← Blog

RAR Breach: 266K Radiology Patients Notified

Share on X

May 21, 2026: Radiology Associates of Richmond began notifying patients that a July 2025 cybersecurity incident led to unauthorized acquisition of protected health information. Maine AG materials and trade press put the count at 266,183 people.

That is a second major RAR disclosure era after an earlier incident HHS reporting associated with roughly 1.4 million people—so Virginia imaging patients should treat any new letter as a distinct event, not a reprint.

What happened

Per RAR’s website notice and SecurityWeek, hackers accessed internal systems on or about July 25, 2025. Forensics and a manual document review finished April 6, 2026, concluding that files with PHI for a limited population were acquired. Letters started May 21, 2026; HIPAA Journal notes each letter spells out which data types applied to that person.

What was exposed

Public summaries confirm protected health information for current and former patients. Social Security numbers were present for a subset; those people were offered complimentary credit monitoring. Exact field lists vary by individual letter.

Action items

  1. If you received an RAR notice, enroll in any offered credit monitoring before the deadline on the letter.
  2. Freeze credit with the major bureaus if your SSN was included.
  3. Watch Explanation of Benefits and patient-portal activity for medical identity theft.
  4. Do not click “RAR billing update” links in unexpected email—verify through the practice’s known phone number.

Canonical record: Radiology Associates of Richmond Jul 2025 intrusion.