Confirmed breach. Intrusion Mar 31, 2026–Apr 9, 2026, discovered Apr 9, 2026 — the first regulatory filing landed 36 days later (flagged late). 3,246 individuals reported across the linked filings.
Lumexa Imaging reported a data breach to the Oregon Attorney General. The breach was reported on 2026-05-15. The breach occurred during 3/31/2026 - 4/9/2026. The breach was discovered on 4/15/2026. 2,994 individuals were affected. Notice was sent on 5/15/2026.
Affected (this filing): 2,994
OR AG ≤45d
🇺🇸NCHHS OCRlinked via same-victim cross-source · 100%
Lumexa Imaging reported to HHS on 2026-05-15 a Hacking/IT Incident affecting 2994 individuals. Breached information located on Network Server.
Affected (this filing): 2,994
HHS notified
Most recent
5 State AG filingsMay 15, 2026 – Jun 1, 2026ExpandCollapse
MTCATXSCMA
Montana State AG
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Lumexa Imaging reported a data breach to the Montana Attorney General. The breach was reported on 2026-05-15. The breach occurred from 03/31/2026 to 04/09/2026. 1 Montana residents were affected.
Affected (this filing): 1
🐻California State AGlinked via multistate filing link · 100%
Lumexa Imaging notified patients that an unauthorized individual accessed a third-party vendor's system between March 31 and April 9, 2026. The vendor provided non-clinical operational support. Patient information, including names, SSNs, dates of birth, and clinical health data, may have been viewed or obtained. Lumexa disconnected systems from the vendor network and is offering identity monitoring via Kroll.
⭐Texas State AGlinked via multistate filing link · 100%
Lumexa Imaging based in Raleigh, North Carolina, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-04-15 and reported on 2026-05-18. 251 Texas residents were affected. 2,994 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Medical Information;Health Insurance Information. Consumers were notified via U.S. Mail.
Affected (this filing): 251
TX AG >30d
🌴South Carolina State AGlinked via same-victim cross-source · 100%
Lumexa Imaging notified South Carolina residents that an unauthorized individual accessed a third-party vendor's system between March 31 and April 9, 2026. Patient information, including names, SSNs, DOBs, and clinical data, may have been viewed. Lumexa disconnected from the vendor and Kroll is providing identity monitoring.
🏛️Massachusetts State AGlinked via multistate filing link · 95%
Lumexa Imaging, a provider of administrative services to radiology practices, disclosed a breach involving a third-party vendor's system. Between March 31 and April 9, 2026, an unauthorized individual accessed patient information, potentially including names, SSNs, DOBs, and clinical data. Lumexa disconnected systems, engaged Kroll for credit monitoring, and the vendor remediated by resetting passwords and enhancing monitoring. The incident affects residents in multiple states, primarily Massachusetts.