Radiology Associates of Richmond Suffers Major Data Breach Affecting 266,000 Individuals
Radiology Associates of Richmond (RAR), a Virginia-based healthcare provider, disclosed a significant data breach impacting approximately 266,000 individuals. The incident involved unauthorized access to sensitive data, including protected health information (PHI), personally identifiable information (PII), and financial details such as Social Security numbers, medical records, and credit/debit account information.
The breach was discovered on or around July 25, 2025, though regulatory filings suggest the intrusion may have occurred between April 2–6, 2024, with detection delayed until May 2, 2025. This discrepancy in timelines remains unresolved, but all sources confirm that notification letters to affected individuals began on May 21, 2026. The breach was reported to the U.S. Department of Health and Human Services (HHS) on July 1, 2025, and to multiple state attorneys general, reflecting its regulatory significance.
Forensic investigations confirmed the unauthorized acquisition of files containing PHI, though no evidence of ransomware, phishing, or specific malware has been publicly identified. The attack vector and threat actor remain unknown, with no technical indicators of compromise (IOCs) or attribution to a known group. While healthcare organizations are frequent targets for data theft often via phishing, remote service exploitation, or credential compromise this incident lacks specific technical details linking it to established tactics.
As of the latest disclosures, there is no indication that the compromised data has been misused. However, the breach underscores persistent vulnerabilities in the healthcare sector, where legacy systems, high-value data, and regulatory pressures make providers prime targets. The incident highlights the need for robust security controls, timely detection, and comprehensive incident response in protecting sensitive patient information.
RADIOLOGY ASSOCIATES OF RICHMOND, INC cybersecurity rating report: https://www.rankiteo.com/company/radiology-associates-of-richmond-inc
"id": "RAD1779784404",
"linkid": "radiology-associates-of-richmond-inc",
"type": "Breach",
"date": "4/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '266000',
'industry': 'Healthcare',
'location': 'Virginia, USA',
'name': 'Radiology Associates of Richmond (RAR)',
'type': 'Healthcare Provider'}],
'customer_advisories': 'Notification letters sent to affected individuals '
'starting May 21, 2026',
'data_breach': {'number_of_records_exposed': '266000',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Protected health information '
'(PHI)',
'Personally identifiable '
'information (PII)',
'Social Security numbers',
'Medical records',
'Credit/debit account '
'information']},
'date_detected': '2025-05-02',
'date_publicly_disclosed': '2025-07-01',
'description': 'Radiology Associates of Richmond (RAR), a Virginia-based '
'healthcare provider, disclosed a significant data breach '
'impacting approximately 266,000 individuals. The incident '
'involved unauthorized access to sensitive data, including '
'protected health information (PHI), personally identifiable '
'information (PII), and financial details such as Social '
'Security numbers, medical records, and credit/debit account '
'information.',
'impact': {'data_compromised': 'Protected health information (PHI), '
'personally identifiable information (PII), '
'Social Security numbers, medical records, '
'credit/debit account information',
'identity_theft_risk': 'High',
'payment_information_risk': 'High'},
'investigation_status': 'Ongoing',
'lessons_learned': 'The incident underscores persistent vulnerabilities in '
'the healthcare sector, where legacy systems, high-value '
'data, and regulatory pressures make providers prime '
'targets. The need for robust security controls, timely '
'detection, and comprehensive incident response in '
'protecting sensitive patient information is highlighted.',
'references': [{'source': 'Regulatory filings'}],
'regulatory_compliance': {'regulations_violated': ['HIPAA'],
'regulatory_notifications': ['U.S. Department of '
'Health and Human '
'Services (HHS)',
'State attorneys '
'general']},
'response': {'communication_strategy': 'Notification letters sent to affected '
'individuals starting May 21, 2026'},
'title': 'Radiology Associates of Richmond Suffers Major Data Breach '
'Affecting 266,000 Individuals',
'type': 'Data Breach'}