Advanced Radiology Services, P.C. Data Breach Exposes Patient Health Information

Published: 8 October 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: September 2026

Advanced Radiology Services, P.C., a Michigan radiology provider, reported a network server hacking incident to federal regulators in September 2026 affecting 826 patients. The specific data types exposed have not been publicly disclosed. If you receive a notice letter, affected individuals should monitor credit reports, watch insurance statements for unfamiliar charges, and consider a credit freeze as a first step.

CompanyAdvanced Radiology Services, P.C.
IndustryHealthcare
Data Types ExposedPatient Names and Dates of Birth, Contact Information, Imaging Orders and Radiology Reports, Diagnosis-Related Information, Insurance and Billing Details, Social Security Numbers
People Affected826 individuals
Attack MethodHacking/IT Incident
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Advanced Radiology Services Data Breach?

Advanced Radiology Services, P.C., a radiology practice based in Grand Rapids, Michigan, reported a data breach to the U.S. Department of Health and Human Services in September 2026. The practice reads imaging studies, including X-rays, CT scans and MRIs, for hospitals and health systems across the state. Its filing identifies the event as a hacking or IT incident affecting a network server.

According to the federal filing, the practice submitted its breach report on September 16, 2026. The notification classifies the incident as outside intrusion into a computer network, which is the designation regulators use when an unauthorized party gains access to an organization’s systems. However, the filing does not describe how the intrusion occurred or how long it may have gone unnoticed.

The breach discovery date has not been publicly disclosed. As a result, it remains unclear exactly when the unauthorized access began or when Advanced Radiology Services first detected suspicious activity on its network. The HHS breach portal entry is intentionally brief, and it does not confirm whether data was copied, viewed only, or extracted by the intruder.

Because the public filing offers limited detail, much of the forensic picture remains unknown. Entities covered by HIPAA must report breaches affecting 500 or more people to the federal government, which is why this incident became public. Still, the investigation into exactly what happened on the practice’s network has not been described in any available source.

Who was affected?

The breach affects patients of Advanced Radiology Services, P.C. according to the federal filing. The practice serves hospitals and health systems throughout Michigan, which suggests the affected population is likely concentrated in that state. However, the full geographic scope has not been confirmed.

The HHS filing states that 826 individuals were affected by this incident. This figure reflects the count submitted to federal regulators, and it has not been contradicted by any other source reviewed for this report. Because the practice interprets imaging studies for referring providers, patients may not have a direct relationship with Advanced Radiology Services itself, even though their information was involved.

It is not clear from available records whether employees, in addition to patients, were affected. Similarly, there is no indication of whether minors are among the affected individuals. Anyone who receives a formal notice from the practice should treat that letter as the definitive source for whether they personally were involved.

What Information Was Potentially Exposed?

The HHS filing does not specify which categories of personal or health information were stored on the compromised server. Therefore, this report does not assume categories of data beyond what radiology practices typically maintain in their systems. The following list reflects the types of information commonly held by imaging providers like this one, rather than a confirmed list from the breach notice.

  • Patient names and dates of birth
  • Contact information such as addresses and phone numbers
  • Imaging orders and radiology reports
  • Information related to diagnoses or reasons for a scan
  • Insurance and billing details
  • Possible Social Security numbers tied to registration records

If any of these categories were in fact exposed, patients could face a meaningful risk of medical identity theft. This occurs when someone uses another person’s identity to obtain treatment or file fraudulent insurance claims. Because the first sign is often an unfamiliar bill or an unexpected explanation of benefits, victims may not notice the problem right away.

In addition, if billing records containing Social Security numbers or insurance identifiers were involved, affected individuals could also face broader financial fraud risks. These range from unauthorized credit applications to fraudulent tax filings. Given the sensitivity of health information generally, even exposure limited to diagnosis-related details can carry emotional and privacy consequences beyond financial harm.

What is the company doing?

Advanced Radiology Services submitted its required breach report to the HHS Office for Civil Rights on September 16, 2026. This filing is a mandatory step for HIPAA-covered entities after discovering a breach affecting 500 or more people. The practice also filed formal notification with the HHS Office for Civil Rights, as required under federal breach notification rules.

Beyond the federal filing itself, the practice has not publicly described additional remediation steps in the sources reviewed for this report. It is unknown whether Advanced Radiology Services has sent individual notification letters to patients, or whether it plans to offer credit monitoring or identity protection services. Under HIPAA, covered entities generally must notify affected individuals without unreasonable delay, and no later than 60 days after discovering a breach.

Organizations handling medical records are expected to maintain safeguards such as access controls, multi-factor authentication and network monitoring. Whether these measures were in place at Advanced Radiology Services at the time of the incident has not been disclosed. Patients should watch their mail for a formal notice, since that letter will contain the most accurate and specific details about what applies to them individually.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Affected individuals should request copies of their credit reports and review them for unfamiliar accounts or inquiries. You can get free reports weekly from all three major bureaus at annualcreditreport.com. Doing this regularly makes it easier to catch fraud early, before it causes lasting damage.

Because the exact data exposed in this incident has not been confirmed, erring on the side of caution makes sense. If you spot anything suspicious, dispute it with the credit bureau immediately. Keeping a simple log of when you checked your reports can also help if you need to document harm later.

Consider a Fraud Alert or Credit Freeze

If Social Security numbers or financial details were part of this incident, a credit freeze offers strong protection. A freeze blocks new creditors from accessing your file, which makes it much harder for someone to open accounts in your name. You can freeze your file for free with Equifax, Experian and TransUnion.

Alternatively, a fraud alert requires creditors to take extra verification steps before extending credit. This option is less restrictive than a freeze but still adds a layer of protection. Either step is a reasonable precaution, even if you are unsure whether your Social Security number was involved.

Watch for Signs of Medical Identity Theft

Because this breach involves a radiology provider, medical identity theft is a specific concern. Review every explanation of benefits statement from your insurer carefully. Look for services, scans or provider visits you do not recognize.

If you spot something unfamiliar, contact your insurer and the provider listed right away. In addition, request a copy of your health records periodically to check for errors that could indicate fraudulent use. Correcting a medical record tainted by fraud can be a lengthy process, so catching it early matters.

Stay Alert for Phishing Attempts

After any healthcare data breach, scammers often send phishing emails or texts posing as the breached organization. These messages may ask you to click a link or confirm personal details. Never click links or provide information in response to unsolicited messages, even if they look official.

Instead, if you receive a notice referencing this breach, verify its legitimacy by contacting Advanced Radiology Services directly using a phone number you find independently. This approach protects you from fraudulent lookalike communications. If you do fall victim to phishing, report it promptly to the Federal Trade Commission at identitytheft.gov.

Report Suspected Identity Theft Promptly

If you discover fraudulent activity tied to your identity, report it to the Federal Trade Commission and your state Attorney General right away. The FTC’s identitytheft.gov site can help you build a recovery plan tailored to your situation. Acting quickly limits the damage and creates an official record of the incident.

You should also consider speaking with a data breach attorney about your options. A consultation is often free, and an attorney can help you understand whether you qualify for compensation. This is especially worthwhile if you can show concrete harm resulting from this breach.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Check other recent data breach notifications →