HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Lumexa Imaging
bd_f8f018a48f8bf529 · schema v1 · pii pii-v1
Full breach record for Lumexa Imaging →Lumexa Imaging notified South Carolina residents that an unauthorized individual accessed a third-party vendor's system between March 31 and April 9, 2026. Patient information, including names, SSNs, DOBs, and clinical data, may have been viewed. Lumexa disconnected from the vendor and Kroll is providing identity monitoring.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_1b89348888381ce9Texas State AGfiled 2026-05-18Verified
- bd_24fcdf7525cc1b2cOregon State AGfiled 2026-05-15(3d gap)Candidate
- bd_2d74a3ba57b9a7e7HHS OCRfiled 2026-05-15(3d gap)Verified
- bd_8c8f4be9987cfe0dMontana State AGfiled 2026-05-15(3d gap)Verified
Show 2 more filings ↓Show fewer ↑up to 14d gap
- bd_e191ee35db29e731California State AGfiled 2026-05-15(3d gap)Verified
- bd_d87e7e4891670bc6Massachusetts State AGfiled 2026-06-01(14d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/Consumer%20Letter%20-%20Lumexa%20Imaging.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 18, 2026
- Raw hash
- 4fee7240675c42c491f02c303075a11de9bed986af5f4398b3078e7d9f91b2b8
Reporting entity
- Name
- Lumexa Imagingnorm: lumexa imaging
Victim entity
- Name
- Lumexa Imagingnorm: lumexa imaging
Incident
- Discovered
- Apr 9, 2026
- Materiality determined
- —
- Notification sent
- Apr 15, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 6 weeks(39 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.