The Northwest Radiologists / Mount Baker Imaging 2025 data breach was an unauthorized-access incident in the Washington-based radiology organization’s network from January 20 through January 25, 2025. According to the organization’s official notice, the actor accessed personal and protected health information stored on affected systems; the current nationwide federal record lists 362,713 affected people.
The Washington Attorney General record lists 348,118 people in the state, while the U.S. Department of Health and Human Services Office for Civil Rights lists 362,713 people in total. The figures are compatible: the first covers Washington residents only and the second is the federal incident total. LeakData imported no patient rows; importedRecordCount is zero, and this entry contains verified incident metadata only.
How Was the Northwest Radiologists Breach Confirmed?
The primary source is the Washington Attorney General’s breach record and its attached consumer notice signed on behalf of Northwest Radiologists and Mount Baker Imaging. The official filing directly confirms the access dates, nature of the event, information categories, protective measures, and number of affected Washington residents.
The second source is the HHS OCR breach portal, which classifies the organization as a Healthcare Provider and the event as a Hacking/IT Incident involving a Network Server. The third is SecurityWeek’s August 4, 2025 report. It independently describes the timeline, scope, and data types using the Washington filing and the organization’s statements.
What Happened Between January 20 and January 25, 2025?
Northwest Radiologists experienced a network disruption affecting certain systems on or about January 25. After discovering it, the organization secured the environment, contacted law enforcement, and engaged third-party specialists to establish the event’s nature and scope. The forensic investigation determined that unauthorized access began January 20 and continued through January 25.
The organization then reviewed the contents of affected systems to identify which information related to which people and obtained current addresses before preparing notices. The breachDate field uses January 20, 2025, the confirmed start of access in the official record, rather than the day the disruption was discovered or the later notification date.
What Information Was Affected?
The fields varied by person and may include first and last names with addresses, phone numbers, email addresses, dates of birth, Social security numbers, driver’s-license or state-identification numbers, military identification, treatment or diagnosis details, provider names, medical-record or patient-identification numbers, health-insurance information, and treatment costs.
The Washington Attorney General also lists financial and banking information among the affected categories. The sources do not say every field belonged to all 362,713 people, so this entry creates no subgroup counts. It adds no undisclosed passwords or payment cards and does not claim the data was published or attribute the incident to a named ransomware group.
How Was the Scope of 362,713 People Determined?
The pwnCount and totalRecords fields use the 362,713-person count in HHS OCR’s current federal row, reported on October 28, 2025. The Washington Attorney General filing submitted July 10 lists 348,118 Washington residents. The difference of 14,595 represents the gap between the federal and single-state totals; there is no evidence that the same people were counted twice.
SecurityWeek used roughly 350,000 Washingtonians in its August 2025 headline while reporting the official 348,118 figure in the article, making the headline a rounded state count. Because HHS later published the nationwide total, this entry uses 362,713 as its main value. It counts affected people, not images, examinations, files, or individual data elements.
What Measures Did the Organization Take?
Northwest Radiologists said it secured its systems, worked with law enforcement and outside forensic specialists, implemented additional technical safeguards, and reviewed security policies and procedures. Affected people were offered complimentary credit monitoring and identity-protection services; the public notice template does not state the duration of those services.
At the time of notice, the organization said it had no reason to believe the information had been or would be misused because of the event. That statement does not negate the confirmed access or guarantee against later misuse. The sources connect the incident to no specific malware, ransomware group, or leak site, so this entry makes no threat-actor attribution.
What Should Affected Patients Do?
Notice recipients should activate the complimentary protection service within the enrollment period and regularly review credit reports, bank accounts, health-insurance explanation-of-benefits statements, and medical-service histories for unfamiliar activity. Suspicious activity should be reported through a verified official channel for the relevant institution.
The possible combination of Social security numbers, identity documents, financial information, and health data creates lasting identity-theft and medical-fraud risk. Patients should watch for unfamiliar bills or insurance statements, new accounts, and links claiming to come from Northwest Radiologists or Mount Baker Imaging. LeakData does not host, distribute, or provide search access to patient data.