Health IT can't move imaging to the cloud. Here's how to keep on-prem systems compliant.
Aug 20, 2026
Radiology imaging, EMR integration servers, and Active Directory are staying on-prem at most health systems, even as everything else moves to the cloud, and those systems still have to meet the same HIPAA bar as anything in the cloud. The HIPAA Breach Notification Rule presumes any impermissible use or disclosure of PHI is a breach unless a documented risk assessment shows otherwise, and that assessment depends on knowing exactly what changed on a given system and whether it was authorized. Native OS logs record events, not intent, which leaves most teams unable to answer that question quickly when it matters most.
Why some systems aren't going anywhere
Every health system is looking at the cloud right now. Storage costs less, scaling is easier, and vendors keep asking why the EMR isn't there yet. But walk into any radiology department and the answer is obvious: those imaging files are massive, and clinicians need them fast. Most hospitals already run a local cache at each site just to keep latency down for imaging. That workload isn't going anywhere.
The EMR is a harder call. Some organizations have migrated it to the cloud. Many haven't, because the integrations built around it (lab systems, pharmacy, scheduling, device interfaces) depend on low latency that a cloud-hosted EMR can't always guarantee when data has to round-trip in real time. Rip out an integration and you risk a clinician staring at a spinner during a live patient encounter.
And as long as core clinical systems stay on-prem, Active Directory stays too. It's the identity layer everything else authenticates against. Moving it before the rest of the environment is ready just adds risk without removing any.
Staying on-prem also means staying static isn't an option. There's no cloud vendor quietly patching the OS or hardening the config in the background. If a hospital keeps a system in-house, the entire lifecycle of keeping that system current and secure stays in-house too, and proving it's actually happening becomes the organization's job, not a vendor's.
So the practical reality for a lot of health IT teams: the cloud migration story is real, but it's partial. Radiology servers, EMR integration points, and AD are staying on-prem for the foreseeable future. And those systems still have to meet the same compliance bar as everything else.
What HIPAA expects when something goes wrong
The HIPAA Breach Notification Rule assumes the worst by default. If protected health information is used or disclosed in a way HIPAA doesn't permit, the law presumes that's a breach unless the organization can document a risk assessment showing a low probability the PHI was actually compromised. That assessment has to weigh things like what type of PHI was involved, who accessed it, whether it was actually viewed or acquired, and whether the risk was mitigated.
Once a breach is confirmed, the clock starts. Affected individuals need notice without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more people also require notice to HHS within 60 days, plus media notification in some cases. Smaller breaches get rolled into an annual report to HHS.
Here's the part that matters most for an on-prem radiology server or an EMR integration box: the organization has to be able to reconstruct what happened. Who touched the file. When. Whether the change was expected. Without that, the risk assessment defaults to "we don't know," and "we don't know" defaults to a reportable breach.
Logs alone won't hold up in an audit
On-prem systems change constantly: patches, config edits, new accounts, a vendor engineer remoting into a PACS interface at 2 a.m. to fix a print queue. Most of that is fine. Some of it isn't authorized at all, and native OS logs don't tell you which is which. They tell you a registry key changed. They don't tell you whether that change matched an approved ticket or came from someone who shouldn't have had access.
So when OCR or an auditor asks whether a specific EMR interface server was touched last quarter, the honest answer for a lot of teams is "we'd have to go check." That's not a good place to be standing when the clock on a breach determination is already running.
Building audit evidence without adding headcount
Netwrix Change Tracker gives health IT a way to hold the line on integrity for systems that have to stay on-prem, including the radiology servers, EMR integration points, and Active Directory infrastructure that aren't going anywhere.
It builds a known-good baseline for those systems, then watches file integrity and configuration state in real time on Windows, Linux, and the network devices between them. When something changes, whether it's a registry key, a config file, or a local account, Change Tracker checks it against approved Planned Changes. If it matches an approved change window, it's filed as expected activity. If it doesn't, it's flagged immediately, and IT knows in minutes instead of finding out during an audit or an incident review.
That means "we'd have to go check" turns into "here it is." The record already shows what changed, when, and whether it was authorized, and that's most of the work behind a defensible four-factor risk assessment.
Change Tracker also ships with more than 250 prebuilt compliance reports mapped to frameworks like HIPAA, NIST, and PCI DSS, so proving the control was in place doesn't mean building a report from scratch every audit cycle. The evidence is already structured the way an auditor expects to see it.
The cloud conversation in health IT isn't finished, and it shouldn't be. But the systems staying on-prem still have to prove they're under control. Change Tracker gives IT and compliance teams a way to do that without waiting for the rest of the infrastructure to catch up.
See how Change Tracker builds HIPAA-ready audit evidence.
Automated change detection, always on for on-prem systems.
Learn moreFAQs
Share on
Learn More
About the author
Dan Piazza
Manager of Product Management
Dan Piazza is a Manager of Product Management at Netwrix, responsible for multiple Endpoint, DSPM, and Directory products. He has worked in technical roles since 2013, with a passion for cybersecurity, data protection, automation, and code. Prior to his current role he worked as a Product Manager and Systems Engineer for a data storage software company, managing and implementing both software and hardware B2B solutions.
Learn more on this subject
The AI agent working for you probably has more access than you do
One config changed. Nobody noticed.
The AI jailbreak problem isn't going away, and compliance frameworks need to catch up
When the actor disappears: CIS Controls in a world of non-human corporations
Ten Most Useful Office 365 PowerShell Commands