What Happened in the Lumexa Imaging Data Breach?
Lumexa Imaging, which provides administrative support to affiliated radiology practices and imaging centers, has confirmed a data breach involving one of its vendors. The company relies on a third-party vendor for non-clinical operational support, and that vendor held patient information on Lumexa’s behalf. As a result, patients tied to Lumexa’s affiliated practices are now receiving breach notification letters.
According to the notification, the vendor first alerted Lumexa Imaging on April 9, 2026, that it was investigating suspicious activity inside a portion of its network. This network segment was dedicated to Lumexa’s affiliated radiology practices and imaging centers. In response, Lumexa immediately disconnected its systems from the vendor’s environment to limit further exposure.
By April 15, 2026, Lumexa determined that an unauthorized person may have viewed or copied documents containing patient information. The intrusion itself occurred earlier, with documents accessed between March 31, 2026 and April 9, 2026. This means unauthorized access to the vendor’s network occurred in March 2026, before it was detected and reported.
Following discovery, the vendor conducted a forensic investigation into the scope of the incident. Before Lumexa reconnected its systems, the vendor provided assurances that it had contained and remediated the issue. These steps reportedly included resetting passwords, scrubbing and validating affected systems, and deploying enhanced monitoring tools to catch future threats.
Who was affected?
The breach affects patients of radiology practices and imaging centers affiliated with Lumexa Imaging. Because Lumexa provides administrative services across multiple affiliated practices, the affected population likely spans several imaging centers rather than a single clinic. However, Lumexa has not publicly disclosed a specific number of affected individuals.
Given that the exposed data includes clinical information tied to radiology visits, affected individuals are likely patients who received imaging services, such as X-rays, MRIs, or CT scans, through one of these affiliated practices. The notification letter does not indicate whether minors were among those affected, though pediatric imaging patients could potentially be included if their guardians used these services.
What Information Was Potentially Exposed?
The information involved varied by individual and by document. Not every affected person had every category of data exposed, but the vendor’s compromised systems held a range of sensitive personal and medical details.
- Full name
- Date of birth
- Address
- Phone number
- Social Security number
- Patient account number
- Insurance information
- Visit dates, diagnoses, and other clinical information related to radiology services
Because Social Security numbers and insurance details were among the exposed data, affected individuals face a real risk of identity theft and financial fraud. Criminals often use stolen SSNs to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. This type of fraud can take months to detect and even longer to fully resolve.
In addition, the exposure of clinical information tied to radiology visits raises the risk of medical identity theft. Fraudsters can use stolen insurance information to receive treatment or submit false claims under a victim’s name. This can lead to inaccurate medical records, denied claims, and confusing bills for services the patient never received.
What is the company doing?
Once notified by the vendor, Lumexa Imaging acted quickly to contain the incident. The company disconnected its systems from the vendor’s network right away to prevent further unauthorized access. Lumexa also required the vendor to provide assurances that it had addressed the security gaps before any systems were reconnected.
As part of its ongoing response, Lumexa is notifying affected individuals directly and offering identity monitoring services through Kroll at no cost. These services include credit monitoring, fraud consultation, and identity theft restoration support. Lumexa has also set up a dedicated phone line for individuals who have questions about the breach or need help enrolling in the offered protections.
What Should Affected Individuals Do?
Enroll in the Free Identity Monitoring Services
Affected individuals should take advantage of the complimentary Kroll identity monitoring services offered by Lumexa Imaging. This includes credit monitoring, fraud consultation, and identity theft restoration assistance. Enrollment requires visiting the activation website before the stated deadline, so acting promptly is important.
These services can alert you quickly if someone opens a new account in your name. Because early detection often limits the damage from identity theft, enrolling as soon as possible gives you the best chance to catch fraud before it spreads. If you have questions about eligibility, Kroll representatives can walk you through the requirements.
Monitor Your Credit Reports and Financial Accounts
Because Social Security numbers were exposed, affected individuals should regularly check their credit reports for unfamiliar accounts or inquiries. You can request a free credit report every 12 months from each of the three major credit bureaus through annualcreditreport.com. Reviewing these reports regularly helps you catch suspicious activity early.
In addition to credit reports, watch your bank and credit card statements closely. If you notice any charges you don’t recognize, contact your financial institution immediately. Acting fast can limit your financial liability and help stop ongoing fraud.
Consider a Fraud Alert or Credit Freeze
Given that Social Security numbers were part of this breach, placing a fraud alert or credit freeze is a smart precaution. A fraud alert requires creditors to verify your identity before opening new credit in your name. This service is free and typically lasts one year, though it can be renewed.
A credit freeze offers even stronger protection because it blocks lenders from accessing your credit file entirely until you lift the freeze. As a result, it becomes much harder for identity thieves to open new accounts using your information. You can request a freeze directly with Equifax, Experian, and TransUnion.
Watch for Signs of Medical Identity Theft
Because clinical and insurance information was exposed, affected individuals should review any statements from healthcare providers and insurers closely. If you see services listed that you never received, contact the provider or insurer right away. This could indicate that someone used your information fraudulently.
You should also request an explanation of benefits from your insurer periodically to check for unfamiliar claims. Catching medical identity theft early can prevent errors in your medical records from affecting future care. If you spot anything suspicious, report it to your insurer and keep detailed records of the communication.
Stay Alert for Phishing Attempts
After a breach like this, scammers sometimes use stolen contact information to send phishing emails or calls pretending to be from Lumexa Imaging or Kroll. Be cautious of any message asking you to click a link or provide personal information. Legitimate companies rarely ask for sensitive details through unsolicited emails or phone calls.
If you’re ever unsure whether a message is genuine, contact the company directly using a verified phone number rather than replying to the message. This simple step can prevent you from unknowingly handing over information to a scammer. If you believe you’ve been targeted by identity theft as a result of this breach, consulting a data breach attorney may help you understand your options for pursuing compensation.
More Information
Official data breach notification from Washington State Attorney General
Official data breach notification from California Attorney General
