00 The card you keep open
Eight things an on-call engineer or an imaging operations lead looks up under pressure. Everything here is verified against the primary source named on the tile.
IANA registers acr-nema on 104, dicom on 11112, dicom-tls on 2762 and dicom-iscl on 2761. If a firewall ticket names only 104, it will not cover a modern deployment.
Result 1 (permanent), Source 1 (service-user), Reason 7 = called AE title not recognized. Reason 3 = calling AE title not recognized. Those two account for most day-one failures. Standard PS3.8 9.3.4
A7xx = refused, out of resources (their disk or queue). A9xx = data set does not match SOP class (your object). Cxxx = cannot understand (parse failure). Standard PS3.4 Table B.2-1
The receiver rewrote your attributes, usually demographics pulled from its own worklist. A success you should treat as an event: silent coercion is how a wrong patient identity becomes permanent.
A801 = move destination unknown: the archive has no entry for your destination AE. A702 = unable to perform sub-operations, which usually means the archive cannot open a connection back to your destination. Standard PS3.4 C.4.2
Scheduled Station AE Title (0040,0001) is single-value matching only; Scheduled Procedure Step Start Date/Time (0040,0002)/(0040,0003) accept ranges; Modality (0008,0060), Patient's Name and Patient ID are also required matching keys. An empty worklist is nearly always one of these. Standard PS3.4 Table K.6-1
The IHE Consistent Time profile specifies synchronisation to a median error under one second, over NTP. Audit correlation, TAT clocks, and "which correction happened first" all depend on it. IHE ITI
Hospital medical records: at least 5 years (42 CFR 482.24(b)(1)). Mammography: the longest of 5 years, 10 years if no further mammograms are performed at the facility, or the state period (21 CFR 900.12(c)(4)). State law and payer contracts routinely exceed both. Regulatory
01 The modality floor
Every operational surprise downstream starts at a device someone else owns, configured by someone who has left, and used at 02:00 by a technologist who will not read your release notes. The atlas treats acquisition as one stratum. Here it is a per-device operating profile: what the thing emits, what drives its object count, and the specific way it fails you.
Operating profiles by modality
Instance count, not gigabytes, is the operational variable. Per-object charges, index writes, queue depth, transfer duration, viewer load time, and migration wall-clock all scale with the number of objects. Sizes vary too much to state as facts; the atlas has the short list of figures that are actually citable, and the honest advice is to measure your own archive.
| Modality | Typically emits | What drives object count | The failure it causes most often |
|---|---|---|---|
| CR / DX | Computed Radiography Image Storage; Digital X-Ray Image Storage — For Presentation and For Processing are separate SOP Classes. | Number of projections; typically single digits per study. | The device sends both For Presentation and For Processing. The archive doubles, hanging protocols pick the unprocessed object, and nobody notices for a quarter. Decide per device which one you accept, and enforce it at ingestion. |
| CT | CT Image Storage; Enhanced CT Image Storage (multi-frame). | Coverage ÷ slice thickness, multiplied by every reconstruction kernel, window, and derived series the protocol produces. | Reconstructions arrive minutes apart on separate associations. The study looks complete, gets assigned, and a fourth series lands after the read starts. You need an explicit completeness rule (see below), not a guess. |
| MR | MR Image Storage; Enhanced MR Image Storage; derived maps as separate series. | Sequence count; derived series (ADC, subtraction, MIP) added by the console or a post-processing station. | Free-text Series Description differs per scanner and per protocol revision, so hanging protocols silently stop matching after a scanner software upgrade. Treat protocol names as a versioned configuration item. |
| US | Ultrasound Image Storage; Ultrasound Multi-frame Image Storage. | Number of stills plus cine loops; a loop is one large multi-frame object, not many small ones. | Lossy compression is applied on the device before you ever see the object, so your "we only store lossless" policy was already violated upstream. Cine playback also depends on frame-time attributes the device may omit. |
| MG | Digital Mammography X-Ray Image Storage, For Presentation and For Processing. | Views per breast; priors are fetched in pairs and compared, so retrieval load is at least double the read count. | Missing or wrong laterality and view codes break the hanging protocol that the entire reading workflow depends on. Mammography retention rules are also longer than your default (21 CFR 900.12(c)(4)). |
| MG / DBT | Breast Tomosynthesis Image Storage, usually alongside a synthesised 2D image. | Reconstructed slice count per view, plus the projection set if the site retains it. | The single largest object volume per study of any routine exam. It is the study type that first exposes an undersized ingest pipe, a slow viewer, or a per-object storage bill. |
| XA / RF | X-Ray Angiographic Image Storage; X-Ray Radiofluoroscopic Image Storage; X-Ray Radiation Dose SR. | Runs per procedure; each run is a multi-frame object. | Dose reports are structured reports, not images. Pipelines built for pixels drop them, and the dose registry submission you promised quietly stops. |
| NM / PT | Nuclear Medicine Image Storage; Positron Emission Tomography Image Storage. | Detector, phase, and gate dimensions; PET studies pair with a CT series for attenuation correction. | Quantitative display (SUV) depends on decay, dose, and timing attributes. Lose or re-derive them in a transcode and the numbers on screen are wrong while the images look fine. |
| IO / dental | Intra-Oral X-Ray Image Storage; panoramic units often emit DX. | Per-tooth or per-quadrant exposures; high study count, low bytes. | Sensor software written for a single-practice server writes non-conformant or missing identifiers, and tooth numbering has no DICOM home, so it arrives in a free-text field you must parse. |
| CBCT | Usually CT Image Storage, whatever the marketing name of the device. | Field of view and voxel size. | Modality and body-part attributes do not describe what the device is, so routing rules, worklists, and reporting templates keyed on Modality send it to the wrong queue. |
| SC | Secondary Capture Image Storage; Encapsulated PDF; Encapsulated CDA. | Ad hoc: screenshots, scanned paper, exported reports. | Burned-in demographics in the pixel data. Every de-identification and sharing workflow has to treat these as a separate class of object, and Burned In Annotation (0028,0301) is frequently absent or wrong. |
| SR / KO / PR | Basic Text, Enhanced, and Comprehensive SR; Key Object Selection Document; Grayscale Softcopy Presentation State. | One per report, selection, or saved annotation. | These are the objects that carry measurements, key images, and annotations. If a migration or export path only moves image SOP Classes, the clinical work product is what you leave behind. |
| SM | VL Whole Slide Microscopy Image Storage. | Tiles per level across a pyramid; orders of magnitude beyond radiology per slide. | Digital pathology shares the standard and almost none of the operating assumptions. Do not fold it into a radiology archive plan without sizing it separately. |
Discontinued procedure steps, decoded
When a modality abandons a procedure step it can say why, using a coded reason from CID 9301. Most platforms store the code and never act on it. Each one implies a different queue, and several are identity-safety events rather than scheduling noise.
| Code | Meaning | What operations must do with it |
|---|---|---|
| 110500 | Doctor canceled procedure | Close the order, stop the turnaround clock, and suppress the "study never arrived" alert. Billing and the ordering system both need the cancellation. |
| 110501 | Equipment failure | Device health event, not a workflow event. Repeated codes from one AE title are your earliest signal of a failing detector or console before the site opens a ticket. |
| 110502 | Incorrect procedure ordered | Route to the order-correction queue. A new order is required; do not let the technologist "fix" it by selecting a different worklist entry mid-exam. |
| 110503 | Patient allergic to media/contrast | Clinical event with a safety record attached. Your platform's job is to preserve it, surface it on any repeat order, and not silently drop it during reconciliation. |
| 110504 | Patient died | Stop all automated communication for that patient immediately: portal notifications, reminder messages, and result callbacks. This is the code that makes an unfiltered notification engine indefensible. |
| 110505 | Patient refused to continue procedure | Partial study exists and may still be interpretable. It must reach a radiologist flagged as partial, never as a completed exam. |
| 110506 | Patient taken for treatment or surgery | Expect a resumption or a repeat later the same day. Duplicate-detection needs to tolerate two partial studies for one order. |
| 110507 | Patient did not arrive | Highest-volume code in most estates. Auto-close the worklist entry after a defined window, or the worklist fills with ghosts and technologists start scrolling past real entries. |
| 110508 | Patient pregnant | Safety hold. Requires an order review, not a reschedule. |
| 110509 | Change of procedure for correct charging | Financial reconciliation, not clinical. The images may be perfectly valid under a different procedure code. |
| 110510 | Duplicate order | Feed it back to the ordering system. Repeated duplicates from one site is an integration defect, not user error. |
| 110511 | Nursing unit cancel | Same handling as 110500, different source. Track separately: the split tells you where scheduling breaks down. |
| 110512 | Incorrect side ordered | Wrong-side is a never-event category in surgery and a serious defect here. Alarm it; do not let it be silently corrected at the console. |
| 110513 | Discontinued for unspecified reason | The default a device sends when its UI offers no list. A rising share of 110513 means your reason codes are decorative and the data is not usable for anything. |
| 110514 | Incorrect worklist entry selected | The identity event. Images were acquired under another patient's demographics. This must trigger the wrong-patient correction path (rejection, correction, downstream propagation) and be counted as a safety metric, not a support ticket. |
| 110515 | Patient condition prevented continuing | Partial study, clinically urgent context. It usually should be read faster than a normal exam, not slower. |
| 110516 | Equipment change | The same procedure will resume on a different AE title. Your completeness rule and duplicate detection must survive a study arriving from two devices. |
| 95384003 | Injection site extravasation (SNOMED CT) | Adverse event. Preserve the association with the study and the contrast record. |
| 292094009 | Radiopharmaceutical adverse reaction (SNOMED CT) | Adverse event with reporting obligations that vary by jurisdiction. Do not let it exist only as a discarded procedure step. |
02 Commissioning a site or a modality
Onboarding is the operation you will perform most often and the one most likely to be improvised. Everything here is a form or a sequence, because the failure mode of onboarding is not difficulty, it is that step 9 was skipped and nobody can prove it.
The site survey, collected before anything is configured
Every field below has cost someone a go-live. Collect them in writing, from the site, before a firewall ticket is raised.
Network and access
- Public egress IP and whether it is static. Dynamic IPs make source allowlisting a recurring outage.
- Outbound port policy, and who approves changes. Naming 104 only is a classic day-one block.
- Whether the clinic network sits behind carrier-grade NAT or a shared practice-group firewall.
- Whether inbound connections are possible at all — this decides push versus pull architecture for the whole site.
- Available upstream bandwidth at the time of day the site actually scans, not the advertised rate.
- Who is on site with physical access to the gateway, and their hours.
Devices and identity
- Per device: manufacturer, model, software version, AE title, IP, listening port, and the conformance statement.
- AE titles in use elsewhere in the estate — collisions are common and produce baffling misrouting.
- Which system is the source of truth for patient or owner identity at this site.
- Whether the site has a RIS or PIMS that can supply a worklist, or whether identity is typed at the console.
- Existing archive, if any, and whether historical studies are in scope for migration.
- Time source of every device, and whether the site has a working NTP path.
Workflow and people
- Who submits studies, who interprets, who receives the report, and who fixes an identity error.
- Operating hours, after-hours volume, and what the site expects to happen at 03:00.
- Report delivery destinations: EHR or PIMS interface, portal, email, fax, printer.
- Named site contact for exceptions, and their escalation backup.
- Training status of each technologist on worklist selection, which is the single highest-leverage control against wrong-patient studies.
Obligations you are inheriting
- Retention period the site is contractually or legally bound to, and who told you.
- Whether mammography is in scope, which changes retention and hanging requirements.
- Jurisdiction of the site and of your storage, which is not always the same country.
- Any existing business associate agreement, data processing agreement, or equivalent.
- What the site was promised by sales that is not in the statement of work.
The bring-up sequence
Fourteen steps, in order, each with a pass criterion you can point at. Tick boxes persist in this browser only.
- Assign the AE title, IP, and port on both sides and record them in the configuration system of record. AE Title is a 16-byte identifier, not a credential — treat allowlisting as a routing convenience, never as authentication.Pass: both sides configured from the same written record, no AE title reused anywhere in the estate.
- Firewall rules in both directions if you use C-MOVE, outbound only if you use push plus DICOMweb. Confirm with a raw TCP connection before involving DICOM at all.Pass: TCP connect succeeds from the device subnet, not from the engineer's laptop on a different VLAN.
- In both directions if both directions will be used. An echo that works one way proves nothing about the other.Pass: echo succeeds from the device and from the archive, logged with timestamps on both.
- Point the device and the gateway at a working NTP source. The IHE Consistent Time profile specifies a median error under one second.Pass: device clock within one second of the archive's, verified after a reboot, not just after configuration.
- Run a modality worklist C-FIND with the exact keys the device will send: Scheduled Station AE Title, start date, modality. Compare against what the device actually queries, captured from the wire, not from its manual.Pass: a scheduled test order appears on the device screen, selected by the technologist, not typed.
- A real acquisition, not a synthetic file, from the console the technologist will use. Synthetic objects hide exactly the encodings that break.Pass: C-STORE status 0000 for every instance, and the instance count on the archive equals the count on the device.
- Compare the stored object's identity attributes against what left the device. Status B000 means the receiver rewrote them.Pass: either no coercion, or coercion is intended, documented, and logged as an event you can query later.
- If the device supports the Storage Commitment Push Model (N-ACTION out, N-EVENT-REPORT back), exercise it. The reverse association is a separate firewall path and fails independently of the store.Pass: commitment returns success, and a deliberately unsupported object returns a documented failure reason rather than silence.
- Start a step, complete one, and discontinue one with a reason code. Confirm your platform branches on the reason (Table 1.2), rather than storing it.Pass: IN PROGRESS, COMPLETED, and DISCONTINUED all land, and the discontinued one appears in the queue you expect.
- If you transcode or compress on ingest, verify the stored object against the original: pixel data, photometric interpretation, and the attributes that record what was done to it.Pass: a documented comparison, per SOP Class this device emits, not per file format in general.
- Diagnostic, clinical review, and customer-facing. Each has a different decoder and a different tolerance for missing attributes.Pass: correct window level, correct orientation and laterality, correct series ordering, cine plays at the right rate.
- Retrieve an older study for the same patient, from the tier it will actually live in. A prior retrieved from hot storage during testing proves nothing about the archive tier.Pass: prior loads within the target the reading workflow assumes, measured from cold, with the retrieval charge recorded.
- Pull the upstream connection mid-study. The gateway must buffer, resume, and not duplicate. This is the test that most often fails and the one most often skipped.Pass: after reconnection the archive holds exactly one complete copy, and the buffer's capacity in hours is a number you know.
- Interpret the test study, sign the report, and confirm delivery to every configured destination, including the fax or printer nobody remembers.Pass: the site contact confirms receipt in their own system, in writing, before go-live is declared.
03 The triage board
The signature tool on this page. Type a status code, a reject reason, or a symptom in plain words. Everything is filtered live, so A801, worklist, and black all land somewhere useful.
| Signal | Symptom | Probe first | Most likely cause and fix |
|---|---|---|---|
| 1 / 1 / 7 | Association rejected immediately; nothing is transferred. | Read the reject PDU: result, source, reason. | Called AE title not recognized. The AE title you are calling is not configured on the receiver, or differs by case, a trailing space, or a character beyond 16 bytes. Compare the two configurations character by character rather than reading them aloud. |
| 1 / 1 / 3 | Association rejected; the receiver logs an unknown peer. | Same PDU, reason field. | Calling AE title not recognized. The receiver allowlists source AE titles and yours is missing, usually because the device was replaced and the new console shipped with a different default. |
| 1 / 1 / 2 | Rejected before any negotiation. | Reject PDU reason 2 with source 1. | Application context name not supported. Rare, and almost always a non-DICOM service answering on the port. Confirm you are talking to what you think you are. |
| 2 / 3 / 1 | Intermittent rejections under load; retries succeed. | Reject PDU with result 2 (transient), source 3. | Temporary congestion. The receiver is at its concurrent-association limit. Fix the sender's parallelism and backoff before raising the receiver's limit, or you move the failure into its queue. |
| 2 / 3 / 2 | Same, but persistent at a fixed concurrency. | Reject reason 2, source 3. | Local limit exceeded. A configured association cap. Raise it deliberately with the memory cost calculated, or serialise the sender. |
| Echo OK, store fails | C-ECHO succeeds, C-STORE fails at once with no status. | Look for a rejected presentation context in the association-accept. | The receiver did not accept the SOP Class or the transfer syntax the device offered. Read section N.5 of the receiver's conformance statement and compare against what the device sends. Echo negotiates only the Verification SOP Class, so it proves connectivity and nothing about content. |
| A7xx | Stores fail across all devices at once. | C-STORE status begins A7. | Refused: out of resources. The receiver, not you: disk, quota, queue depth, or a stuck consumer. Check the archive's own alarms before touching a modality. |
| A9xx / B007 | One device or one exam type fails; others are fine. | C-STORE status A9 or warning B007. | Data set does not match SOP Class. The object's contents disagree with the SOP Class UID it claims. Capture the failing object and diff it against a working one from the same device before escalating to the vendor. |
| Cxxx | A subset of instances fails, reproducibly. | C-STORE status begins C. | Cannot understand. Parse failure at the receiver. Keep the raw object: this is the one class of failure where the artefact is the entire ticket, and it is routinely deleted by a retry loop. |
| B000 | Everything "succeeds", but stored demographics differ from the console. | C-STORE warning B000 in the response. | Coercion of data elements. The receiver rewrote attributes, typically identity, from its own worklist. Decide whether coercion is policy. If it is, log every coerced attribute; if it is not, turn it off. Undocumented coercion turns a mis-selected worklist entry into a permanent record. |
| B006 | Objects store but something is missing later. | C-STORE warning B006. | Elements discarded. The receiver dropped attributes it did not want, often private ones carrying measurements or reconstruction parameters. Ask which, in writing, and check whether your AI or quantitative workflow needed them. |
| A801 | C-MOVE fails instantly. | C-MOVE status A801. | Move destination unknown. The archive has no configuration entry for your destination AE title. C-MOVE requires the SCP to know the destination in advance; this is the structural reason many platforms move to C-GET or DICOMweb retrieval. |
| A702 | C-MOVE accepts, then fails part-way. | C-MOVE status A702, plus the sub-operation counters. | Unable to perform sub-operations. Usually the archive cannot open a connection back to the destination: a firewall that permits outbound only, or a destination that is not listening. Check the direction of the second connection, not the first. |
| B000 on C-MOVE | Retrieval "succeeded" with fewer images than expected. | Warning B000 with failed sub-operation count above zero. | Sub-operations complete, one or more failures. A partial retrieval reported as a warning. If your code treats anything that is not a failure as success, you have silently delivered incomplete studies to a reading workstation. |
| A701 | Query fails before any match is returned. | C-MOVE or C-FIND status A701. | Out of resources, unable to calculate number of matches. The query is too broad for the archive to plan. Constrain by date range and level rather than retrying. |
| Empty worklist | The device shows no scheduled procedures, but orders exist. | Capture the device's actual C-FIND request from the wire. | A required matching key does not match: Scheduled Station AE Title (single-value matching only), the start date range format, or the Modality code. Devices often send an AE title that differs from their calling AE title, and the fix is in the order feed, not the network. |
| Wrong patient | A study is filed under another patient's name. | Look for MPPS reason 110514 and for a coercion warning at ingest. | An incorrect worklist entry was selected at the console. This is an identity-safety event: reject the objects through the change-management path, correct, propagate to everything that already received them, and count it. It is never a support-desk edit. |
| Never completes | Study sits at "in progress" forever; the reading queue never receives it. | Compare arrival timestamps of the last series against your completeness rule. | No MPPS COMPLETED arrived and the quiet timer never expired because a trickle of objects kept resetting it, or a reconstruction landed after the window closed. Completeness must be a stated rule per modality, with premature and stalled completion both alarmed. |
| Transfer stalls | Transfers stop mid-study and never resume. | Check the association timeout and the sender's queue depth. | The association hit an inactivity timeout, or the device's outbound queue was purged on reboot. Devices are not durable queues. If your architecture assumes the modality will retry, verify that assumption per device before you depend on it. |
| TLS handshake | Connection resets during handshake on the secure port. | openssl s_client -connect host:2762 | Certificate chain, trusted CA, hostname mismatch, or an expired certificate. On appliances, a wrong clock also breaks validity checks — which is one more reason step 4 of commissioning is not optional. |
| Black images | Objects arrive and index correctly; the viewer shows black or inverted. | Inspect transfer syntax, Photometric Interpretation, and the window attributes. | The viewer cannot decode that transfer syntax, or window centre and width are absent and its default is wrong, or MONOCHROME1 is being rendered as MONOCHROME2. This is a rendering fault, not a transfer fault: the bytes are fine. |
| Priors missing | Current study loads; the comparison does not. | Check the patient identifier and issuer on both studies, then the storage tier. | Either identity (the prior is under a different identifier or issuer and was never linked) or economics (the prior is in an archive tier whose retrieval latency exceeds the reader's patience). Both look identical to the radiologist and have completely different fixes. |
| Duplicate studies | Two identical studies with the same Study Instance UID. | Compare arrival paths and source AE titles. | Two gateways or two routing rules sent the same objects. Idempotency at ingest must be keyed on SOP Instance UID; if it is keyed on filename or arrival order, duplicates are inevitable. |
| Split studies | One acquisition appears as two studies for the same patient and time. | Compare Study Instance UIDs and acquisition times. | The device regenerated the Study Instance UID on resend, or two devices contributed to one procedure. This one requires a merge with an audit trail, not a delete-and-resend. |
| Audit disorder | Events appear out of order across systems; corrections seem to precede the errors. | Compare timestamps across three nodes for one known transaction. | Clock skew. The IHE Consistent Time target is a median error under one second. Without it, no incident reconstruction and no "which write won" question can be answered. |
| Commitment silence | Storage commitment requests are sent and nothing ever comes back. | Check whether the SCP can open an association back to the SCU. | The N-EVENT-REPORT arrives on a separate association from the SCP to the SCU, so it needs its own firewall path and a listener. Silence is not success: without the notification you have no evidence the archive accepted responsibility. |
| Commitment 0110 / 0112 | Commitment returns a failure list. | Read the failure reason per instance. | 0110 processing failure, 0112 no such SOP instance, 0119 class/instance conflict, 0122 referenced SOP class not supported, 0131 duplicate transaction UID, 0213 resource limitation. 0112 in particular means the archive never received what you think you sent. |
| Preliminary forever | The report is signed but the EHR still shows it as preliminary. | Inspect OBR-25 and OBX-11 on the outbound message. | The result status never advanced to F. HL7 v2 table 0123 defines P preliminary, F final, C corrected final, M corrected not final, X order cancelled; table 0085 adds A amended, C correction, W wrong patient, and U status change to final without retransmission. Sending an addendum with the original status is the most common variant of this bug. |
| Delivery blackhole | Reports leave your system and the site says they never arrived. | Check the acknowledgement, not the send. | An interface that logs "sent" without checking the application acknowledgement will lose messages silently for months. Every delivery channel needs a positive receipt and an unacknowledged-message queue with an age alarm. |
No row matches that. Try a status code (A801), a keyword (worklist, coercion, TLS), or clear the filter.
The five commands worth memorising
DCMTK 3.6 syntax, verified against the tool documentation. These are diagnostics, not a production integration path.
# 1. Is anything listening, and does it accept my AE title?
echoscu -v -aet MY_AE -aec THEIR_AE 10.20.30.40 11112
# 2. What does the worklist actually return for the keys the device sends?
# Sequence keys use the path syntax: (0040,0100)[0].Attribute
findscu -v -W -aet MY_AE -aec THEIR_AE 10.20.30.40 11112 \
-k "(0040,0100)[0].Modality=CT" \
-k "(0040,0100)[0].ScheduledStationAETitle=CT_SCANNER_1" \
-k "(0040,0100)[0].ScheduledProcedureStepStartDate=20260905" \
-k "PatientName=" -k "PatientID=" -k "AccessionNumber="
# 3. Send a real study and watch every status code come back
storescu -v --scan-directories --recurse -aet MY_AE -aec THEIR_AE \
10.20.30.40 11112 /studies/case-0001/
# 4. Pull a study back to a named destination (A801 lives here)
movescu -v --study --move DEST_AE --port 11113 -aet MY_AE -aec THEIR_AE \
10.20.30.40 11112 -k "QueryRetrieveLevel=STUDY" \
-k "StudyInstanceUID=1.2.840.113619.2.55.3.12345"
# 5. Is the TLS problem the certificate, the chain, or the clock?
openssl s_client -connect 10.20.30.40:2762 -showcerts < /dev/null
04 The exception desk
Every imaging platform runs a human loop that nobody put in the architecture diagram. Its throughput determines how many studies reach a radiologist, and its authority limits determine whether a support agent can quietly destroy a clinical record. Design it deliberately or inherit it by accident.
The queues, and what each one is really measuring
| Queue | Enters when | Resolved by | Ages badly because |
|---|---|---|---|
| Unmatched study | Images arrive with no corresponding order or worklist entry. | Match to an order, or create an unscheduled case with a documented identity source. | The study is invisible to the reading queue while it waits. This queue's age is undiagnosed patient time. |
| Orphan order | An order exists and no images arrived within the expected window. | Confirm cancellation (often MPPS 110507), or chase the site. | Silence looks identical to a cancelled exam and a failed gateway. Without this queue, a site whose connectivity died on Friday is discovered on Monday. |
| Demographic mismatch | Study identity disagrees with the order's on name, identifier, date of birth, or accession. | Reconcile against the declared source of truth, or reject and correct. | Reading a study filed under the wrong identity is the highest-severity failure this platform can produce. |
| Duplicate / split | Same Study Instance UID twice, or one procedure under two UIDs. | Deduplicate on SOP Instance UID; merge with an audit record. | A split study means the radiologist sees half the exam and does not know it. |
| Incomplete study | Completeness rule not satisfied within its window. | Chase the missing series, or release as partial with an explicit flag. | Silently releasing an incomplete study is worse than holding it, and holding it forever is worse than releasing a flagged partial. |
| Failed ingest | Non-zero C-STORE status, transcode failure, or validation rejection. | Fix and re-send, with the original object retained. | Retry loops delete the evidence. Failed-ingest items must be immutable until a human closes them. |
| Stalled delivery | Report sent, no application acknowledgement received. | Re-deliver, or fall back to a secondary channel. | The report exists, the clinician does not have it, and every dashboard shows green. |
| Past turnaround | An assigned study exceeds its target read time. | Reassign, escalate, or renegotiate the target. | This is the queue customers see. It is also the one most often gamed by redefining when the clock starts. |
| Correction propagation | An identity or content correction has been made and one or more downstream recipients have not been updated. | Re-issue to every recipient, with confirmation. | A corrected record upstream and an uncorrected copy downstream is a worse state than the original error, because now two systems disagree and both look authoritative. |
| Automated-analysis failure | An AI or post-processing job errored, timed out, or produced an unusable result. | Re-run, or mark unavailable for that study. | A quietly missing result reads as a negative finding to anyone who assumed the tool ran. |
Authority limits: who may do what
The reason to write this down is not process hygiene. It is that "support can merge patients" and "support cannot merge patients" are two different products with different risk profiles, and most organisations have never decided which one they are.
| Action | Support tier 1 | Imaging operations | Engineering | Requires clinical sign-off |
|---|---|---|---|---|
| Read study metadata, view audit history | Yes | Yes | Yes | No |
| Re-send a report to a configured destination | Yes | Yes | Yes | No |
| Re-queue a failed ingest or delivery | Yes | Yes | Yes | No |
| Correct a typographic demographic error on an unread study | No | Yes | Yes | No |
| Reassign a study to another radiologist | No | Yes | Yes | No |
| Merge two patient records | No | Yes, dual control | No | Yes |
| Move a study between patients (wrong-patient correction) | No | Yes, dual control | No | Yes |
| Reject or retire imaging objects | No | Yes, dual control | No | Yes |
| Amend or retract a signed report | No | No | No | Yes, radiologist only |
| Delete imaging objects permanently | No | No | No | Policy exception, named approver, recorded |
| Direct database edit | No | No | Break-glass only, recorded and reviewed | Yes |
05 Degraded operations
Imaging degrades in pieces. The archive can be down while acquisition continues; reporting can be up while delivery is dead. A single "system down" runbook is useless because the correct human behaviour differs completely per component, and the expensive part is almost never the outage — it is the catch-up.
Failure modes and the manual fallback
| What is down | Still works | Manual fallback | Catch-up work created |
|---|---|---|---|
| Upstream link at one site | Acquisition, local review on the modality, the gateway's buffer. | Keep scanning. The gateway buffers and forwards on reconnection. Urgent cases go by a pre-agreed alternate route. | A burst on reconnection that can exceed the ingest rate. Size the buffer in hours and rate-limit the drain, or the recovery causes the next incident. |
| Ingest pipeline | Acquisition, existing archive reads, reporting on already-ingested studies. | Modalities hold and retry — but only those that actually queue. Confirm per device rather than assuming. | Reconciliation of anything that retried into a partially-processed state. Idempotency on SOP Instance UID is what makes this survivable. |
| Archive / repository | Acquisition and buffering. Nothing downstream. | Full downtime procedure: paper or local-worklist tracking, hand-carried media for urgent cases. | Every study acquired during the window has to be ingested and reconciled, in order, with duplicates detected. This is the most expensive catch-up in the list. |
| Metadata index (objects intact) | Objects are safe; nothing is findable. | Treat as a full archive outage for users. | Index rebuild time, which almost nobody has measured at production object counts. Measure it, then decide whether that number is acceptable, because it is your true recovery time. |
| Worklist / order feed | Everything except scheduled acquisition. | Technologists type identity at the console. | Every typed study becomes an unscheduled case needing reconciliation, and typed identity is the leading cause of demographic mismatch. Expect the exception desk load to spike for days, not hours. |
| Diagnostic viewer | Ingest, archive, reporting engine. | Fall back to the secondary viewer, if you have licensed and tested one. Most organisations discover here that they have not. | Little data catch-up, large turnaround-time debt. This is the outage that most damages the customer relationship per minute. |
| Reporting / dictation | Everything up to interpretation. | Dictate to an offline recorder or type into a plain document, then transcribe in. | Reports created outside the system must be reconciled to the correct study and re-issued through the normal delivery path with the correct status. |
| Report delivery | Everything. Reports are signed and correct, and nobody receives them. | Phone and secondary channel for anything urgent; hold the rest in the retry queue. | Bulk re-delivery, with duplicate suppression at the recipient, and correct result status so a re-send is not read as a new finding. |
| Identity source (EHR / PIMS) | Imaging, in isolation. | Local identifiers, quarantined for later reconciliation. | The hardest catch-up of all: locally-created identities must be merged against the authoritative source afterwards, and merges are irreversible in practice. |
| Automated analysis | Everything else. | Read without it, explicitly. | Almost none — provided the absence is visible. The danger is a workflow where "no finding shown" and "the tool did not run" look the same. |
The downtime kit
- A printed contact tree that does not depend on the systems that are down, including the site contacts.
- The current site and device inventory, offline: AE titles, IPs, ports, owners.
- A stated read-only mode, if the platform has one, and the exact conditions for entering and leaving it.
- The urgent-case alternate route, agreed with each site in advance and tested, not invented during the incident.
- A downtime log template: what was acquired, when, by whom, under which identity.
- The catch-up order of operations, written down before it is needed.
- Named authority to declare downtime and to declare it over. These are different decisions and both are frequently nobody's.
Catch-up, in order
- Stop new work into the affected path before draining, or you will chase a moving target.
- Ingest the backlog with rate limiting, oldest first, so turnaround clocks recover in the order patients waited.
- Deduplicate on SOP Instance UID before anything is assigned for reading.
- Reconcile identity for everything acquired without a worklist, against the authoritative source, before release.
- Release to the reading queue only after completeness is confirmed per study.
- Re-deliver reports, with correct status codes so a re-send is not mistaken for a new or corrected result.
- Reconcile the downtime log against the system: anything in the log with no matching study is the incident's real damage.
- Record the actual recovery time against the target, and correct the target if reality disagrees with it.
06 Service levels that survive contact with a customer
Most imaging service levels are written as a single availability percentage, which is the one number that can be simultaneously true and useless. The read path and the write path fail independently; a platform that accepts studies perfectly while nobody can open one is at 100% by that measure.
The indicator menu
| Indicator | Measured from → to | Anchor target | Why this boundary |
|---|---|---|---|
| Ingest acceptance | Association close at the gateway → object durably stored and indexed. | p95 under 2 min | Measured from the archive's own receipt, it hides gateway queueing, which is where backlogs actually live. |
| Study availability | Last instance received → study visible and openable in the worklist. | p95 under 5 min | This is the customer's definition of "the study is here". Index lag lives entirely inside it. |
| Completeness detection | Last instance received → study marked complete. | Stated per modality | Not a performance metric but a correctness one: publish the value per modality so nobody has to guess whether an exam is finished. |
| Hot retrieval | Viewer request → first image rendered, current study. | p95 under 2 s | Server-side time alone excludes the decode and the network, which is most of what the radiologist experiences. |
| Prior retrieval | Request → prior displayable, from the tier it really lives in. | p95 under 10 s | The quiet killer. If priors come from an archive tier, this number is set by your storage-class choice, not your code. |
| Worklist availability | Successful worklist load, measured by synthetic probe. | 99.9% monthly | Separate from the archive. Radiologists cannot start work without it even when every image is retrievable. |
| Report delivery | Signature → positive acknowledgement from each destination. | 99.5% within 15 min | Acknowledgement, not transmission. Anything measured at send-time cannot detect a black hole. |
| Exception queue age | Item created → item resolved. | p95 under one shift | The only indicator that measures the human loop. Without it, understaffing the desk is invisible on every dashboard. |
| Correction propagation | Correction applied → all downstream recipients confirmed updated. | p95 under 1 hour | Measures the state nobody watches: upstream fixed, downstream stale. |
| Turnaround time | Defined event → report signed. See the trap below. | Per priority class | The headline clinical metric and the most contested definition on this page. |
What suppliers will rarely sign, and the substitute
- End-to-end turnaround when they do not control acquisition or reading. Substitute: their segment, measured at their boundary, with the boundary named.
- Prior retrieval latency from archive tiers. Substitute: a published latency per storage class plus a maximum, with the retrieval fee stated.
- Index rebuild time. Substitute: a tested figure at your object count, refreshed annually, in writing.
- Bulk export throughput. Substitute: objects per hour achieved in a real customer migration, with the per-object charge named. A supplier who cannot produce one has never migrated a customer out.
- Correctness of any kind. Nobody signs a defect-rate SLA. Substitute: severity definitions, response times per severity, and a root-cause commitment with a deadline.
Remedies that mean something
- Service credits are compensation, not remedy. A month of credits does not restore a week of turnaround debt.
- Tie repeated breach to a termination right and to data egress on defined terms, which is the only leverage that survives a bad relationship.
- Require a root-cause analysis with a deadline for each severity-1 event, delivered whether or not credits apply.
- Require notice of maintenance windows in the customer's local time, and count unannounced maintenance as unplanned downtime.
- Make the measurement method contractual, including the probe location. Two honest parties measuring at different boundaries will disagree forever.
07 What five years actually costs
Storage price per gigabyte is the number everyone models and the one that decides least. This section is a working model with the arithmetic exposed, so you can put your own measurements in and get a defensible answer out — and then discover, as the worked example does, that the storage bill is a rounding error next to the people.
Rates, dated and sourced
| Line | Rate | Operational note |
|---|---|---|
| Hot storage (S3 Standard, first 50 TB) | $0.023 / GB-month | Where the current-study working set must live. |
| Archive storage (Glacier Instant Retrieval) | $0.004 / GB-month | Millisecond retrieval, but with a per-GB retrieval fee and a 90-day minimum storage duration. Correct or delete an object inside 90 days and you still pay the balance. |
| Archive data retrieval | $0.03 / GB | Seven and a half times the monthly storage rate. Retrieve an object once a month and the tier is costing you money, not saving it. |
| Write requests (PUT/COPY/POST/LIST) | $0.005 / 1,000 | Charged per object, so this line scales with instance count. A thin-slice CT study can be thousands of PUTs. |
| Read requests (GET) | $0.0004 / 1,000 | Small per request, large across a prior-fetch workload measured in instances. |
| Egress to internet (first 10 TB/month) | $0.09 / GB | Applies to browser-based viewing and to the day you leave. Both. |
| Other minimum durations | 30 / 90 / 180 days | Standard-IA 30, Glacier Flexible 90, Deep Archive 180. Early-deletion penalties interact badly with correction and retention workflows. |
The model
Month m from 0 to 59. Studies grow geometrically. Data accumulates with no expiry inside the window when retention exceeds five years. Objects newer than the hot window sit in hot storage, everything older in the archive tier, and each is stored r times. Writes are charged per instance per replica; reads and archive retrievals are charged against the studies actually retrieved.
Values persist in this browser only.
The worked example, all the way to a number
Using the defaults above — 12,000 studies a month growing 12% a year, 120 MB and 900 instances per study, two copies, three months hot then Glacier Instant Retrieval, 3% of the archive retrieved monthly with 60% of that egressed, and 3.5 FTE at $135,000 loaded:
- 964,095 studies ingested over the five years, reaching 20,949 studies a month by month 60.
- 110.3 TB of unique data at month 60, held twice.
- Storage capacity across both tiers and both copies: $37,621.
- Write requests: $8,677 — 16% of the infrastructure bill, and entirely a function of instance count. Halve the instances per study and this line halves; halve the gigabytes and it does not move.
- Read requests $288, archive retrieval fees $2,516, egress to viewers $5,067.
- Infrastructure subtotal: $54,170 for five years, or $0.056 per study.
- Operations staffing: $2,362,500.
- Five-year total: $2,416,670, which is $2.51 per study — and 97.8% of it is people.
- Leaving at the end of year five costs $10,168 in egress alone, before anyone writes migration code. That single one-time line is 19% of everything you spent on infrastructure in five years.
08 Operating models and who is actually responsible
The sourcing decision picks components. The operating model decides who answers the phone at 03:00, and those are different questions with different answers. A team can buy every component and still own every operational obligation on this page.
| Obligation | Software platform only | Hosted PACS | Teleradiology service | Embedded in an EHR / PIMS | Platform + outsourced operations |
|---|---|---|---|---|---|
| Modality commissioning | Site | Split | You | Split | Sup |
| Gateway health and buffering | Site | You | You | You | Sup |
| Identity source of truth | Site | Site | Split | Host system | Site |
| Exception desk | Site | Split | You | Split | Sup, to your standard |
| Wrong-patient correction | Site | Split | You | Split | Split — never fully delegate |
| Study completeness rule | You | You | You | You | You |
| Turnaround-time commitment | None | None | You | None | Split |
| Critical-result communication | Site | Site | You | Site | You |
| Diagnostic viewing conditions | Site | Site | You | Site | You |
| Retention and legal hold | Site | Split | Split | Host system | You |
| 24-hour technical support | You | You | You | Split | Sup |
| Downtime declaration | Site | You | You | Split | You |
| Archive integrity and recovery | Site | You | You | You | Split — you must be able to verify |
| Bulk export on exit | You | You | You | You | You, contractually |
The three rows that decide the model
- Wrong-patient correction. Whoever holds this holds clinical risk. It is the one obligation that should never be wholly outsourced, whatever the contract says, because you cannot delegate the consequence.
- Downtime declaration. If nobody is named, the answer during an incident is "everyone, eventually, after an hour of discussion".
- Bulk export. The only row that is identical in every column. If you cannot get your objects out at a demonstrated rate, the operating model is decorative.
Delegation tests before signing an operations partner
- Can you observe their queues directly, or only their monthly report? A partner you can only audit retrospectively is a partner you cannot manage.
- Do they operate to your written authority matrix, including dual control on merges?
- Whose audit trail records their actions — yours, or theirs?
- What happens to in-flight exceptions on the day the contract ends?
- Can you take the function back in-house within one notice period, and have you written down how?
09 Human and veterinary operations are not the same job
The standard is shared; almost nothing about running the service is. Veterinary imaging is not human imaging with looser rules, and treating it as a configuration flag on a human platform produces a system that is wrong in both directions.
| Dimension | Human health | Veterinary | What it changes operationally |
|---|---|---|---|
| Who the patient is | The person, with a durable identifier issued by an assigning authority. | The animal, usually identified through its owner and clinic. Patient's Name (0010,0010) frequently carries an owner-plus-animal convention with no standard form. | Deduplication and prior-matching cannot rely on a stable identifier. Two clinics in the same group will encode "Rex Alvarez" three different ways. |
| Extra required attributes | None specific. | Patient Species Description (0010,2201) and Code Sequence (0010,2202); Patient Breed Description (0010,2292) and Code Sequence (0010,2293); Breed Registration Sequence (0010,2294). | Species is clinically load-bearing: it drives reference ranges, hanging protocols, and which radiologist can read the case. If it arrives as free text, it will arrive as free text forever. |
| Decision-maker | The patient or a legal representative. | Responsible Person (0010,2297), Responsible Person Role (0010,2298) with defined terms including OWNER and VETERINARIAN, and Responsible Organization (0010,2299). | Report delivery and consent route to a party the standard models explicitly. Ignoring these attributes means rebuilding them badly in your own schema. |
| Ordering context | EHR order with an accession number, an ordering provider, and an encounter. | A PIMS request, or often a consultation request with no order at all. | Where there is no order, every study is an unscheduled case and the exception desk is the primary workflow rather than the fallback. |
| Species range | One. | Small animal, equine, exotic, production animal — different body parts, positioning, sizes, and reading expertise. | Routing rules keyed on Modality and body part are insufficient. Equine distal limb and feline thorax are different services sharing one SOP Class. |
| Retention | US hospitals: at least 5 years (42 CFR 482.24(b)(1)). Mammography: the longest of 5 years, 10 years absent further mammograms, or the state period (21 CFR 900.12(c)(4)). | Set by state veterinary practice acts and board rules, which vary substantially by state and are not harmonised with human rules. | Retention becomes per-jurisdiction configuration, not a global constant. Get it in writing from the customer, per state. |
| Privacy regime | HIPAA and equivalents apply to protected health information. | Animal records are generally not protected health information; owner contact details are still personal data under general privacy law. | Do not claim HIPAA where it does not apply, and do not assume the absence of HIPAA means the absence of obligations. The owner's data is still regulated. |
| Who reads | Credentialled radiologists, with privileges by facility. | Board-certified veterinary radiologists, in a much smaller pool, often reading across many clinics. | Assignment, capacity planning, and after-hours cover are constrained by a scarce reader pool. Queue design matters more than in a large human practice. |
| Who pays and who receives | Payer, provider, and patient are distinct parties. | The clinic is the customer, the owner is the payer, and the referring veterinarian may be a third party. | Report distribution has three audiences with different needs, and the portal you build for the owner is a different product from the one you build for the clinic. |
10 The operations readiness memo
A fill-in artefact for the review before go-live, or the one you should have run before signing. Every blank is a question this page argues you cannot leave open. Edit it here and copy it out; it saves in this browser only.
11 Common mistakes and anti-patterns
Fourteen failures that are operational rather than architectural. Each one has a healthy-looking architecture diagram behind it.
1 — Treating a green dashboard as evidence the clinical path works
Component health checks answer "is the process running". They do not answer "can a radiologist open today's chest CT with its priors". Run a synthetic transaction end to end on a schedule: push a known study, retrieve it, render it headlessly, generate and deliver a report to a test destination, and alarm on the whole path. Every incident in this page's tables is invisible to component-level monitoring.
2 — A retry loop that deletes the failing object
Cxxx and A9xx failures are diagnosable only from the artefact. A pipeline that retries three times and drops the object has converted a solvable vendor ticket into an unreproducible anecdote. Quarantine failed objects immutably, subject to your retention and privacy rules, and make the quarantine a queue with an owner.
3 — Assuming the modality is a durable queue
Some devices retry indefinitely, some hold a shallow queue, some drop everything on reboot. Which one each of your devices is, is a fact you can only learn by pulling the link during commissioning (step 13). Architectures that assume "the modality will resend" fail silently on the devices that will not.
4 — Silent attribute coercion
Status B000 means the receiver rewrote your data. Coercion is sometimes correct policy, but undocumented coercion means an incorrectly-selected worklist entry is written into the permanent record with no trace of what the device actually sent. If you coerce, log every changed attribute with both values; if you do not, alarm on B000.
5 — Support tooling with production-grade destructive power
See the authority matrix in Table 4.2. Merges, moves, rejections, and deletions belong behind dual control with a named second approver. A tier 1 agent should be able to see nearly everything and change almost nothing.
6 — A completeness rule that is a timeout nobody wrote down
The value exists — it is in someone's configuration file. If it is not published per modality, then changing it silently changes turnaround-time reporting, the rate of incomplete reads, and your headline service level, all at once and without a change record.
7 — Measuring delivery at send time
An interface that logs "message transmitted" and never inspects the acknowledgement will lose reports for months while every dashboard stays green. Every delivery channel needs positive receipt and an unacknowledged queue with an age alarm. This is the single most common way a correct report fails to reach a clinician.
8 — Correcting upstream and forgetting downstream
A corrected identity in your archive plus an uncorrected copy in the EHR, the portal, the referring practice's system, and last night's export is worse than the original error: two systems now disagree and both appear authoritative. Correction is not complete until propagation is confirmed, which requires knowing every place a study or report has been.
9 — Testing recovery on a sample dataset
The procedure validates; the durations do not. Index rebuild time at production object count, bulk ingest rate during a drain, and per-object archive retrieval fees are the three numbers that decide your real recovery time, and all three are commonly first measured during the incident.
10 — One availability number for the whole platform
Ingest, worklist, current-study retrieval, prior retrieval, reporting, and delivery fail independently. A single monthly percentage can report 99.95% through two working days in which priors were effectively unavailable. Publish availability per path.
11 — Tiering storage on the per-gigabyte rate
Archive classes carry per-GB retrieval fees and minimum storage durations (90 days for Glacier Instant Retrieval and Flexible, 180 for Deep Archive, 30 for Standard-IA). An object read once a month costs more to retrieve than to store, and an object corrected at day 30 is billed for 90. Tier on read frequency and mutability, then check the price.
12 — No exit-cost line in the business case
In the worked example, egress alone to leave at year five is $10,168 — 19% of five years of infrastructure spend, one-time, before any migration engineering. Suppliers know this number. Model it on day one, because it is also what determines your negotiating position at renewal.
13 — Discontinuation reasons captured and never routed
CID 9301 hands you an incorrect-worklist-selection event (110514), an equipment-failure trend (110501), and a deceased-patient signal (110504) for free. A platform that stores all nineteen codes identically has the evidence and acts on none of it.
14 — Staffing a queue instead of fixing its cause
An exception queue whose depth is stable is not under control; it is in equilibrium with the rate of a defect you are paying people to absorb. Review monthly by cause, and convert the top cause into a configuration or product change. In the worked cost model, one FTE of avoided exception work outweighs the entire five-year infrastructure bill more than twelvefold.
12 Operations glossary
Terms used here in a specific operational sense. Protocol and architecture vocabulary lives in the atlas glossary; this list does not repeat it.
| Term | Meaning on this page |
|---|---|
| Association reject | A refusal before any data is exchanged, carrying result, source, and reason fields (PS3.8 9.3.4). Distinct from a DIMSE status, which is returned after a service request is accepted. |
| Bring-up | The commissioning sequence for one device or site, from identity allocation to confirmed end-to-end delivery. |
| Catch-up | Work created by an outage after service is restored: backlog ingest, deduplication, identity reconciliation, and re-delivery. Usually longer than the outage. |
| Coercion | The receiver rewriting attributes of an object it stores, reported as C-STORE warning B000. Frequently identity attributes taken from the receiver's own worklist. |
| Completeness rule | The written, per-modality definition of when a study is considered finished and may be released for reading. Three mechanisms exist and each fails differently. |
| Downtime kit | The offline artefacts an incident needs: contact tree, device inventory, alternate urgent route, downtime log, and named declaration authority. |
| Dual control | A destructive action requiring two named people, both recorded. Applied here to merges, moves between patients, rejections, and deletions. |
| Exception desk | The human loop that resolves studies the automated path cannot: unmatched, mismatched, duplicated, incomplete, undelivered. |
| Exit cost | The one-time cost of removing your data from a platform: egress, per-object retrieval, engineering, and dual-run time. Distinct from the licence you stop paying. |
| Hot window | How long after acquisition an object stays in immediate-access storage before moving to an archive class. A workflow decision constrained by prior-read frequency. |
| Instance count | Number of SOP Instances, as distinct from bytes. The variable that drives per-object charges, index writes, queue depth, and migration wall-clock. |
| Minimum storage duration | The billing floor of an archive storage class (30, 90, or 180 days). Objects deleted or moved earlier are still charged for the balance. |
| Orphan order | An order with no images inside the expected window. The queue that detects a site whose connectivity failed. |
| Propagation | Pushing a correction to every downstream system that already received the incorrect record, and confirming each one. |
| Quiet timer | The fallback completeness mechanism: no new object for n minutes means done. A guess with a clinical consequence in both directions. |
| Read path / write path | Retrieval and display versus ingestion and storage. They fail independently and deserve separate service levels. |
| Site survey | The written record of a site's network, devices, identity sources, people, and inherited obligations, collected before configuration begins. |
| Synthetic transaction | A scheduled end-to-end probe: push, retrieve, render, report, deliver. The only monitoring that fails when the clinical path fails. |
13 Sources
Every code, rate, and legal figure on this page traces to one of these. Standards editions and published prices move; the rate table in section 7 will go stale first.
DICOM, current edition (PS3, 2026c)
- PS3.4 Table B.2-1 — Storage Service Class status values (A7xx, A9xx, Cxxx, B000, B006, B007).
- PS3.4 Section C.4.2 — C-MOVE response statuses (A701, A702, A801, A900, B000, FE00, FF00).
- PS3.4 Table K.6-1 — Modality Worklist matching keys.
- PS3.4 Annex J — Storage Commitment Push Model (N-ACTION and N-EVENT-REPORT).
- PS3.3 Section C.14 — Storage commitment failure reasons (0110, 0112, 0119, 0122, 0131, 0213).
- PS3.3 Section C.7 — Patient module, including species, breed, and responsible-person attributes.
- PS3.7 Annex C — status class conventions (Axxx, Bxxx, Cxxx, FE00, FF00).
- PS3.8 Section 9.3.4 — A-ASSOCIATE-RJ result, source, and reason values.
- PS3.16 CID 9301 — Modality PPS Discontinuation Reason; CID 9300 for the general procedure set.
Integration profiles, regulation, and rates
- IHE IT Infrastructure Technical Framework Volume 1 — Consistent Time (CT) profile, median error under one second over NTP.
- 45 CFR §164.308(a)(7) — HIPAA Security Rule contingency plan standard.
- 42 CFR §482.24(b)(1) — hospital medical record retention, at least five years.
- 21 CFR §900.12(c)(4) — MQSA mammography record retention.
- HL7 v2 table 0123 — Result Status; table 0085 — Observation Result Status.
- IANA Service Name and Transport Protocol Port Number Registry — acr-nema 104, dicom-iscl 2761, dicom-tls 2762, dicom 11112.
- Amazon S3 pricing, US East (N. Virginia), retrieved September 2026, for the rates and minimum storage durations in Table 7.1.
- DCMTK 3.6 tool documentation for
echoscu,findscu,storescu, andmovescuoption syntax, including the sequence path form(0040,0100)[0].Attribute. - Joint Commission National Patient Safety Goal NPSG.02.03.01 requires accredited organisations to define in writing who reports critical results to whom and within what interval, and to evaluate timeliness. Numbering differs between accreditation programmes and has moved; verify against the manual for your programme.