Northeast Radiology
bd_ae55b2108f5ede74 · schema v1 · pii pii-v1
Full breach record for Northeast Radiology →Northeast Radiology, P.C. (NERAD) reported to HHS OCR on 2020-03-11 a Hacking/IT Incident affecting 298,532 individuals. Between April 2019 and January 2020, unauthorized individuals accessed radiology images stored on NERAD's PACS (Picture Archiving and Communication System) network server. OCR's investigation found NERAD failed to conduct a required risk analysis. NERAD paid a $350,000 settlement and entered a two-year corrective action plan as the 6th enforcement action under OCR's Risk Analysis Initiative.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 1, 2019
Begins
Mar 11, 2020
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Montana State AGbd_78fd7616737985cb2020-03-11Verified
- Massachusetts State AGbd_f306b619c132c28f2020-03-11Verified
- HHS OCR enforcementbd_0f3fa12d8c2e6fa02025-04-04 · +1850dVerified by operator
Filing propagation · 4 filings · 3 states
View merged incident ↗Pattern: first filing Mar 11 (MT), last Apr 4 — a 1850-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.