GE HealthCare recalled certain Revolution CT systems, the Apex, Ascend and CT lines, over a vulnerability in the AW Server deployed through the Edison Health Link CT Smart Subscription. About 200 systems worldwide, an FDA Class 2 recall, no breaches reported. Customers can keep using the systems while following cybersecurity best practices, which matters because a CT scanner is not a device a hospital takes offline to wait for a fix.

Handling a software weakness through a device recall while the equipment stays in clinical use reflects how postmarket safety oversight now treats connected systems. A recall in this sense is a formal notice and corrective action, not necessarily a removal from service, and telling operators they may continue while following cybersecurity best practices signals a risk judged manageable with controls while a correction is prepared.

The affected piece is the connected-services layer, the AW Server reached through a cloud subscription. Every service you bolt onto a device to make it smarter is a new thing to secure. The subscription that ships analytics also ships a network path into the imaging chain.

The affected element is a server reached over a subscription rather than the imaging hardware itself, which is characteristic of how diagnostic equipment is now built out. Analytics, storage and remote support arrive as networked services layered onto the scanner, and each layer enlarges the software that must be maintained and defended across the machine's long service life.

For a hospital the practical worry is continuity as much as confidentiality. A computed tomography service anchors emergency and inpatient diagnosis, and disruption reaching the connected layer could interfere with how studies are routed, processed or retrieved even when the scan itself proceeds. Diagnostic imaging that cannot be reached or trusted on demand slows every clinical decision that waits on it.