In the medical domain, computer systems in digital healthcare have increased connectivity continuously and the DICOM Message Service Element (DIMSE) protocol has a critical role in exchanging biomedical imaging data among different digital healthcare systems. As the data communication technology is used to handle sensitive information such as patient information (e.g., patient’s name, date of birth, and address) and medical images (e.g., ultrasound, X-ray, and MRI), it has emerged as a major target for security attacks. In this work, we study security concerns on the message exchange method used in the DIMSE protocol. It is important to know which DIMSE services are available on a given healthcare IT system to an adversary and we observe that the DIMSE protocol can be implemented in various ways across products, with each supporting different DIMSE services as well. We present DIMScern, a framework for discerning DIMSE services on remote medical devices. To show the effectiveness of DIMScern, we evaluate our framework on multiple DIMSE implementations, including commercial products and libraries, and identify the supported DIMSE services of them. We demonstrate that DIMScern successfully identifies medical services that are supported differently across 22 healthcare IT systems in a remote environment.