[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82879-en":3,"doc-seo-82879-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82879,8796095462418,"Noah","https://ap-avatar.wpscdn.com/avatar/80000253c1241d02b47?x-image-process=image/resize,m_fixed,w_180,h_180&k=1778826106357471780",8,"Research & Report","Measuring Healthcare Data Leaks and Security Flaws at Internet Scale","Medical data processing systems require careful protection, yet healthcare network services often miss fundamental security controls. Prior work showed DICOM network segmentation issues exposing millions of patient records. This study operates a low-interaction honeypot for medical protocols and performs large-scale Internet scans of HL7 and FHIR alongside expanded DICOM measurements. Scans across IPv4 and IPv6 identify healthcare systems, authentication-related data leaks, TLS configuration weaknesses, and insecure software. Findings include 2,841 services with authentication flaws and widespread lack of transport encryption, plus many known vulnerabilities, followed by coordinated responsible disclosure.","Measuring Healthcare Data Leaks and Security Flaws at Internet Scale  \nNico Br¨uggemann∗ , Lukas Schmidt†‡, Marvin Dlzer∗ , Marius Brockhoff ∗, Fabian Ising∗ ,  \nChristoph Saatjohann†‡, Sebastian Schinzel ∗†‡  \n∗ Fraunhofer SIT and National Research Center for Applied Cybersecurity ATHENE, Steinfurt, Germany  \n{nico.brueggemann, marvin.doelzer, marius.brockhoff, [fabian.ising](fabian.ising}@sit.fraunhofer.de)[}](fabian.ising}@sit.fraunhofer.de)[@sit.fraunhofer.de](fabian.ising}@sit.fraunhofer.de)[ ](fabian.ising}@sit.fraunhofer.de)†FH Mnster University of Applied Sciences, Steinfurt, Germany {lukas-schmidt, christoph.saatjohann, [schinzel](schinzel}@fh-muenster.de)[}](schinzel}@fh-muenster.de)[@fh-muenster.de](schinzel}@fh-muenster.de)  \n‡ Graduate School for Applied Research in North Rhine-Westphalia (Graduate School NRW), Bochum, Germany  \narXiv :2607 .04965v 1 [ cs .CR] 6 Jul 2026  \nAbstract—Systems that process medical data should be meticulously secured. Yet, network services in healthcare environments often fail to implement basic security measures. For example, previous studies showed that network segmentation flaws led to DICOM systems leaking millions of patient records.  \nIn addition to DICOM, healthcare facilities rely heavily on the HL7 and FHIR protocols to transmit data. For nine months, we operated a low-interaction honeypot for medical protocols. We found it was regularly scanned for DICOM but never for HL7 or FHIR, indicating that despite their widespread use and importance for patient data security, the security of these services remains underexplored.  \nIn this paper, we present the first large-scale study on HL7 and FHIR services and expand previous work on DICOM. Our large-scale Internet scans, covering the three major healthcare protocols across IPv4 and IPv6 address spaces, identify healthcare systems and uncover data leaks due to authentication flaws. Additionally, we scanned for deficiencies in TLS configurations of these services and known insecure healthcare software.  \nIn total, we found 2,841 healthcare services with authentication flaws. 94.4% of all exposed systems do not support transport encryption, and 1,373 systems have known software vulnerabilities, including those with potential for system takeover and CVSS scores up to 9.8. Overall, our study reveals an alarming state of cybersecurity in healthcare deployments, for which we discuss potential reasons and countermeasures. Finally, we report on the coordinated disclosure campaign we initiated to improve the security of patient data.  \nIndex Terms—FHIR, DICOM, HL7, Healthcare Protocols, Data Leaks, Internet Measurement, IPv6  \n1. Introduction  \nDigitalization has become ubiquitous in healthcare facilities such as hospitals and medical centers. However, the long life cycles of expensive medical devices have led to the widespread adoption of outdated network protocols. These protocols often fail to implement basic security features, such as authentication or encryption, and, to protect patient data, must not be exposed to the Internet.  \nNonetheless, previous studies have shown that patient data was publicly accessible due to simple network seg-  \nmentation flaws, e.g., on the Digital Imaging and Communications in Medicine (DICOM) network servers [1]–[6] . As a result, these studies revealed data leaks affecting millions of patients. The disclosure of these data leaks helped contain the exposure of particularly sensitive information, such as health status, medication, or Sexual Orientation and Gender Identity [7], whose public dissemination poses incalculable risks for affected persons.  \nNext to DICOM, which is primarily utilized for the transmission and storage of medical image data originating from X-rays or CTs, the HL7 and Fast Healthcare Interoperability Resource (FHIR) protocols are of utmost relevance in healthcare environments [8] . HL7 is used to control the Hospital Information System (HIS), which stores patient data, diagnoses, and ","cbCaipQiFJcPIPJL","https://ap.wps.com/l/cbCaipQiFJcPIPJL","pdf",1002223,2,1,19,"English","en",105,"# Introduction\n## Internet-scale healthcare protocol measurements\n# Key findings and scope\n## Authentication flaws and data exposure\n## TLS configuration and vulnerable software","[{\"question\":\"What security problems in healthcare networking does the study investigate?\",\"answer\":\"The study investigates data leaks and security flaws affecting healthcare protocol services, focusing on authentication weaknesses, missing or inadequate transport encryption, TLS misconfiguration, and known vulnerable software versions.\"},{\"question\":\"How did the researchers assess HL7 and FHIR security compared with DICOM?\",\"answer\":\"They conducted the first large-scale Internet study for publicly accessible HL7 and FHIR services and supplemented it with more thorough DICOM measurements, scanning both IPv4 and IPv6 address spaces.\"},{\"question\":\"What were the main outcomes of the large-scale scans?\",\"answer\":\"The researchers found 2,841 healthcare services with authentication flaws, observed that 94.4% of exposed systems did not support transport encryption, and identified 1,373 systems with known software vulnerabilities, some with high CVSS scores.\"}]",1784183627,48,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"measuring-healthcare-data-leaks-and-security-flaws-at-internet-scale","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/measuring-healthcare-data-leaks-and-security-flaws-at-internet-scale/82879/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-24","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What security problems in healthcare networking does the study investigate?","Question",{"text":75,"@type":76},"The study investigates data leaks and security flaws affecting healthcare protocol services, focusing on authentication weaknesses, missing or inadequate transport encryption, TLS misconfiguration, and known vulnerable software versions.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How did the researchers assess HL7 and FHIR security compared with DICOM?",{"text":80,"@type":76},"They conducted the first large-scale Internet study for publicly accessible HL7 and FHIR services and supplemented it with more thorough DICOM measurements, scanning both IPv4 and IPv6 address spaces.",{"name":82,"@type":73,"acceptedAnswer":83},"What were the main outcomes of the large-scale scans?",{"text":84,"@type":76},"The researchers found 2,841 healthcare services with authentication flaws, observed that 94.4% of exposed systems did not support transport encryption, and identified 1,373 systems with known software vulnerabilities, some with high CVSS scores.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":22,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},"General","general"]