On-premise PACS software for hospitals and clinics

Medisfera is the on-premise PACS/VNA designed for modern healthcare environments. Designed for regulatory compliance, integrates with any HIS/RIS, and eliminates recurring cloud costs.

What is a PACS system?

A PACS (Picture Archiving and Communication System) is the central technology infrastructure for medical imaging management in hospitals and clinics. It receives DICOM images from any diagnostic modality (CT, MRI, ultrasound, conventional radiology, mammography, PET, endoscopy...), stores them securely, and distributes them to radiologists, clinicians, and other professionals who need them.

A modern PACS also integrates the Modality Worklist (MWL) to automate patient data entry on modalities, MPPS for procedure status tracking, and HL7/FHIR connectors to communicate with the facility's HIS and RIS.

The question is no longer whether to use PACS — it is which PACS to choose and under which deployment model.

Components of a complete PACS

  • Storage SCP: Receives DICOM images from modalities (C-STORE)
  • Modality Worklist (MWL): Provides patient data to imaging modalities
  • MPPS SCP: Tracks procedure completion status
  • DICOMWeb (QIDO/WADO/STOW): REST access to images from any web client
  • Clinical viewer: Diagnostic workstation with MPR, measurements, and annotations
  • VNA / Long-term archive: Vendor-neutral storage with tiers to optimise costs
  • HL7 / FHIR connector: Bidirectional integration with HIS, RIS, and laboratory

On-premise PACS vs cloud PACS

Cost model

Cloud

Per study / subscription

Medisfera

Perpetual licence

5-year cost

Cloud

>€90,000

Medisfera

Request a quote

Data control

Cloud

Vendor servers

Medisfera

Your infrastructure

Offline

Cloud

No connectivity = no access

Medisfera

Independent of internet

HL7/FHIR

Cloud

Varies by vendor

Medisfera

Native, bidirectional

Regulatory

Cloud

Vendor certification

Medisfera

Aligned with EU MDR

Updates

Cloud

Automatic (no control)

Medisfera

Planned by facility

Regulatory requirements: EU MDR and GDPR

Regulation (EU) 2017/745 — EU MDR

The EU Medical Device Regulation classifies PACS systems that process images for diagnostic purposes as Class IIa medical devices (Annex VIII, Rule 11). This requires:

  • Certified Quality Management System (ISO 13485)
  • Complete technical documentation (Annex II of the MDR)
  • Clinical evaluation with safety and performance evidence
  • Certification by a Notified Body (e.g. TÜV, BSI, SGS)
  • EU Declaration of Conformity and CE marking

Medisfera is designed with this regulatory framework in mind. The architecture and documentation are aligned with EU MDR requirements to facilitate your certification process.

GDPR — Patient data

Medical images are health data (special category under Art. 9 GDPR). Healthcare facilities act as data controllers and must ensure:

  • Lawful basis for processing (Art. 6 and 9 GDPR)
  • Data minimisation and retention limitation
  • Appropriate technical and organisational measures (Art. 25 and 32)
  • Data Protection Impact Assessment (DPIA) for high-risk processing
  • Data processing agreement if using cloud services

By keeping data in their own infrastructure, Medisfera customers eliminate the need for data processing agreements with cloud providers and ensure data remains within EU territory.

Why choose Medisfera?

Modern technology stack

Built with .NET 10, Kubernetes, PostgreSQL 18. Deployed via Terraform + Ansible on ESXi, Proxmox, or Hyper-V. Documented, open APIs.

Unlimited integration

HL7 v2.x, FHIR R4, DICOMWeb, LDAP/AD, SAML 2.0, and OAuth 2.0. Connects with any existing system.

No vendor lock-in

Open MedPack format, standard DICOM export, documented APIs. Your data is always yours and fully portable.

Responsive support

Technical team available during CET business hours. Deep knowledge of EU regulatory requirements.

Lower TCO

Perpetual licence with optional annual maintenance. No costs per study stored, per user, or per bandwidth consumed.

Security by design

End-to-end encryption, granular RBAC, MFA, full audit trail, DICOM anonymisation. DPIA-ready.

Frequently asked questions

How is Medisfera priced compared to cloud PACS solutions?
Medisfera is sold as a perpetual licence, which delivers significant savings compared to cloud solutions that charge per stored study (typically €0.05–€0.20/study). For a hospital with 50,000 studies per year, the 5-year saving can exceed €60,000. Request a personalised ROI analysis.
Does an on-premise PACS need to comply with EU MDR?
Yes. Under Regulation (EU) 2017/745 (EU MDR), a PACS that processes diagnostic images is typically classified as a Class IIa medical device. This requires a quality management system (ISO 13485), technical documentation, clinical evaluation, and certification by a Notified Body. Medisfera is designed with this regulatory framework in mind — the architecture and documentation are aligned with EU MDR requirements to facilitate the certification process.
Can Medisfera integrate with my hospital HIS/RIS?
Yes. Medisfera includes HL7 v2.x connectors (SIU, ORM, ORU, ADT) via MLLP for integration with any HIS or RIS. The native FHIR R4 server enables integration with modern systems. We support all major HIS platforms including Agfa Orbis, SAP IS-H, and any system with a standard HL7 interface.
What is the difference between a PACS and a VNA?
A PACS (Picture Archiving and Communication System) manages the image lifecycle for one or more modalities within a department. A VNA (Vendor Neutral Archive) is a centralised, vendor-independent archive that can aggregate images from multiple PACS and heterogeneous systems. Medisfera combines both: it acts as a departmental PACS and a corporate VNA, unifying all medical imaging in a single repository.
How does Medisfera help with GDPR compliance?
As an on-premise system, patient personal data and medical images remain in the healthcare facility's own infrastructure, under its full control. Medisfera includes AES-256 encryption at rest and TLS 1.3 in transit, full access auditing, DICOM anonymisation, role-based access control (RBAC), and tools to support your DPIA process. The facility remains the data controller and is responsible for its own GDPR compliance.

Talk to our technical team

We will show you Medisfera in an environment similar to yours. No commitment. Under 45 minutes.

Request a free demo

Request your personalised quote

Tell us about your setup and we will send you a detailed quote within 48 hours.