From the article :
"We’re not naming the affected organizations to limit the risk of exposing patient data."
However, a google inurl:dicom search sure shows up the affected organizations on the first page (and plenty pages after that).
And the sites are still fully open. Absolutely zero hacking required.
A lot of organizations had better get to work fast on this.
(edit: no images were viewed in the making of this post)