HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Lumexa Imaging
bd_d87e7e4891670bc6 · schema v1 · pii pii-v1
Full breach record for Lumexa Imaging →Lumexa Imaging, a provider of administrative services to radiology practices, disclosed a breach involving a third-party vendor's system. Between March 31 and April 9, 2026, an unauthorized individual accessed patient information, potentially including names, SSNs, DOBs, and clinical data. Lumexa disconnected systems, engaged Kroll for credit monitoring, and the vendor remediated by resetting passwords and enhancing monitoring. The incident affects residents in multiple states, primarily Massachusetts.
Massachusetts clock⏱ MA AG >30d8 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1b89348888381ce9Texas State AGfiled 2026-05-18(14d gap)Verified
- bd_f8f018a48f8bf529South Carolina State AGfiled 2026-05-18(14d gap)Verified
- bd_24fcdf7525cc1b2cOregon State AGfiled 2026-05-15(17d gap)Candidate
- bd_2d74a3ba57b9a7e7HHS OCRfiled 2026-05-15(17d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 17d gap
- bd_8c8f4be9987cfe0dMontana State AGfiled 2026-05-15(17d gap)Verified
- bd_e191ee35db29e731California State AGfiled 2026-05-15(17d gap)Verified
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-972-lumexa-imaging/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 1, 2026
- Raw hash
- d94d77924d2e4c1b453bc279130812031a669ae4b0f4e48409bcc40045938c04
Reporting entity
- Name
- Lumexa Imagingnorm: lumexa imaging
Victim entity
- Name
- Lumexa Imagingnorm: lumexa imaging
Incident
- Discovered
- Apr 9, 2026
- Materiality determined
- —
- Notification sent
- Apr 15, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 8 weeks(53 days from discovery to filing)
- Compliance flags
- MA AG >30d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.