[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f36xgnb3909tku":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":23,"affectedCount":23,"affectedCountStatus":24,"affectedCountLowerBound":13,"affectedCountUnit":25,"hasEnglishDescription":4,"contentLocale":26,"availableLocales":27,"translations":29,"severity":32,"dataClasses":33,"description":56,"seoTitle":57,"seoDescription":58,"logoUrl":59,"isVerified":4,"isSensitive":4,"isSpamList":60,"isMalware":60,"company":61},"6a4f8e26c0e06d6639ce5f47","SimonMed Imaging 2025","SimonMed Imaging 2025 Data Breach","simonmed-imaging-2025","simonmed.com","2025-01-21T00:00:00.000Z","2026-07-09T12:03:50.572Z",null,"2026-07-19T00:11:06.963Z","Official company notice; California AG; Maine AG reporting cited by healthcare security reporting; healthcare security reporting; official website logo","https:\u002F\u002Fwww.simonmed.com\u002Fnotice-of-data-incident\u002F",[16,18,19,20,21,22],"https:\u002F\u002Foag.ca.gov\u002Fecrime\u002Fdatabreach\u002Freports\u002Fsb24-612578","https:\u002F\u002Foag.ca.gov\u002Fsystem\u002Ffiles\u002FSimonMed%20Individual%20Letter-%20SAMPLE.pdf","https:\u002F\u002Fwww.hipaajournal.com\u002Fsimonmed-imaging-confirms-january-2025-cyberattack\u002F","https:\u002F\u002Fwww.auntminnie.com\u002Fimaging-informatics\u002Fcybersecurity\u002Farticle\u002F15741679\u002Fsimonmed-confirms-data-breach","https:\u002F\u002Fsimonmed.com\u002F",1275669,"known","unknown","en",[26,28],"tr",{"en":30,"tr":31},{"slug":9},{"slug":9},"Critical",[34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55],"Names","Physical addresses","Dates of birth","Dates of service","Provider names","Medical record numbers","Patient numbers","Medical conditions","Diagnoses","Treatment information","Medical information","Medical images","Medications","Health insurance information","Driver's license numbers","Government issued IDs","Social security numbers","Tax identification numbers","Financial account numbers","Authentication credentials","Biometric data","Protected health information","\u003Cp>The SimonMed Imaging 2025 data breach is an unauthorized access incident that occurred on the network of an outpatient medical imaging provider working with numerous centers in the United States. The organization stated that after learning on January 27, 2025, that one of its vendors had experienced a security incident, it examined its own systems and identified suspicious activity on its network on January 28, 2025. As a result of the investigation, it was reported that there was unauthorized access to SimonMed systems between January 21, 2025, and February 5, 2025, and that files belonging to individuals were affected during this period.\u003C\u002Fp>\n\u003Cp>The scope of the incident is highly sensitive because it includes patient data, identification information, healthcare service records, and financial data categories together. The number of affected individuals has been reported as 1,275,669. This number should not be interpreted as the number of unique online accounts confirmed to have been leaked; it should be considered as the number of individuals for whom notification was made or who were determined to fall within the scope of the incident. Since the organization explained in its notification that the types of data may vary from person to person, this record does not claim that the same fields are present for each individual.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>Among the types of data that may be at risk in the SimonMed Imaging incident are first and last names, address, date of birth, service date, service provider name, medical record number, patient number, medical condition information, diagnosis and treatment information, medical images, medication information, health insurance information, driver's license number, government-issued identification information, Social Security number or tax identification number, financial account number, authentication information, and biometric identifiers. The presence of these fields within the same incident increases the risk of identity theft and medical identity fraud.\u003C\u002Fp>\n\u003Cp>Medical imaging data is more sensitive than ordinary communication information because it can lead to inferences about a person's health status, services received, diagnostic process, or treatment history. Official identification fields, such as Social Security number, tax identification number, driver's license, or government ID, pose a long-term risk because they are permanent. Individuals with financial account numbers or authentication information are at higher risk of account takeover, payment fraud, and targeted phishing. The compromise of biometric identifiers requires additional attention due to the unreproducible nature of the identity data.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>In this record, the breach start date has been used as January 21, 2025, because the disclosed unauthorized access period begins on this date. The date that SimonMed Imaging became aware of the incident has been evaluated as January 28, 2025. It has been reported that the unauthorized access period ended on February 5, 2025. The scope of the record relates to current and former patients receiving services from facilities operated by SimonMed or formerly operated by SimonMed. Therefore, an individual remembering their institution by only a single center name does not necessarily mean they were outside the incident.\u003C\u002Fp>\n\u003Cp>Although the data classes appear broad, this list does not indicate that the same fields exist for every individual. It has been stated in the organizational notice that the categories listed are general fields found in affected systems and may not apply to every individual. Therefore, the identity, health, financial, and biometric fields mentioned in the statement are presented as potential impact categories. The record does not contain a definite claim of misuse by attackers using this data; the security risk of the incident arises from the files being affected during unauthorized access.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>People in the highest risk group are those who have received medical imaging services from SimonMed Imaging centers or facilities later operated by SimonMed. Patients who have registered for MRI, CT, mammography, ultrasound, PET\u002FCT, X-ray, or similar diagnostic imaging services should take this into consideration. Fields such as the name of the service provider, date of service, medical record number, and patient number can lead not only to an identity risk but also to the targeted use of a person's healthcare history.\u003C\u002Fp>\n\u003Cp>For individuals whose official identification or financial data is affected, the risk of credit applications, bank account openings, payment redirection, and fraudulent indebtedness is higher. For individuals whose health insurance, medical imaging, diagnosis, or treatment information is affected, insurance claim abuse, unknown service registration, incorrect billing, or unauthorized transactions in health accounts may occur. Affected individuals with authentication information should use an additional security step in patient portals, payment systems, and health service accounts.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Individuals who may have been affected by this incident should first separate the types of data listed in the notification text under their names. If a Social Security number, tax identification number, driver’s license, or government ID is included, credit reports should be checked, and options such as credit freeze or fraud alert should be considered. Individuals with financial account numbers should closely monitor bank transactions, automatic payment instructions, and new creditor notifications. If authentication information is affected, changing passwords, enabling multi-factor authentication, and closing account sessions should be prioritized.\u003C\u002Fp>\n\u003Cp>Individuals with health data should check their explanation of benefits documents, health insurance claims, patient portal registrations, and clinical bills. If an unrecognized appointment, service, imaging request, prescription record, or payment is visible, a written objection should be made to the relevant healthcare provider and insurance institution. Be cautious of phishing messages; attackers may request personal information under the pretext of an appointment update, imaging result, payment discount, patient account verification, or free protection service. Typing the institution's address manually instead of clicking on a link is a safer method.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>In incidents like the SimonMed Imaging 2025 data breach, where health and official identity information are both affected, the protection period should be kept long. While changing passwords is helpful, it is not sufficient on its own; because the incident may involve permanent identity fields, healthcare service history, and financial information. Users should regularly review their credit reports, be alert for fraudulent applications before tax season, periodically check insurance service statements, and report unexplained healthcare services early.\u003C\u002Fp>\n\u003Cp>Strong and unique passwords should be used on patient portals, multi-factor login should be enabled where possible, and old phone or email information should be updated. New service notification, new claim, and payment notification options can be enabled on the health insurance account. Individuals whose official identification information has been affected should continue to monitor credit applications, bank correspondence, insurance claims, and healthcare records not only in the first weeks but also in the following months. In the event of a suspicious transaction, the date, institution name, transaction number, and correspondence should be kept.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>The record check on this page helps the user determine whether they are associated with the SimonMed Imaging 2025 data breach. A match does not mean that all types of data on the list were exposed for the same individual. The data classes included in the notification sent to the person should also be reviewed separately. If the user received services from SimonMed or a facility now operated by SimonMed and received a physical notification, the details in that notification should be used as the basis.\u003C\u002Fp>\n\u003Cp>After users see the impact status, they should prioritize their steps according to the type of data. If there is identity data, credit and official application checks should be prioritized; if there is financial data, banking and payment checks should take precedence; if there is health data, insurance and patient record checks should be prioritized. Since medical imaging and diagnostic records can be used for personalized fake messages, identity information should not be shared in unexpected calls or messages. The SimonMed Imaging 2025 data breach is a large-scale health data security incident that shows how critical internal network review is following a supplier alert in medical imaging services.\u003C\u002Fp>","SimonMed Imaging 2025 Data Breach (1.3 Million Reported Records)","SimonMed Imaging 2025 Data Breach. 1.3 Million reported records are reported. Reported data: Names, Physical addresses, Dates of birth. Review the scope…","\u002Fuploads\u002Flogo\u002Fsimonmed-imaging-2025.svg",false,{"name":62,"sector":63,"country":64,"website":10,"websiteArchiveUrl":65,"websiteStatus":65,"websiteCheckedAt":13},"SimonMed Imaging","Healthcare","United States",""]