Women’s Center for Radiology Data Breach Exposes Driver’s License Numbers and Health Records

Healthcare data breach illustration
Breach Discovery: April 2026Breach Notification: August 2026

In April 2026, hackers accessed the network of the Women’s Center for Radiology in Orlando, Florida, exposing files on 66,422 patients that included names, driver’s license numbers, medical diagnoses, and health insurance details. The practice notified patients in August 2026 and offered free credit monitoring. Affected individuals should enroll in that monitoring immediately and watch for signs of medical identity theft.

CompanyWomen’s Center for Radiology
IndustryHealthcare
Data Types ExposedNames, Addresses, Dates of Birth, Contact Information, Diagnosis/Condition Information, Lab Test Results, Medical Record Numbers, Driver’s License Numbers, Health Insurance Information
People Affected66,422 patients
Attack MethodUnauthorized Network Access
Regulators NotifiedNot Publicly Disclosed

What Happened in the Women’s Center for Radiology Data Breach?

The Women’s Center for Radiology, a women’s imaging practice with two locations in Orlando, Florida, recently notified thousands of patients about a serious data security incident. The practice discovered the breach in April 2026. According to the notification, an unauthorized party had gotten into its computer network and viewed or copied files containing sensitive patient information.

Investigators determined that the intrusion actually began a few days before it was caught. The unauthorized access took place between April 26, 2026, and April 28, 2026. During that window, the intruder was able to reach files stored on the practice’s systems and download some of them before the network was secured.

Once the practice identified the suspicious activity, it brought in outside cybersecurity specialists to investigate. This forensic team worked to contain the intrusion, secure the network, and figure out exactly what happened. As a result, the practice was able to determine which files were accessed and what information they contained.

After containment, the specialists conducted a detailed review of every affected file. This step took time because reviewing large volumes of medical records for exposed data is a careful, document-by-document process. The practice then used the findings to prepare notification letters, which is why patients did not learn about the incident until months after it was discovered.

Who was affected?

The Women’s Center for Radiology has confirmed that 66,422 patients were affected by this breach. That is a substantial number for a two-location practice, which suggests the exposed files covered a broad span of patient records rather than a narrow subset.

Because this is a women’s radiology provider, the affected group is almost certainly composed mostly of women who received imaging or diagnostic services at either Orlando center. In addition, the exposed data likely spans many years of patient visits, since medical record systems typically retain historical files for both current and former patients.

There is no indication in the notification that employees or minors were specifically targeted. However, because the practice serves patients of many ages, some records belonging to younger patients could be included among those affected. The practice has not indicated any narrower category within the total count.

What Information Was Potentially Exposed?

The forensic review found that the accessed files included a wide range of personal and medical details. This combination of data is especially concerning because it links medical history directly to identifying information like driver’s license numbers.

  • Full names
  • Home addresses
  • Dates of birth
  • Contact information (phone numbers and/or email)
  • Diagnosis and condition information
  • Lab test results
  • Treating and referring physician names
  • Medical record numbers
  • Driver’s license numbers
  • Health insurance information

This type of exposure creates several distinct risks. For example, driver’s license numbers combined with names and addresses can be used to open fraudulent accounts or pass identity checks. Meanwhile, health insurance information can be used to submit fake medical claims, which can quietly damage a patient’s coverage history without their knowledge.

Diagnosis and treatment details add another layer of risk beyond financial fraud. Because this information is deeply personal, its exposure can lead to unwanted disclosure of private health conditions. In some cases, stolen medical details are also used in targeted phishing scams that reference real diagnoses to appear more convincing.

What is the company doing?

After securing its network, the Women’s Center for Radiology began reviewing its data privacy and security policies. This includes examining internal procedures and processes with the goal of reducing the chance of a similar incident happening again.

The practice has stated that it has not found evidence that any patient data has actually been misused so far. Even so, as a precautionary measure, it is offering affected individuals complimentary credit monitoring and identity theft protection services. This gives patients a tool to watch for suspicious activity tied to their personal information.

The practice notified patients directly by mail once the file review was finished. In addition, it appears the incident has been reported through the appropriate federal channels required for healthcare providers handling protected health information.

What Should Affected Individuals Do?

Enroll in the Offered Credit Monitoring and Identity Protection Services

Affected patients should sign up for the free credit monitoring and identity theft protection being offered by the practice. This service can alert you quickly if someone tries to open new credit accounts using your information.

Because enrollment is time-limited in most breach notification offers, it’s wise to activate the service as soon as your notification letter arrives. Doing so early gives you the maximum benefit period and reduces the risk that you’ll forget or miss the deadline.

Watch for Signs of Medical Identity Theft

Since diagnosis, lab results, and insurance information were exposed, patients should review their insurance statements and explanation-of-benefits notices closely. Look for unfamiliar providers, unrecognized procedures, or claims for services you never received.

If anything looks off, contact your insurer immediately to dispute the charge. This matters because medical identity theft can affect your medical records and future coverage, not just your finances.

Consider a Fraud Alert or Credit Freeze

Because driver’s license numbers were exposed alongside names and addresses, affected individuals should consider placing a fraud alert or credit freeze with the three major credit bureaus. A freeze blocks new credit accounts from being opened in your name without extra verification.

This step is especially important here, since a driver’s license number combined with a full name and address gives criminals nearly everything needed to impersonate someone. Setting up a freeze is free and can be lifted temporarily whenever you need to apply for credit yourself.

Stay Alert to Phishing Attempts

Because scammers often use stolen medical details to craft convincing phishing emails or calls, affected patients should be cautious of unexpected messages referencing their health history. Never click links or share personal details in response to unsolicited contact.

Instead, verify any suspicious communication by contacting the Women’s Center for Radiology or your insurer directly using a known phone number. This simple habit can prevent a phishing attempt from turning into actual financial loss.

Monitor Your Credit Reports Regularly

All affected individuals should pull their free credit reports and review them for unfamiliar accounts or inquiries. Doing this regularly, not just once, helps catch fraud that may surface months after the breach.

If you notice unauthorized activity, report it immediately to the credit bureau and consider speaking with a data breach attorney. An attorney can help you understand whether you may be eligible for compensation given the specific harm you experienced.



Related Data Breaches

Check other recent data breach notifications →