All Breaches
March 31, 2026 Verified Unknown

Lumexa Imaging 2026

The Lumexa Imaging 2026 data breach concerns unauthorized access in a vendor system that provides support services for Lumexa Imaging’s affiliated radiology practices and imaging centers. According to the official patient notification, the vendor reported on April 9, 2026, that it was investigating suspicious activity in its network section containing patient data belonging to Lumexa. Lumexa disconnected its systems from the vendor network and on April 15, 2026, learned that an unauthorized individual may have viewed or copied patient records belonging to the affiliated radiology practices and imaging centers. The period during which the records were accessed is between March 31, 2026, and April 9, 2026. In the public health breach record, the incident appears as a hacking event affecting 2,994 individuals.The notification indicates that data types vary according to the document and the person; therefore, users should check the fields included in their own notification separately.

Leaked Data Types and Risks

The types of data reported in the Lumexa Imaging incident may include patient name, date of birth, address, phone number, patient account number, insurance information, and clinical information related to radiology services. The scope of clinical information may include visit dates, diagnoses, or other health information related to imaging services. It has been stated that Social Security numbers may also have been included for a limited number of individuals. When these fields are considered together, they pose significant risks in terms of health privacy, insurance fraud, targeted social engineering, and identity theft. In particular, the context of radiology services can make fake appointment, result notification, insurance approval, or bill correction messages appear convincing.

Variation of data types by person is an important boundary. Not every affected individual may have their Social Security number or all clinical details impacted. Nevertheless, even the combination of patient name, date of birth, address, phone number, and insurance information can be sufficient for health account verification, fraudulent payment claims, or patient portal phishing. Patient account numbers and radiology service information can help fraudsters act as if there is a real service relationship. For this reason, the incident should be evaluated not only as a contact information leak but as a high-sensitivity breach where health and identity data are present together.

Verified Scope and Boundaries

The basic timeline of the incident is clearly verified. Unauthorized access to the supplier systems occurred between March 31, 2026, and April 9, 2026; the supplier reported the suspicious activity to Lumexa on April 9, 2026; Lumexa learned on April 15, 2026, that patient records may have been viewed or copied. The public health breach record shows a scope of 2,994 individuals with a report date of May 15, 2026. This record has been marked as verified because the official patient notification supports the data fields, and the public record supports the number of individuals and type of breach.

The scope should still not be generalized for all Lumexa patients or all affiliated radiology practices. The notification indicates that the incident occurred in a specific part of the supplier's network and that the documents were associated with affiliated radiology practices and imaging centers. Not every document may contain the same fields; for some individuals, only basic identification and contact information may be present, for others insurance and clinical information, and for a limited group, a Social Security number may be included. Therefore, user matching does not mean that all data types definitively belong to that user; however, caution is warranted due to the risk associated with health data.

User Groups at Risk

The main group at risk consists of patients who receive services through Lumexa Imaging’s affiliated radiology practices or imaging centers. Individuals associated with affiliated practices, such as Charlotte Radiology, may be included in this dataset even if they do not directly recognize the Lumexa name. Since radiology services typically involve referral, insurance approval, imaging appointment, result reporting, and billing processes, a patient may have records associated with multiple institutions. Therefore, users who find a match should consider notifications from not only the Lumexa name but also the affiliated radiology center, insurance company, and healthcare provider.

The Social Security number carries a higher risk of identity theft for the affected limited group. For individuals with clinical data such as insurance information, visit date, and diagnosis, the risk of health privacy breaches and fraudulent health communications is more prominent. Users with phone and address information can be targeted via mail, calls, or text messages. Patient account numbers can be used in fake patient portal or billing verification attempts. Especially topics such as expected imaging results, insurance approvals, or payment corrections can appear realistic in fraud messages; users should verify such requests directly through known institutional channels.

Urgent Measures to Be Taken

Users matching the Lumexa Imaging record should first check the notification they receive to try to understand which types of data are present in their records. Unique passwords should be used for the patient portal, radiology center account, insurance account, and email account, and multi-factor authentication should be enabled wherever possible. Unexpected imaging results, invoices, insurance approvals, appointment updates, or patient account verification requests should be confirmed directly through known clinic or insurance channels. Entering credentials through a link or sharing personal data over the phone is risky.

Users affected by their Social Security number should check their credit reports and consider options such as credit freezing or fraud alerts. Users affected by insurance information or clinical data should periodically review explanation documents, medical bills, and service lists. If unrecognized medical services, incorrect appointments, unknown imaging procedures, or unexpected insurance claims are observed, the healthcare provider and insurance company should be contacted immediately. Even if the institution states that there is no evidence of misuse, early monitoring is important because risks may emerge later in such cases.

Long-Term Security Strategies

This incident shows that supplier connections in imaging and radiology services are critical in terms of patient data. In the long term, users should monitor not only major healthcare institutions but also radiology centers, laboratories, insurance, and medical billing notifications. In events involving health data, risk is not only measured by financial account activity; it can also appear as false health communication, incorrect billing, insurance fraud, or authentication attempts. Therefore, notification letters should be kept, noting which institution reported the incident on which date, and compared with subsequent health disclosures.

For institutions, the most critical aspects in supplier network connections are minimal permissions, detailed access logs, alerts for unusual document access, rapid disconnection procedures, and supplier security audits. On the user side, strong password management, keeping patient portal notifications enabled, regularly checking insurance documents, and verifying unexpected health communications are the most effective defenses. Since a limited group may have a Social Security number, the user should finalize the fields in their notification and, if necessary, turn identity protection steps into a long-term habit.

Record Control and User Action

A match with Lumexa Imaging as of 2026 indicates that the user may be included in the patient records of the affiliated radiology or imaging center. In case of a match, the user should check the radiology service history, insurance explanation documents, patient portal activities, and types of data in the notification letter together. If the Social Security number is included in the notification, credit report, credit freeze, and fraud alert options should be considered. Even if only health and insurance information is present, caution should be exercised against healthcare fraud and fake invoice risks.

This record does not contain financial card or bank account information; no such field is indicated in the official notice. On the other hand, the patient account number, insurance information, and clinical data are valuable enough for personalized phishing messages. Users should verify unexpected messages using the names Lumexa, the affiliated radiology center, the insurance company, or the patient portal directly through official communication channels. In incidents involving health data, harm is sometimes detected late; therefore, credit, insurance, and healthcare checks should be maintained not only during the initial notification period but also in the subsequent months.

3 Thousand
Affected Accounts
9
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

9
Names
Dates of birth
Physical addresses
Phone numbers
Patient IDs
Health insurance information
Medical records
Personal health data
Social security numbers

Additional Information

Added DateJuly 7, 2026
Breach DateMarch 31, 2026
Domainlumexaimaging.com
SourceOfficial patient notice, federal health breach portal, and state notification references
Last Content UpdateJuly 19, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information