Register Now: Image-Based Risk: The Next Frontier in Breast Cancer Screening
Blog|Articles|October 5, 2026

Security: A Way to Be Safe and Unproductive in Radiology

Has the barrage of passwords, PINs and authenticator apps gone around the bend to a point where it hampers efficiency and productivity?

One of the tidbits of wisdom I inherited from my grandfather regarded security. No matter what clever innovations the makers of locks come up with, someone will find a way to pick or otherwise circumvent them. I imagine he was helped to this conclusion by cases he worked on as an assistant DA.

He wasn’t around quite long enough to see everybody needing dozens of passwords, PINs, and other digital equivalents of keys for virtual locks, but I am sure he would have been amused by the mass illusion (or delusion) of safety. Even I thought it was pretty darned silly when my first computer science teacher walked around with a pocket-sized notebook to keep track of all his log-ins. Who could possibly need that many? Years later, I started having to maintain one of my own.

Someone with greater foresight than I might have predicted the next level of complexity. It wasn’t enough to have a layer of security for everything you did. There were dozens of logins for work, banks, stores, streaming services, etc., that drove you to distraction. Each of those would eventually add extra layers to their systems. Dr. Postal, before we let you log in, please enter the code we emailed or texted you.

Nowhere was this more evident than in my work as a radiologist. One might imagine that as I switched to working in a home office back in 2011, I might have been spared some of this.

A no-goodnik looking to wrongly access health-care computing systems might reasonably set his or her sights on a hospital or imaging center. “That’s where the money is” as Mr. Sutton allegedly put it. Someone breaking into my house would far more likely be doing it to loot tangible valuables (and be disappointed with what he or she found) than to settle down at my computer.

No health-care system I have seen, however, has made any allowances for remote users to have fewer security barriers. I suspect that is not so much a failure of common sense as following the path of least resistance. It is less work for the policy-making folks to have a single set of rules for all users than it would be to carve out a special category for telerads.

So it was that I started having a longer and more bothersome routine when logging into my workstation. What had been one password became two and then three. They required changing at different intervals so I could never keep them in any sort of sync with one another. Some required more than one check per day, especially if I dared to step away from my keyboard longer than a prescribed “idle” interval.

An “authenticator” app entered the picture at some point. Now you had to have your cellphone ready because of course someone who had done the legwork to be at your machine with your passwords couldn’t possibly have stolen or cloned your cell. One employer of mine tried to make things easier with a fingerprint reader so you could just scan yourself whenever the system wanted, but that soon developed conflicts with other software and had to be sidelined.

As annoying as all of this is, an apologist for the system might say that it only takes a few seconds, maybe a minute out of your day. How bad is that, really? I would counter that might be the case when it all works the way it is supposed to work.

Unfortunately, it doesn’t. Every extra layer introduces potential for periodic failures. When that happens, the system doesn’t just shrug and let me go on to my work while it sorts itself. Rads like me get locked out and have to sit idle until we can get the attention of support people. When we eventually do, they can almost never solve things swiftly because it invariably means that something deep in the system is bolluxed. I have lost hours of productive time this way.

Let’s take it a step further. All of the security contrivances that have been forced on us have been vastly more successful at getting in the way of authorized users than crooks. That is nothing sinister. It is just the way the numbers tumble.

Suppose I use passwords 100,000 times per year, and 1 percent of the time, I hit the wrong button, the system is buggy or undergoing maintenance, etc. That is a thousand times I am kept from doing whatever I should have been allowed to do.

Now, I can’t really know how many times bad actors have been prevented from getting into my stuff. I am not exactly a juicy target, and I can’t remember the last time I got any sort of “suspicious activity” warning message. Let’s assume that, perhaps 10 times a year, sometime tries to target me and fails? Even if we say 100, the security is screening me out 10 times as frequently.

So, this past week, when I saw that the “use your Authenticator” pop-up window wanted me to set up yet another layer to “make sure it’s you,” I sent a message to the tech folks behind our scenes. Hey guys, are we really introducing another barrier? If what we have already got isn’t doing the job, can’t we remove one of the other layers, so we don’t go further down this rabbit hole? My answer was a resounding “Maybe,” which I am pretty sure will evolve into “No.”

This dovetails with a frequent issue brought up by one of my fave podcasters. Our society has gotten way too enamored with safety. Especially since COVID, when “stay safe” became some sort of cultural mantra. It is like a conversational trump card. If you claim that something is safer than the alternative, it is almost not allowed for anyone to argue against it.

In his world (which includes construction in the state of California), he has repeatedly observed how, courtesy of an ever-increasing tonnage of laws and regulations in the name of “safety,” rebuilding homes in the aftermath of wildfires, earthquakes, etc., has been brought to a standstill. Requirements effectively prevent people from reconstructing their private homes just the way they were before, let alone upgrading something like a front porch.

Security is, of course, a necessity, and every measure that impairs villainous behavior is worth consideration. We nevertheless seem to be forgetting that there are trade-offs involved. 100 percent security would be having no workstations to log into at all, and maybe not getting out of bed each morning lest we stub our toes. It’s time to accept that “safer” isn’t always better.


Related to this article

Current Perspectives on Integrating AI into Radiology
In a recent interview with Diagnostic Imaging, Joseph Cavallo, MD, MBA, offered insights on post-deployment monitoring with AI, the potential for improved workflow efficiency and the ongoing challenge of balancing essential clinical skills and AI literacy in the training of radiology residents and fellows.