Clingantry

From ClingantryAI Health Regulator News

healthcare ai & robotics — regulatory & breach intelligence, sourced only from primary government record


Tagged “radiology” · 5 entries

Expert MRI reports hacking incident affecting 209,560 patients

A California radiology group, Expert MRI, filed a breach report with HHS OCR on October 31, 2025. The filing indicates a hacking/IT incident compromised data stored on a network server, affecting 209,560 individuals. As a healthcare provider, Expert MRI is a covered entity under HIPAA. This submission date marks when the report was sent to regulators, not necessarily when the breach occurred or was discovered. Healthcare administrators should monitor for further details regarding the specific data elements exposed and any required notifications to affected patients.

University Diagnostic Medical Imaging reports hacking breach affecting 138,080 patients

A New York radiology group, University Diagnostic Medical Imaging, PC, filed a report with HHS OCR on January 21, 2025, disclosing a hacking/IT incident. The breach involved unauthorized access to a network server, exposing the protected health information of 138,080 individuals. As a healthcare provider, the entity is directly responsible for this disclosure. Administrators at imaging centers and hospitals should note the scale of this incident as a benchmark for risk assessment. While the filing date is January 21, 2025, this does not indicate when the breach occurred or was discovered. Monitor for further details on the nature of the data exposed.

Radiology Associates of Richmond reports massive data breach affecting 266,183 patients

A Virginia-based radiology group, Radiology Associates of Richmond, has filed a report with HHS OCR regarding a significant security incident. The filing, submitted on May 21, 2026, indicates that a hacking/IT incident compromised data stored on a network server. This breach affects a substantial number of individuals, with 266,183 people impacted. As a healthcare provider, the entity is a Covered Entity under HIPAA rules. Administrators should note that this submission date reflects when the report was filed with regulators, not necessarily when the breach occurred or was discovered. Given the scale of the incident, this serves as a reminder of the risks associated with network server vulnerabilities in medical imaging and diagnostic settings.

Central Kentucky Radiology reports hacking incident affecting 166,953 individuals

Central Kentucky Radiology, a physician-owned radiology group in Kentucky, filed a breach notification with HHS OCR on June 13, 2025. The filing reports a hacking/IT incident that compromised a network server, exposing the protected health information of 166,953 individuals. While the submission date is June 2025, secondary sources indicate the underlying incident occurred in October 2024. Healthcare administrators, particularly those running imaging practices, diagnostic labs, or provider networks, should note this risk profile. This event highlights the vulnerability of network servers to unauthorized access. Review your own incident response plans and ensure your IT teams are monitoring for similar vulnerabilities. Verify that your security protocols align with current best practices for protecting patient data in digital health environments.

Primary source: HHS OCR Breach Portal

Radiology group reports 1.4M-record breach; second incident status unclear

Radiology Associates of Richmond, Inc., a Virginia-based healthcare provider, filed a breach notification with HHS OCR on July 1, 2025, reporting a hacking/IT incident affecting 1,419,091 individuals. The data was accessed from a network server. This entity has since disclosed a second, separate breach involving 266,183 individuals, stemming from an incident on or about July 25, 2025. This subsequent disclosure was reported to the Maine Attorney General on May 21, 2026. However, claims that this second breach has appeared on HHS OCR's public breach portal are unsupported by primary sources and contradicted by contemporaneous reporting stating it had not yet appeared. The HHS OCR record for the initial filing indicates no business associate was involved. Administrators should monitor the OCR portal for updates on both incidents.

← Back to AI Health Regulator News