Monday, October 5, 2026
Home » What Storage Should Hospitals Use for PACS and VNA Archives?

What Storage Should Hospitals Use for PACS and VNA Archives?

PACS and VNA storage is one of the largest and fastest-growing infrastructure commitments in any hospital or health system. Every CT, MRI, ultrasound, X-ray, mammogram and digital pathology slide lands in an image archive that clinicians expect to open in seconds, sometimes decades after the study was taken. At the same time, imaging archives are prime ransomware targets, subject to long retention rules and growing every year as modalities produce larger studies.

This article explains how imaging archives are typically structured, what the storage underneath has to deliver, and how hospitals evaluate options as they consolidate PACS and VNA platforms. It is written for PACS administrators, imaging informatics teams and hospital infrastructure architects.

How imaging archives are structured

Most hospitals have some combination of three layers:

  • PACS (picture archiving and communication system) handles day-to-day reading and clinical workflow for a department, typically radiology or cardiology. It includes viewers, worklists and a short-term cache of recent studies.
  • VNA (vendor neutral archive) consolidates long-term storage for images from multiple PACS, departments and sometimes multiple hospitals, using standard formats such as DICOM and interfaces that are not tied to one viewer vendor.
  • Enterprise imaging platforms extend the archive to non-DICOM content such as photos, videos, endoscopy and pathology images, and connect it to the electronic health record.

Underneath each layer sits storage. Historically, each PACS came with its own storage, often a dedicated array per department. Consolidation onto a VNA and a shared storage platform is now common. The differences are covered in PACS vs VNA: what changes for the storage team.

What imaging storage has to deliver

Fast access to recent and prior studies

Radiologists compare new studies with prior ones. When a patient arrives, the PACS often pre-fetches relevant priors from the long-term archive. If the archive is slow, reading is delayed. Storage must deliver fast retrieval for recent studies and acceptable retrieval for older ones, typically seconds rather than minutes.

Very large and growing capacity

Imaging volumes grow every year as more studies are performed and newer modalities produce larger datasets. Multi-slice CT, digital breast tomosynthesis and digital pathology in particular generate studies that can run to hundreds of megabytes or more each. Many health systems manage hundreds of terabytes to several petabytes of images.

Long retention

Images must be kept for years, often far longer than other IT data. In the United States, the Mammography Quality Standards Act regulations, for example, require original mammograms to be retained for at least five years, or ten years if the patient has no further mammograms at the facility, or longer if state law requires. Pediatric images are often kept until well after the patient reaches adulthood.

Integrity and durability

A diagnostic image must be exactly what was acquired. Storage should prevent silent corruption, verify data integrity over time and survive hardware failures without loss.

Security and privacy

Images are protected health information. HIPAA in the US, GDPR in Europe and national health data rules elsewhere require access control, audit logging, encryption and breach response.

Ransomware resilience and disaster recovery

Healthcare is one of the most targeted sectors for ransomware. An encrypted image archive can halt diagnostics across a hospital. Storage needs immutable copies, isolation from general IT credentials and a tested recovery plan.

Storage tiers for imaging

Imaging archives commonly use tiers:

  • Short-term or cache tier on fast storage within the PACS, holding recent studies for immediate reading.
  • Long-term archive tier in the VNA or PACS archive, holding all studies for the retention period.
  • Disaster recovery copy at a second site or in an isolated environment.

The long-term tier is where most capacity sits, and it is where the choice of storage technology matters most for cost and scale. The concepts behind tiering are explained in hot storage vs cold storage.

Storage options

Dedicated SAN or NAS per PACS

The traditional model gives each PACS its own array. It is simple for a single department but creates islands, repeated purchases and data migrations every time an array or PACS is replaced. Migrating years of images between PACS vendors is notoriously slow and expensive.

Shared NAS

Consolidating archives onto shared NAS reduces islands. NAS performs well for moderate capacities, but large imaging archives create very high file counts, scale-up arrays hit limits and hardware refresh still requires migration.

Object storage

Object storage scales out by adding nodes, handles billions of files, protects data with erasure coding and supports immutability through object lock. Many modern PACS, VNA and enterprise imaging platforms can write to S3-compatible object storage for their long-term archive, either natively or through a gateway.

Public cloud

Some health systems archive images in public cloud storage. Considerations include data residency, long-term cost as the archive grows, retrieval and egress charges when priors are fetched and the effort to move data out later. Many hospitals keep the primary archive on premises and use cloud or a second site for disaster recovery.

Consolidation: one archive, many applications

The main trend in imaging storage is consolidation. Instead of each department and PACS owning storage, a health system builds one archive platform that serves radiology, cardiology, pathology and other departments, often across multiple hospitals. Benefits include:

  • One place to apply retention, immutability and security policies.
  • Less duplication and better utilization.
  • Freedom to change PACS vendors without migrating the archive.
  • Simpler disaster recovery.

The general case for consolidating healthcare data silos is covered in how to consolidate the patchwork of data silos in healthcare.

Disaster recovery for imaging

A practical imaging DR design includes:

  • A second copy of the archive at another site, replicated continuously or nightly.
  • Immutable retention on at least one copy so ransomware cannot delete or encrypt it.
  • Separate administrative credentials for the archive storage.
  • A documented process to bring PACS or VNA back online against the DR copy.
  • Regular recovery tests with real studies.

The scality.com blog covers restore speed as the new RTO and ransomware recovery clean rooms, both relevant for imaging.

Integrating with the wider health IT estate

Imaging storage does not operate alone. The archive exchanges data with the electronic health record, referral portals, regional image-sharing networks and, increasingly, AI tools that analyze images for triage or quantification. Each of these adds access patterns: bulk reads for AI model validation, frequent small reads for portal viewing and inbound studies from other hospitals. A storage platform that exposes standard interfaces and scales throughput with capacity copes with these new consumers far better than one sized only for radiologist reading. It also helps to keep a clear inventory of which systems read the archive directly, since each one is affected when storage changes.

Cost over the life of the archive

Imaging archives outlive several generations of hardware and often more than one PACS vendor. Cost should be modeled over at least five to ten years, including capacity growth, protection overhead, power and space, refresh and migration. Avoiding migrations at hardware refresh, by using storage that can replace nodes in place, is one of the biggest long-term savings. object storage hardware refresh explains how that works. The healthcare retention cost picture is covered in the cost of health data retention.

Checklist: choosing PACS and VNA storage

  • Inventory every PACS, VNA and departmental archive and its storage.
  • Measure current capacity, annual growth and largest study types.
  • Confirm retrieval performance needs for priors and older studies.
  • Map retention requirements by study type and patient age.
  • Check which PACS and VNA products support S3-compatible storage.
  • Require integrity checking, encryption and audit logging.
  • Design immutable, isolated copies and a second-site DR plan.
  • Model cost over ten years, including refresh and migration.
  • Plan consolidation so PACS changes do not require archive migration.

Putting it together

The right PACS and VNA storage gives clinicians fast access to current and prior images, keeps every study intact for its full retention period, survives ransomware and hardware failure and grows without repeated migrations. For most health systems, that points to a consolidated long-term archive on scalable storage, with tiering for recent studies, immutable copies and a tested DR plan. Choose storage that will outlast the next PACS replacement, not just the current contract.

Frequently asked questions

What storage do hospitals use for PACS?

Hospitals use fast storage for recent studies within the PACS and larger, lower-cost storage for long-term archives. Increasingly, the long-term archive is consolidated on a VNA backed by scalable storage such as object storage.

Can PACS images be stored in the cloud?

Yes, if residency, security and cost requirements are met. Many hospitals keep the primary archive on premises and use cloud or a second site for DR.

How much storage does a hospital imaging archive need?

It varies widely with study volume and modality mix. Many health systems manage hundreds of terabytes to several petabytes, growing every year.

What is a VNA?

A vendor neutral archive consolidates images from multiple PACS and departments in standard formats so the archive is not tied to one viewer vendor.

How do hospitals protect imaging archives from ransomware?

With immutable copies, separate credentials, network isolation, a second-site copy and regular recovery tests.

Further reading