--- title: On-Prem Servers | Avara description: Avara-managed on-prem PACS routing nodes — encrypted DICOM relay, plug-and-play hardware, and HIPAA-compliant imaging integration without VPN. --- ## Overview Avara **on-prem servers** are secure routing appliances at your imaging site. They sit between your modality scanners and Avara’s cloud archive — receiving DICOM locally, **encrypting** it, and relaying studies to the platform over the internet. They are **not local PACS storage**. Data passes through the node in encrypted form and is **not retained on the device**. Think of each box as a **proxy DICOM node**: your modalities talk to familiar on-site DICOM endpoints, and Avara handles secure delivery to the cloud. On-prem servers are **strongly recommended for clinical deployment** when enabling PACS on a [room](/clinical-platform/rooms-pacs/#enabling-pacs-for-a-room/index.md). See [Rooms & PACS](/clinical-platform/rooms-pacs/index.md) for how nodes connect to scheduling, worklists, and study access across your organization. ## Security and HIPAA Compliance Every Avara on-prem server is built for **HIPAA-compliant imaging integration**: - **Encrypted disk** — Storage on the appliance itself is encrypted at rest, as an additional safeguard on the routing hardware - **Encrypted DICOM relay** — Studies are processed and **encrypted in transit** before they leave your site for Avara’s cloud servers - **Proxy DICOM node** — The box presents as a standard DICOM endpoint to your modalities while acting as a secure gateway to the cloud - **No local data retention** — The server **does not store patient imaging locally**; it relays data through, reducing on-site PHI footprint - **No VPN required** — Secure connectivity is built into the integration. You do **not** need to stand up or maintain a site-to-site VPN for DICOM routing — unlike many cloud PACS deployments that tunnel traffic over VPN Together, these properties give you a **fast, performant path** from scanner to cloud — typically **lower latency and higher throughput** than sending DICOM to a cloud PACS node over a VPN — without compromising on encryption or compliance. ## Plug-and-Play Provisioning Avara handles **the entire provisioning and setup** for you. When you order an Avara on-prem server, it arrives **fully configured** — validated, imaged, and enrolled with your organization before it ships. **All you do is plug in power and Ethernet.** There is no server build-out, no OS hardening checklist, and no multi-day integration project on your side. Unlike traditional PACS vendors or custom PACS integrations that leave IT to assemble software, credentials, and routing rules from scratch, **Avara’s appliances are ready to go out of the box**. ### Using Your Own Hardware If you already have servers or a virtual machine you prefer to use, we are **more than happy to leverage your existing hardware**. Our team can deploy the same secure routing stack onto infrastructure you provide. That said, **Avara-provisioned on-prem servers are recommended**. Every unit is **comprehensively validated** before it leaves our facility — hardware, encryption, DICOM services, and cloud pairing are tested end to end. You get a known-good appliance with predictable performance and support, instead of variable results across ad hoc VMs or repurposed boxes. ## One Server, Many Modalities Deployment is flexible to match how your site is wired and how strict your security model needs to be: - **One on-prem server for multiple modality machines** — A single box can serve several scanners on the same network segment - **One server per device** — Isolate each modality behind its own routing node when your policy calls for tighter segmentation - **Any combination** — Mix shared and dedicated nodes across rooms and modalities as best fits your environment There is no forced one-size-fits-all topology. We help you choose a layout that balances simplicity, performance, and your internal security requirements. ## Network Requirements The on-prem server must be able to communicate with your modality scanners on the **local imaging network**. In practice, that means the server and each scanner it serves should sit on the **same IP subnet**. For IPv4, the server’s address and the scanner’s address must share the **same first three octets** — for example, `192.168.1.10` for the on-prem box and `192.168.1.50` for the modality. Both devices live on the `192.168.1.x` network, which allows direct DICOM worklist and send traffic between them before studies are encrypted and relayed to the cloud. Your IT team or imaging vendor typically assigns these addresses on the modality VLAN or imaging subnet. Avara works with you during provisioning to confirm addressing, firewall rules, and outbound internet access for encrypted cloud relay — without requiring VPN. ## Pricing On-prem servers are **$300 one time per appliance** — **hardware cost only**. - **No setup fees** - **No recurring fees** for the on-prem box itself - **No long-term contracts** or minimum commitments tied to the appliance You pay for the validated routing hardware once; Avara handles provisioning, cloud pairing, and ongoing support for the integration as part of your Clinical Platform PACS workflow. See [Rooms & PACS — Pricing and Commitment](/clinical-platform/rooms-pacs/#pricing-and-commitment/index.md) for broader PACS pricing philosophy. ## Getting Started On-prem servers are configured by users with **Can Manage PACS**. See [Inviting Users](/clinical-platform/inviting-users/#can-manage-pacs/index.md) for access requirements. When you are ready to connect imaging at a site, reach out to Avara — we guide you from **room and modality setup** through **node deployment**, **worklist configuration**, and **go-live validation** so your scanners are sending encrypted studies to the cloud with minimal lift from your team.