Lumexa Imaging
ent_64a7fbf309907ebbf65ff639
Disclosures
13
State AG · HHS OCR · 12 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
5,830,949
nationwide · HHS OCR NC
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Lumexa Imaging
- Normalized
- lumexa imaging— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- 0002071288
- Domain
- None on record
Disclosure history (13)newest first
- New Hampshire State AGas victim2026-06-12
Lumexa Imaging, a provider of administrative services to radiology practices, notified the NH Attorney General of a breach involving a third-party vendor. Between March 31 and April 9, 2026, an unauthorized individual accessed patient records, potentially exposing names, SSNs, DOBs, and clinical data for 186 NH residents. Lumexa disconnected systems, notified the AG on June 12, 2026, and offered credit monitoring via Kroll.
- Washington State AGas victim2026-06-12
Lumexa Imaging reported a third-party vendor breach affecting 3,632 Washington residents. Unauthorized access occurred March 31–April 9, 2026, exposing patient PII, SSNs, and clinical data. Lumexa detected the incident on April 15, 2026, and began notifying individuals on May 15, 2026. The vendor remediated the issue and Lumexa provided credit monitoring services.
- Nebraska State AGas victim2026-06-12
Lumexa Imaging, a provider of administrative services to radiology practices, notified Nebraska AG that a third-party vendor experienced unauthorized access to a network portion dedicated to Lumexa. Between March 31 and April 9, 2026, patient information (names, SSNs, DOB, clinical data) of approximately 157 Nebraska residents was accessed. Lumexa discovered the incident on April 15, 2026, disconnected systems, and began notifying affected individuals on May 15, 2026, offering credit monitoring via Kroll.
- Massachusetts State AGas victim2026-06-12
Lumexa Imaging, a provider of administrative services to radiology practices, disclosed a breach involving a third-party vendor's system. Between March 31 and April 9, 2026, an unauthorized individual accessed patient information, potentially including names, SSNs, DOBs, and clinical data. Lumexa disconnected systems, engaged Kroll for credit monitoring, and the vendor remediated by resetting passwords and enhancing monitoring. The incident affects residents in multiple states, primarily Massachusetts.
- Vermont State AGas victim2026-06-12
Lumexa Imaging reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-06-12. The reporting organization type is Health Care. 98 Vermont residents were affected. Categories of data breached: Social Security Numbers, Health Records.
- Texas State AGas victim2026-05-18
Lumexa Imaging based in Raleigh, North Carolina, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-04-15 and reported on 2026-05-18. 251 Texas residents were affected. 2,994 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Medical Information;Health Insurance Information. Consumers were notified via U.S. Mail.
- South Carolina State AGas victim2026-05-18
Lumexa Imaging notified South Carolina residents that an unauthorized individual accessed a third-party vendor's system between March 31 and April 9, 2026. Patient information, including names, SSNs, DOBs, and clinical data, may have been viewed. Lumexa disconnected from the vendor and Kroll is providing identity monitoring.
- Oregon State AGas victim2026-05-15
Lumexa Imaging reported a data breach to the Oregon Attorney General. The breach was reported on 2026-05-15. The breach occurred during 3/31/2026 - 4/9/2026. The breach was discovered on 4/15/2026. 2,994 individuals were affected. Notice was sent on 5/15/2026.
- NORTH CAROLINAHHS OCRas victim2026-05-15
Lumexa Imaging reported to HHS on 2026-05-15 a Hacking/IT Incident affecting 2994 individuals. Breached information located on Network Server.
- NORTH CAROLINAHHS OCRas victim2026-05-15
Lumexa Imaging reported to HHS on 2026-05-15 a Hacking/IT Incident affecting 5,830,949 individuals. Breached information located on Network Server. No business associate was involved.
- Montana State AGas victim2026-05-15
Lumexa Imaging notified individuals that an unauthorized individual accessed a third-party vendor's system, potentially viewing patient information. The incident occurred between March 31 and April 9, 2026. Lumexa discovered the suspicious activity on April 9, 2026. Data involved included names, SSNs, DOBs, and clinical information. Lumexa engaged Kroll for credit monitoring.
- California State AGas victim2026-05-15
Lumexa Imaging notified patients that an unauthorized individual accessed a third-party vendor's system between March 31 and April 9, 2026. The vendor provided non-clinical operational support. Patient information, including names, SSNs, dates of birth, and clinical health data, may have been viewed or obtained. Lumexa disconnected systems from the vendor network and is offering identity monitoring via Kroll.
- Illinois State AGas victim2026-05-01
LUMEXA IMAGING filed a data-breach notice with the Illinois Attorney General in May 2026 (case 26-05-1208). The register records the breach as discovered on April 15, 2026. Personal information types reported: medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
Subsidiary disclosures (newest 10)filed by group companies
◈ These filings were made by or about subsidiaries of Lumexa Imaging — not by Lumexa Imaging itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- California State AGvia Radiology Ltd.2022-10-07
Radiology Ltd. reported that between December 17 and December 24, 2021, an unauthorized party gained access to its network containing patient information. The incident was identified on December 24, 2021. Affected data may include names, addresses, dates of birth, Social Security numbers, health insurance information, medical record numbers, and radiology service details. The company notified law enforcement, engaged a forensic firm, and is offering one year of credit monitoring to affected individuals.
- Massachusetts State AGvia Gateway Diagnostic Imaging2022-09-02
Gateway Diagnostic Imaging reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-09-02. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGvia Radiology Ltd.2022-09-02
Radiology Ltd. notified Montana patients of a security incident where unauthorized access occurred between Dec 17-24, 2021. Patient PII, PHI, and SSNs were accessed. The company engaged forensic investigators and law enforcement, and offered one year of credit monitoring.
- Montana State AGvia Gateway Diagnostic Imaging2022-09-02
Gateway Diagnostic Imaging notified Montana patients of a security incident where unauthorized access occurred between Dec 17-24, 2021. Patient PII and PHI (names, SSNs, DOBs, medical records) were accessed. The company engaged forensic investigators and notified law enforcement. Affected individuals received one year of Equifax Credit Watch Gold.
- Montana State AGvia Diversified Radiology of Colorado, Inc.2022-02-18
Diversified Radiology of Colorado, Inc. reported a security incident where an unauthorized party accessed the network between Dec 17-24, 2021, copying patient documents containing PII and PHI. The company notified law enforcement and engaged forensic investigators. No fraud evidence was found at the time of notification.
- Montana State AGvia Touchstone Medical Imaging, LLC2022-02-18
Touchstone Medical Imaging, LLC reported that between Dec 17-24, 2021, an unauthorized party accessed its network and copied patient documents. Data included names, SSNs, DOBs, and PHI. The company notified law enforcement, engaged forensic investigators, and enhanced security safeguards. No fraud evidence found.
- New Hampshire State AGvia Touchstone Medical Imaging, LLC2022-02-18
Touchstone Medical Imaging, LLC reported a security incident in New Hampshire where an unauthorized party accessed the network between Dec 17-24, 2021, exfiltrating patient documents. One NH resident's name and SSN were compromised. TMI notified law enforcement, engaged forensic investigators, and offered one year of credit monitoring. The incident is contained.
- Illinois State AGvia Diversified Radiology of Colorado, Inc.2022-01-01
DIVERSIFIED RADIOLOGY OF COLORADO filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-131). The register records the breach as discovered on December 24, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGvia Touchstone Medical Imaging, LLC2022-01-01
TOUCHSTONE MEDICAL IMAGING, LLC filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-133). The register records the breach as discovered on December 24, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- FEDERALHHS OCR enforcementvia Touchstone Medical Imaging, LLC2019-05-06
Tennessee Diagnostic Medical Imaging Services Company (Touchstone) paid $3,000,000 to settle potential HIPAA Security and Breach Notification Rules violations involving a breach exposing over 300,000 patients' protected health information.