Radiology Associates of Richmond
266,000 people at one imaging practice. The images are the smallest part of the problem.
What happened?
Radiology Associates of Richmond reported a data breach affecting approximately 266,000 individuals. The full field list has not been publicly enumerated as of this writing and no threat actor has been publicly attributed.
What data was actually inside?
Not fully disclosed. What a radiology practice holds, labeled as inference from the billing and clinical workflow: patient identity and demographics, insurance and billing records, the ordering physician, the clinical indication that justified the imaging, the radiologist's report, and the images themselves.
The clinical indication is the sensitive field, and it is easy to overlook. A radiology record does not say "routine visit." It records why the scan was ordered — suspected malignancy, trauma consistent with assault, pregnancy dating, cognitive decline workup. The reason for the image is frequently more disclosive than the image.
Who gets hurt and how?
266,000 people who were referred for imaging, most of whom have no relationship with the practice at all. You are referred, you are scanned, you leave. The practice bills your insurer and you may never think about it again.
The harm is disclosure of a medical trajectory. An indication field reading "rule out malignancy" discloses that a physician suspected cancer. A record of imaging consistent with assault discloses violence. Pregnancy dating discloses a pregnancy, including one that may not have continued. None of these can be remediated, and none is protected by credit monitoring.
Standard identity harms apply too, since billing requires the insurance and demographic data that supports medical identity theft.
What did they think they were doing right?
While not publicly confirmed for this practice, radiology groups operate under HIPAA with documented security risk assessments, and their imaging systems are typically supplied by established vendors with their own security programmes.
The structural issue is size mismatch rather than negligence. A practice serving 266,000 people is, by headcount and revenue, a mid-sized business. Its data footprint is hospital-scale. There is no in-house security function, no incident response team, and no budget line for either, because the organisation is sized to read scans rather than to run a security programme.
What did they not know about their own data?
Medical imaging has a specific and under-appreciated inventory problem. DICOM files embed patient identifiers directly in file metadata, which means an image is identity data even when separated from the database that indexes it. A folder of scans copied to a research share or a vendor's support environment carries names, dates of birth, and accession numbers inside the files themselves.
Imaging archives are also enormous and long-lived. State law requires retention for years, volumes grow continuously, and storage decisions are driven by capacity and cost rather than by security. So imaging data routinely ends up on systems chosen because they were big and cheap, outside whatever perimeter protects the practice management system.
The question worth asking in any organisation is where the files too large for the main system ended up, and who has looked inside them recently.
If your environment was compromised today, could you say within 24 hours exactly what sensitive data was accessed?
What does attribution look like the morning after?
HIPAA applies with its 60-day notification deadline and reporting to the HHS Office for Civil Rights, with the breach appearing on the OCR breach portal. At 266,000 individuals, media notice is required and Virginia's state statute applies in parallel.
Determining scope in an imaging breach is harder than in a records breach. Establishing which patients appear requires reading file metadata across an archive that may span years and multiple storage systems, and the practice must also notify referring physicians and the hospitals it serves, since those relationships carry their own contractual obligations. All of this is contracted out, at unbudgeted expense, by an organisation with no capacity to run it internally.
What would have changed the outcome?
Knowing where the imaging archives live and what is embedded in the files — because the identifiers are inside the images, not only in the database.
Every organisation has data that outgrew its primary system: imaging archives, video, scanned documents, backups of backups. These move to whatever storage was cheapest, they carry identifiers inside the files where no database scan finds them, and they are almost never re-inventoried after the migration. If your data map covers the systems people log into, it is missing the ones that simply hold volume. See also our analysis of the ClarityCheck breach, another case of image stores nobody had characterised.
Radiology Associates of Richmond found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.