HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Lumexa Imaging
bd_e191ee35db29e731 · schema v1 · pii pii-v1
Full breach record for Lumexa Imaging →Lumexa Imaging notified patients that an unauthorized individual accessed a third-party vendor's system between March 31 and April 9, 2026. The vendor provided non-clinical operational support. Patient information, including names, SSNs, dates of birth, and clinical health data, may have been viewed or obtained. Lumexa disconnected systems from the vendor network and is offering identity monitoring via Kroll.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_24fcdf7525cc1b2cOregon State AGfiled 2026-05-15Candidate
- bd_2d74a3ba57b9a7e7HHS OCRfiled 2026-05-15Verified
- bd_8c8f4be9987cfe0dMontana State AGfiled 2026-05-15Verified
- bd_1b89348888381ce9Texas State AGfiled 2026-05-18(3d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 17d gap
- bd_f8f018a48f8bf529South Carolina State AGfiled 2026-05-18(3d gap)Verified
- bd_d87e7e4891670bc6Massachusetts State AGfiled 2026-06-01(17d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-623542
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 15, 2026
- Raw hash
- 7a6625caef481fe1019ab6209e5441d4a9c23bdda6695c1396bd706c5a9a853c
Reporting entity
- Name
- Lumexa Imagingnorm: lumexa imaging
Victim entity
- Name
- Lumexa Imagingnorm: lumexa imaging
Incident
- Discovered
- Apr 15, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Third party
- via Vendor (unnamed)
- Initial access
- supply_chain
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.