That was not a sentence I was expecting to read today.
I've now debugged (as a well known patient) two computer systems for local clinics - and they were completely and entirely owned from the ground up. They saw this as completely normal/routine (as in - "oh man, call the IT guy - we've been infected again!"), and I watched as they would minimize whatever medical records app they used with my info in it to pull up the toolbar-laden IE to run my credit card via an on-line processor.
Luckily in those cases it was typical malware/botnet infestation. All it takes is the wrong person/group to come across that secretary's workstation that is almost assuredly connected to the same network the random medical equipment and storage is as well.
Security/IT in general in healthcare is a complete unmitigated disaster. Everyone focuses on hospitals (for good reason) - but those are typically far better ran than your local plastic surgery/lasik/clinic practice.
Not too long ago I saw a straight-faced suggestion on this forum that doctors should have cameras in their offices to record all patient interactions/exams/procedures for ML purposes.
I'd be out the door immediately if a doctor ever pulled something like this.
On the other hand, the clinic in question has a big "follow us live in surgery & clinic" banner with Facebook, Twitter, YouTube, Instagram and Snapchat links on their home page...
If it's about the clinic, that doesn't ring true to me. Why would photos of the clinic's customers total to that much data? Do they have hours of 4K video on them or something?
From http://siim.org/?page=archiving_chapter2 :
> One example of the data generated for breast MRI can reveal the large number of sequences and significant amounts of data that are generated for what might be perceived as a “small” study. [...] A significant number of sequences and images result in an average of ~300 MB of data storage per study.