No, you don't have to, but we take security very very seriously. However, we are not a covered entity in the eyes of HIPAA, but we do go above and beyond their guidelines for storing and transmitting patient data.
The FDA comes out every year or two, and of course they keep digging until they find something to ding you on, just so the inspector looks like they're doing their job.
EDIT: I now realize I was conflating FDA certification and HIPAA, though you'll probably have to deal with both while doing DICOM.