Torrance Memorial Medical Center notified patients of a data security incident involving an unsecured server used by an outside radiology vendor. The server was accessible from June 20, 2019, to December 13, 2019. Patient images and basic PII (name, DOB, MRN) were stored on the server, but no SSNs or financial data were involved. No evidence of unauthorized access to patient images was found. The vendor secured the server, and Torrance Memorial offered 12 months of identity monitoring services.