← Lumexa Imaging

2026 Lumexa Imaging — vendor network incident Mar 31–Apr 9; HHS OCR 5,830,949 patients

2026 5.8M records affected Share on X

Data compromised

Names, birth dates, addresses, phones, patient account numbers, insurance information, clinical radiology info (diagnoses, visit dates, related service data); small subset with Social Security numbers

Technical writeup

Verified Lumexa Imaging / HHS OCR update — HIPAA Journal September 7, 2026. Vendor notified Lumexa April 9 of suspicious activity; investigation found vendor breach Mar 31–Apr 9 2026; on Apr 15 Lumexa learned an unauthorized actor may have used the vendor connection to obtain affiliated radiology documents. Initial OCR filing listed 2,994; updated to 5,830,949 individuals. Credit monitoring offered for SSN subset. Catalog supersedes thin CA AG stub row for census/detail (stub retained historically if present). companyConfirmed true; recordsAffected 5830949.

Root cause

Unauthorized activity on a non-clinical support vendor’s network; actor may have used the Lumexa–vendor connection to view/obtain affiliated radiology practice documents

References