Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsChecklistsAI RankingsNewsletterStatusTagsAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Checklists
AI Rankings
Newsletter
Status
Tags
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1158+ Articles
126+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. 266,000 Affected by Data Breach at Radiology Associates of Richmond
266,000 Affected by Data Breach at Radiology Associates of Richmond
NEWS

266,000 Affected by Data Breach at Radiology Associates of Richmond

Radiology Associates of Richmond has disclosed a cyberattack in which threat actors stole files containing names and protected health information belonging to approximately 266,000 patients.

Dylan H.

News Desk

May 25, 2026
5 min read

Overview

Radiology Associates of Richmond, a medical imaging provider serving patients in Virginia, has disclosed a data breach affecting approximately 266,000 individuals. Threat actors gained unauthorized access to the organization's systems and exfiltrated files containing patient names and protected health information (PHI), according to the breach notification filed with the U.S. Department of Health and Human Services.

The incident follows a sustained wave of cyberattacks targeting healthcare imaging organizations throughout 2026.


Incident Details

What Happened

Radiology Associates of Richmond discovered that an unauthorized party had accessed its systems and stolen files containing sensitive patient data. The organization launched an investigation with the help of cybersecurity professionals and notified federal authorities.

The exact attack vector — whether ransomware, data extortion, or another intrusion method — has not been specified in public disclosures. Radiology practices have been a particularly attractive target for ransomware operators in 2026 due to the high sensitivity of imaging data and the operational pressure to restore systems quickly.

Timeline

  • Breach discovery: Internal detection or third-party alert triggered investigation
  • Investigation: Forensic review to determine scope and affected records
  • HHS notification: Filed with the breach notification portal
  • Public disclosure: May 25, 2026
  • Patient notification: Written letters being sent to affected individuals

Affected Individuals

MetricDetail
Total affected266,000 individuals
OrganizationRadiology Associates of Richmond
LocationRichmond, Virginia
TypeHIPAA-covered entity (healthcare provider)

Data Categories Exposed

The stolen files contained the following categories of protected health information:

Personal Identifiers

  • Full patient names
  • Dates of birth
  • Addresses and contact information
  • Social Security numbers (scope under investigation)

Medical Information

  • Radiology orders and imaging study details
  • Dates of service
  • Referring physician information
  • Diagnostic codes and clinical notes

Administrative Data

  • Insurance policy information
  • Billing records
  • Internal patient identifiers

The combination of personally identifiable information with detailed medical imaging records presents significant risks for affected individuals, including insurance fraud, medical identity theft, and targeted social engineering attacks.


Impact on Affected Patients

Immediate Risks

Medical Identity Theft — Stolen radiology records and insurance information can be used to fraudulently bill insurers for medical services or obtain prescription medications.

Targeted Phishing — Attackers in possession of detailed medical histories often craft highly convincing phishing messages that reference real treatment details, increasing click-through rates dramatically.

Insurance Fraud — PHI combined with insurance policy numbers enables fraudulent claims submissions that may affect patients' coverage or out-of-pocket costs.

What to Do If You're Affected

  1. Watch for your notification letter — Radiology Associates of Richmond is required to notify all 266,000 affected individuals by mail
  2. Accept the offered credit and identity monitoring — these services typically include dark web monitoring for your information
  3. Review your Explanation of Benefits (EOB) statements from your health insurer for any unfamiliar charges
  4. Check your medical records via your patient portal for any unauthorized changes
  5. Place a credit freeze with Equifax, Experian, and TransUnion to prevent new account fraud
  6. File an FTC report at identitytheft.gov if you discover your information has been misused

Radiology Sector Under Siege

The healthcare imaging sector has faced intensifying cyberattacks throughout 2025 and 2026. Radiology organizations hold some of the most comprehensive and sensitive patient data in healthcare — imaging studies combined with clinical history paint a detailed picture of a patient's health — making them highly attractive targets.

Contributing factors to the sector's vulnerability include:

  • Legacy imaging systems (PACS/RIS) that are difficult to patch and often run outdated software
  • Integration with hospital networks creating broad access paths for attackers
  • Operational pressure — downtime directly affects patient care, making ransom payment more likely
  • Third-party connectivity with referring physicians, labs, and insurance networks

2026 Healthcare Breach Context

OrganizationAffectedCategory
Qualderm Partners3.1 millionDermatology
Oncology InstituteTBDOncology
OpenLoop Health716,000Mental health
Sandhills Medical170,000General healthcare
Radiology Associates of Richmond266,000Medical imaging

HIPAA Compliance and Regulatory Response

As a HIPAA-covered entity, Radiology Associates of Richmond is subject to specific breach notification requirements under the HIPAA Breach Notification Rule:

  • Individual notification within 60 days of breach discovery (written mail)
  • HHS notification via the HHS breach portal (completed as of disclosure date)
  • Media notification if more than 500 residents of any single state are affected
  • Business Associate Agreement review to assess vendor liability

The HHS Office for Civil Rights (OCR) may open an investigation following the breach report, particularly given the scale of 266,000 affected individuals.


Recommendations for Healthcare Imaging Organizations

  • Segment PACS and RIS systems from general corporate networks
  • Apply patches aggressively to imaging infrastructure, even when vendor certification is required
  • Implement network monitoring specifically tuned for large data transfers from imaging servers
  • Require multi-factor authentication on all remote access to imaging systems
  • Conduct regular penetration testing focused on medical device and imaging infrastructure
  • Maintain offline backups of imaging data to enable recovery without paying ransom

Sources

  • SecurityWeek — 266,000 Affected by Data Breach at Radiology Associates of Richmond

Related Reading

  • Oncology Institute Discloses Data Breach
  • Millions Impacted Across Several US Healthcare Data Breaches
  • Sandhills Medical Says Ransomware Breach Affects 170,000
#Data Breach#Healthcare

Related Articles

Verizon DBIR 2026: Healthcare Fends Off Rising Social Engineering Attacks

The 2026 Verizon Data Breach Investigations Report highlights how evolving social engineering tactics are making the healthcare sector more vulnerable,...

6 min read

Millions Impacted Across Several US Healthcare Data Breaches

Multiple healthcare data breaches impacting hundreds of thousands to millions of individuals have been added to the HHS breach tracker, continuing a...

5 min read

716,000 Impacted by OpenLoop Health Data Breach

Telehealth platform OpenLoop Health has disclosed that a January 2026 cyberattack resulted in the exfiltration of personal information belonging to...

4 min read
Back to all News