree and both appear authoritative. Correction is not complete until propagation is confirmed, which requires knowing every place a study or report has been.

9 — Testing recovery on a sample dataset

The procedure validates; the durations do not. Index rebuild time at production object count, bulk ingest rate during a drain, and per-object archive retrieval fees are the three numbers that decide your real recovery time, and all three are commonly first measured during the incident.

10 — One availability number for the whole platform

Ingest, worklist, current-study retrieval, prior retrieval, reporting, and delivery fail independently. A single monthly percentage can report 99.95% through two working days in which priors were effectively unavailable. Publish availability per path.

11 — Tiering storage on the per-gigabyte rate

Archive classes carry per-GB retrieval fees and minimum storage durations (90 days for Glacier Instant Retrieval and Flexible, 180 for Deep Archive, 30 for Standard-IA). An object read once a month costs more to retrieve than to store, and an object corrected at day 30 is billed for 90. Tier on read frequency and mutability, then check the price.

12 — No exit-cost line in the business case

In the worked example, egress alone to leave at year five is $10,168 — 19% of five years of infrastructure spend, one-time, before any migration engineering. Suppliers know this number. Model it on day one, because it is also what determines your negotiating position at renewal.

13 — Discontinuation reasons captured and never routed

CID 9301 hands you an incorrect-worklist-selection event (110514), an equipment-failure trend (110501), and a deceased-patient signal (110504) for free. A platform that stores all nineteen codes identically has the evidence and acts on none of it.

14 — Staffing a queue instead of fixing its cause

An exception queue whose depth is stable is not under control; it is in equilibrium with the rate of a defect you are paying people to absorb. Review monthly by cause, and convert the top cause into a configuration or product change. In the worked cost model, one FTE of avoided exception work outweighs the entire five-year infrastructure bill more than twelvefold.

12 Operations glossary

Terms used here in a specific operational sense. Protocol and architecture vocabulary lives in the atlas glossary; this list does not repeat it.

TermMeaning on this page
Association rejectA refusal before any data is exchanged, carrying result, source, and reason fields (PS3.8 9.3.4). Distinct from a DIMSE status, which is returned after a service request is accepted.
Bring-upThe commissioning sequence for one device or site, from identity allocation to confirmed end-to-end delivery.
Catch-upWork created by an outage after service is restored: backlog ingest, deduplication, identity reconciliation, and re-delivery. Usually longer than the outage.
CoercionThe receiver rewriting attributes of an object it stores, reported as C-STORE warning B000. Frequently identity attributes taken from the receiver's own worklist.
Completeness ruleThe written, per-modality definition of when a study is considered finished and may be released for reading. Three mechanisms exist and each fails differently.
Downtime kitThe offline artefacts an incident needs: contact tree, device inventory, alternate urgent route, downtime log, and named declaration authority.
Dual controlA destructive action requiring two named people, both recorded. Applied here to merges, moves between patients, rejections, and deletions.
Exception deskThe human loop that resolves studies the automated path cannot: unmatched, mismatched, duplicated, incomplete, undelivered.
Exit costThe one-time cost of removing your data from a platform: egress, per-object retrieval, engineering, and dual-run time. Distinct from the licence you stop paying.
Hot windowHow long after acquisition an object stays in immediate-access storage before moving to an archive class. A workflow decision constrained by prior-read frequency.
Instance countNumber of SOP Instances, as distinct from bytes. The variable that drives per-object charges, index writes, queue depth, and migration wall-clock.
Minimum storage durationThe billing floor of an archive storage class (30, 90, or 180 days). Objects deleted or moved earlier are still charged for the balance.
Orphan orderAn order with no images inside the expected window. The queue that detects a site whose connectivity failed.
PropagationPushing a correction to every downstream system that already received the incorrect record, and confirming each one.
Quiet timerThe fallback completeness mechanism: no new object for n minutes means done. A guess with a clinical consequence in both directions.
Read path / write pathRetrieval and display versus ingestion and storage. They fail independently and deserve separate service levels.
Site surveyThe written record of a site's network, devices, identity sources, people, and inherited obligations, collected before configuration begins.
Synthetic transactionA scheduled end-to-end probe: push, retrieve, render, report, deliver. The only monitoring that fails when the clinical path fails.

13 Sources

Every code, rate, and legal figure on this page traces to one of these. Standards editions and published prices move; the rate table in section 7 will go stale first.

DICOM, current edition (PS3, 2026c)

  1. PS3.4 Table B.2-1 — Storage Service Class status values (A7xx, A9xx, Cxxx, B000, B006, B007).
  2. PS3.4 Section C.4.2 — C-MOVE response statuses (A701, A702, A801, A900, B000, FE00, FF00).
  3. PS3.4 Table K.6-1 — Modality Worklist matching keys.
  4. PS3.4 Annex J — Storage Commitment Push Model (N-ACTION and N-EVENT-REPORT).
  5. PS3.3 Section C.14 — Storage commitment failure reasons (0110, 0112, 0119, 0122, 0131, 0213).
  6. PS3.3 Section C.7 — Patient module, including species, breed, and responsible-person attributes.
  7. PS3.7 Annex C — status class conventions (Axxx, Bxxx, Cxxx, FE00, FF00).
  8. PS3.8 Section 9.3.4 — A-ASSOCIATE-RJ result, source, and reason values.
  9. PS3.16 CID 9301 — Modality PPS Discontinuation Reason; CID 9300 for the general procedure set.

Integration profiles, regulation, and rates

  1. IHE IT Infrastructure Technical Framework Volume 1 — Consistent Time (CT) profile, median error under one second over NTP.
  2. 45 CFR §164.308(a)(7) — HIPAA Security Rule contingency plan standard.
  3. 42 CFR §482.24(b)(1) — hospital medical record retention, at least five years.
  4. 21 CFR §900.12(c)(4) — MQSA mammography record retention.
  5. HL7 v2 table 0123 — Result Status; table 0085 — Observation Result Status.
  6. IANA Service Name and Transport Protocol Port Number Registry — acr-nema 104, dicom-iscl 2761, dicom-tls 2762, dicom 11112.
  7. Amazon S3 pricing, US East (N. Virginia), retrieved September 2026, for the rates and minimum storage durations in Table 7.1.
  8. DCMTK 3.6 tool documentation for echoscu, findscu, storescu, and movescu option syntax, including the sequence path form (0040,0100)[0].Attribute.
  9. Joint Commission National Patient Safety Goal NPSG.02.03.01 requires accredited organisations to define in writing who reports critical results to whom and within what interval, and to evaluate timeliness. Numbering differs between accreditation programmes and has moved; verify against the manual for your programme.