Leo · 2026-10
Imaging archives only grow, and the procurement decision has to survive that. A single CT study can carry hundreds of images, and every one of them is kept for years, which is why specifying a NAS for medical imaging archive OEM builds is closer to capacity planning than to buying storage. The platform quoted today becomes the platform a clinic replaces in year three if the retention horizon was guessed rather than calculated.

Four things decide the quote: the arithmetic, the ceiling, the site structure, and the paperwork. All four are cheapest to settle before tooling is discussed.
Imaging behaves differently from a general file estate in three ways, and each one moves a number in the specification. Studies are large and arrive in bursts. They are read rarely but urgently, usually by a radiologist comparing a new scan against priors. And they are retained for a decade or more under a rule that nobody on the buying committee can shorten.
That third property is the one that breaks assumptions. Versioning is meaningless here, because a study is never edited. Deletion is not a user action but an end-of-retention event that has to be traceable. The records also carry their own structure: DICOM (the file format and network protocol imaging equipment uses to store and exchange studies) defines how objects are written, indexed and fetched, so a platform that ignores it pushes the buyer into a translation layer. The DICOM standard is published openly, which means the questions you put to a supplier can be checked against a primary source instead of a brochure.
The arithmetic starts with modality counts, not with terabytes. Annual raw volume equals studies per day × average study size × 365. Take an imaging centre with three modalities:
That totals 20.4 GB a day and about 7.4 TB a year before overhead. Viewer caches and thumbnails add roughly a fifth, which takes the annual figure to 8.9 TB. Multiply by the retention horizon and the shape of the purchase appears: seven years is 62 TB, and that number is the one to carry into a supplier conversation.
Study sizes and daily volumes here are illustrative inputs, chosen to make the method visible. Substitute your own modality counts before these figures reach a quotation.
Run the same formula a second time against the next scanner, because that is the calculation imaging groups forget. Add a second CT unit and CT volume doubles to 80 studies a day, which puts the site at 34 GB a day, 12.4 TB a year raw and 14.9 TB after cache overhead. Seven years then reaches 104 TB, and a four-bay chassis at 30 TB per drive offers 90 TB usable under RAID 5. The plan that fit comfortably in year one no longer fits at all, and the second scanner is usually approved long before the storage team is asked about it.
Capacity ceilings do not fail gracefully, and this is where the arithmetic meets the catalogue. Four bays at 30 TB per drive reach 120 TB raw, a ceiling published for the <a href="products/x4-nas-server“>woCyber X4 4-bay NAS server. The same platform publishes RAID 0/1/5/6/10, Intel N100, dual 2.5GbE ports with link aggregation or failover up to 5 Gbps, 8 GB DDR4 rising to 16 GB in OEM configurations, 64 GB eMMC boot storage, and hardware 4K transcoding.
| Drive size | Raw capacity, 4 bays | RAID 5 usable | RAID 6 usable | Years covered at 8.9 TB/year |
|---|---|---|---|---|
| 8 TB | 32 TB | 24 TB | 16 TB | 2.7 / 1.8 |
| 16 TB | 64 TB | 48 TB | 32 TB | 5.4 / 3.6 |
| 20 TB | 80 TB | 60 TB | 40 TB | 6.7 / 4.5 |
| 30 TB | 120 TB | 90 TB | 60 TB | 10.1 / 6.7 |
Read that table as a retention decision rather than a capacity comparison, and the pairing in the last column becomes the whole point. On the worked case above, RAID 5 across 30 TB drives fits a decade of archive; RAID 6 over the same drives fits under seven years. That margin is not free: RAID 6 tolerates two simultaneous failures, which is what a long rebuild on large drives makes plausible. An imaging archive that wants both the margin and the decade has to add a second tier for older years, and that is exactly what <a href="enterprise-nas-cold-data-storage“>cold data tiering is for.

Imaging groups rarely operate from one building. Satellite clinics push studies to the central archive and keep a local cache for the day the link drops, and that cache does not need enterprise capacity. It needs a quiet box that can live in a treatment room. The <a href="products/s2-smart-nas“>woCyber S2 dual-bay storage hub is published with 2 bays, an RK3568 processor with a 1 TOPS NPU, 4 GB DDR4, a 2.5GbE port and a 60 TB ceiling, in a chassis built around a rigid steel mid-frame to control vibration and noise. For a clinic node the useful property is not the capacity, though. It is that one firmware family covers both ends of the estate, so the integrating team maintains a single image instead of two.

The specification behind a NAS for medical imaging archive OEM build is wider than the appliance itself, because branding and localisation change what leaves the factory. White-label app publishing under the buyer’s own app-store listing, branded UI and boot animation, logo by silkscreen or laser engraving, packaging and documentation localised for the destination market, region-specific power adapters, and firmware variants for event rules and retention defaults. Interface languages already span EN, DE, FR, IT, ES, JA, KO and FI, which shortens the localisation work at the buyer’s end.
Commercial terms have to be fixed before tooling is discussed, and the published positions are specific enough to plan against. MOQ starts at 100 units per SKU where an existing platform is reconfigured, and 1,000 units where the project needs a new PCB respin or new tooling. Sample fees are charged at the published unit price and credited in full against the first bulk order. NRE is quoted per project and creditable against agreed volume. Tooling is amortised into the unit price or invoiced separately, with ownership transferring to the buyer once paid, and customer-specific tooling is never reused for another client. Payment terms are confirmed in writing at order confirmation, and hardware warranty terms are confirmed in writing at quotation with spare-part supply for the project lifecycle. The <a href="oem-odm“>OEM/ODM pages carry the detail, and the <a href="certifications“>certifications and quality page lists the documents that ship with an order: CE, UKCA, FCC, RoHS, REACH and WEEE, and ONVIF support where cameras are in scope.

Imaging buyers ask for compliance, and the honest answer is narrower than most suppliers imply. No storage appliance makes an organisation compliant with a regulation. What a local platform changes is where the data sits and what the buyer can demonstrate about access to it. Where patient records are in scope, the rule text setting access-control and audit expectations is public — the Security Rule at 45 CFR Part 164 is one example — so a specification that supports local deployment, per-account isolation and an exportable access log answers the real question without claiming a certificate it does not hold.
Put that wording in writing, because this is where bids quietly diverge. “Supports local deployment and access auditing” is a statement a supplier can stand behind for a decade. “Compliant with” is a statement that will be tested by somebody else’s lawyer, and the test rarely ends well.
Three compromises appear on nearly every imaging project, and they tend to be made in the wrong order.
The first is cutting the second network port. Retrieval is what users feel, not ingest: a radiologist opening a 350 MB study with priors attached is working on the retrieval path, and link aggregation or failover across dual 2.5GbE is far cheaper to specify than to retrofit.
The second is sizing drives to the current year instead of the retention horizon. The table above shows what that costs. A configuration that fits year two comfortably can leave a site facing a rebuild decision in year four.
The third is treating the archive as a one-off purchase. Imaging estates grow in steps, and the platform that survives the steps is the one whose ceiling was published before the first order.
If one preference is worth stating plainly: specify the retention horizon, then the drives, then the discount. Reaching 120 TB with 8 TB drives takes fifteen of them (120 ÷ 8 = 15), and no four-bay chassis will hold that.
Multiply studies per modality per day by the average study size and by 365. A three-modality centre running 40 CT, 20 MRI and 30 ultrasound studies a day produces roughly 20 GB a day, or about 7.4 TB a year before overhead, and about 8.9 TB after caches. Apply your own retention horizon to that figure.
RAID 6 where rebuild risk is real, RAID 5 where the retention horizon matters more than the safety margin, and never RAID 0 for patient records. On four 30 TB drives, RAID 5 leaves 90 TB usable and RAID 6 leaves 60 TB; a seven-year archive at 8.9 TB a year needs 62 TB, so the choice changes the architecture.
Not credibly by the hardware vendor. Describe what the platform does instead: data stays on the buyer’s own hardware, accounts are isolated, access is logged and the log can be exported. Rules such as the Security Rule at 45 CFR Part 164 set expectations for access control and audit; the deployment supports meeting them rather than certifying them.
From 100 units per SKU where an existing platform is reconfigured with your branding, firmware defaults and packaging. A project needing a new PCB respin or new tooling starts at 1,000 units, since those costs have to be spread over the build. Sample fees are credited in full against the first bulk order.
Keep the central archive on the larger platform and give each clinic a cache sized for a few days of studies, then let the archive pull rather than the clinic push. One firmware family across both ends means a single image to maintain, and a two-bay chassis built around a rigid steel mid-frame takes less shelf space than a tower in a treatment room.
From 100 units per model: white-label app, custom firmware, silkscreen or laser-engraved logo, market-specific documentation and packaging. Our export engineering team replies within one working day.
{“@context”: “https://schema.org”, “@type”: “FAQPage”, “mainEntity”: [{“@type”: “Question”, “name”: “How much storage does an imaging archive need each year?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Multiply studies per modality per day by the average study size and by 365. A three-modality centre running 40 CT, 20 MRI and 30 ultrasound studies a day produces roughly 20 GB a day, or about 7.4 TB a year before overhead, and about 8.9 TB after caches. Apply your own retention horizon to that figure.”}}, {“@type”: “Question”, “name”: “Which RAID level suits a long-term imaging archive?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “RAID 6 where rebuild risk is real, RAID 5 where the retention horizon matters more than the safety margin, and never RAID 0 for patient records. On four 30 TB drives, RAID 5 leaves 90 TB usable and RAID 6 leaves 60 TB; a seven-year archive at 8.9 TB a year needs 62 TB, so the choice changes the architecture.”}}, {“@type”: “Question”, “name”: “Can a storage appliance be described as compliant with a medical privacy rule?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Not credibly by the hardware vendor. Describe what the platform does instead: data stays on the buyer’s own hardware, accounts are isolated, access is logged and the log can be exported. Rules such as the Security Rule at 45 CFR Part 164 set expectations for access control and audit; the deployment supports meeting them rather than certifying them.”}}, {“@type”: “Question”, “name”: “What is the minimum order for a branded imaging archive appliance?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “From 100 units per SKU where an existing platform is reconfigured with your branding, firmware defaults and packaging. A project needing a new PCB respin or new tooling starts at 1,000 units, since those costs have to be spread over the build. Sample fees are credited in full against the first bulk order.”}}, {“@type”: “Question”, “name”: “How should satellite clinics be connected to the central archive?”, “acceptedAnswer”: {“@type”: “Answer”, “text”: “Keep the central archive on the larger platform and give each clinic a cache sized for a few days of studies, then let the archive pull rather than the clinic push. One firmware family across both ends means a single image to maintain, and a two-bay chassis built around a rigid steel mid-frame takes less shelf space than a tower in a treatment room.”}}]}{“@context”: “https://schema.org”, “@type”: “Article”, “headline”: “NAS for Medical Imaging Archive OEM: What to Specify”, “datePublished”: “2026-10-02”, “dateModified”: “2026-10-02”, “inLanguage”: “en”, “author”: {“@type”: “Person”, “name”: “Leo”, “url”: “https://wocybersec.com/about/”}, “publisher”: {“@type”: “Organization”, “name”: “woCyber”, “url”: “https://wocybersec.com/”}}
A storage review that covers what goes in and stops there has tested half the system. The half carrying the risk is…
October 1, 2026.wo-note{font-size:.92rem;color:#555;border-left:3px solid #cfd6e0;padding:.2rem 0 .2rem .9rem;margin:20px 0} .wo-tbl{width:100%;border-collapse:collapse;margin:26px 0;font-size:.95rem} .wo-tbl th,.wo-tbl td{border:1px solid #dfe3e9;padding:10px 12px;text-align:left;vertical-align:top} .wo-tbl th{background:#f2f5f9;font-weight:600} .wo-tbl td.wo-num{white-space:nowrap} .wo-calc{background:#f7f8fb;border:1px solid #dfe3e9;border-radius:8px;padding:16px…
October 1, 2026.wo-tbl{width:100%;border-collapse:collapse;margin:26px 0;font-size:.95rem} .wo-tbl th,.wo-tbl td{border:1px solid #dfe3e9;padding:10px 12px;text-align:left;vertical-align:top} .wo-tbl th{background:#f2f5f9;font-weight:600} .wo-tbl td.wo-num{white-space:nowrap} .wo-calc{background:#f7f8fb;border:1px solid #dfe3e9;border-radius:8px;padding:16px 20px;margin:24px 0} .wo-calc p{margin:.45rem 0} .wo-calc code{background:#fff;border:1px…
Ask our export team for the OEM/ODM cooperation guide and a written quotation.