What Happened in the Saint Pete MRI Data Breach?
Saint Pete MRI, a diagnostic imaging and sleep lab operating in St. Petersburg, Florida, has told patients that a network intrusion may have exposed their personal and health information. The Saint Pete MRI data breach involves a range of sensitive details, including Social Security numbers, that patients trusted the practice to safeguard. This incident shows how long it can take for patients to learn their data was at risk after a breach first occurs.
According to the practice, staff first spotted suspicious activity on the network around February 2025. Once discovered, the practice says it moved to lock down its systems and brought in outside forensic specialists to figure out what had happened. That early investigation found that the clinic’s electronic patient care and imaging systems remained untouched. However, the same review determined that certain scanned files had likely been accessed without permission.
Because the exposed material consisted of scanned records rather than live database entries, sorting out exactly whose information was involved took considerably longer. A dedicated document review wrapped up in April 2026, more than a year after the initial detection. Investigators then spent additional months confirming affected individuals and verifying contact details, a process the practice says it finished in mid-July 2026 before mailing notification letters shortly after.
Who was affected?
The breach affects patients who received diagnostic imaging or sleep lab services through Saint Pete MRI. The practice has not published a specific total count of affected individuals in its public notice. As a result, patients who are unsure whether their records were involved should check any letter they received or reach out to the dedicated call center directly.
Because this is a medical practice, the exposed population likely includes patients across a wide age range, potentially including minors who received imaging services. Health records of this kind often include not just the patient’s own information but also insurance policy details tied to family coverage. This means the practical impact of the breach could extend beyond the named patient to household members listed on shared insurance plans.
What Information Was Potentially Exposed?
Saint Pete MRI’s notice describes several categories of personal and health information that may have been included in the affected files. This combination of data is especially concerning because it spans both financial identity theft and medical fraud risks.
- Full names
- Social Security numbers
- Dates of birth
- Driver’s license numbers or state identification numbers
- Medical information
- Health insurance information
Unlike a stolen credit card number, a Social Security number cannot simply be canceled and replaced. As a result, once this type of identifier is exposed, the risk of misuse can linger for years rather than fading after a single fraud alert. Combined with a date of birth and a government ID number, this data set gives criminals nearly everything needed to open new credit accounts or file fraudulent tax returns in a victim’s name.
The medical and insurance information raises a separate concern: medical identity fraud. This occurs when someone uses a stolen identity to obtain treatment, prescriptions, or equipment, sometimes leaving false entries mixed into the real patient’s medical history. Because insurance fraud claims can take a long time to surface, victims may not notice the damage until they receive an unexpected bill or a denial of coverage for a legitimate claim.
What is the company doing?
Saint Pete MRI says it acted quickly once it noticed the suspicious activity, securing its network and hiring independent forensic experts to investigate. The practice states that its core electronic patient care and imaging systems were not compromised, which suggests the intrusion was contained to a more limited set of scanned files rather than the full clinical record system.
Following the initial investigation, the practice conducted a lengthy review of the affected files to identify exactly whose data was contained within them. Once that review and the individual notification process were complete, the practice mailed letters to affected patients and posted a substitute notice online for anyone whose current contact information could not be located. It has also set up a toll-free call center for patients with questions and says it currently has no evidence that any exposed information has actually been misused.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Anyone who received a notice from Saint Pete MRI should pull their credit reports and check them for unfamiliar accounts or inquiries. You can request a free report from each of the three major bureaus through AnnualCreditReport.com.
Because Social Security numbers were involved, monitoring should continue for months, not just weeks. Identity thieves sometimes wait before using stolen data, so a clean report today doesn’t guarantee safety later on.
Consider a Fraud Alert or Credit Freeze
Given that Social Security numbers, dates of birth, and driver’s license numbers were all potentially exposed, placing a fraud alert or a full credit freeze with the major bureaus is a reasonable precaution. A freeze blocks new creditors from accessing your credit file entirely, which makes it much harder for someone to open an account in your name.
A fraud alert is a lighter-touch option that requires lenders to verify your identity before extending new credit. Either step is generally free to set up, and you can lift a freeze temporarily whenever you need to apply for credit yourself.
Watch for Medical and Insurance Fraud
Because medical and health insurance information was potentially involved, patients should review their insurance statements and explanation-of-benefits notices carefully. Look for services, prescriptions, or provider visits you don’t recognize.
If you spot something unfamiliar, contact your insurer immediately to dispute the charge and request a corrected record. Catching medical identity fraud early makes it much easier to fix before it affects your actual treatment history or coverage limits.
Stay Alert for Phishing Attempts
After a breach like this becomes public, scammers often send fake emails or texts pretending to be a follow-up from the breached company. These messages try to trick recipients into handing over even more personal information.
Before clicking any link or replying to a message referencing this breach, verify it independently. Call the official Saint Pete MRI call center directly instead of using contact details provided in an unsolicited message.
Talk to a Data Breach Attorney
If your Social Security number or medical information was exposed in this incident, you may have legal options worth exploring. An attorney who focuses on data breach cases can review your notice and explain whether you qualify to join a claim.
Consulting with a lawyer typically costs nothing upfront, and many firms only get paid if you recover compensation. Given how long this notification process took, it may also be worth asking an attorney about deadlines that could apply to your specific situation.
