The Saint Pete MRI 2025 data breach emerged when the Florida imaging center and sleep lab identified suspicious network activity around February 23, 2025. Independent forensic specialists confirmed that electronic patient-care and imaging systems were not accessed, but concluded that certain scanned data may have been acquired without authorization.
A comprehensive file review determined on April 7, 2026 that personal information may have been present in the affected data; identity and contact verification was completed July 15. Possible fields were names, Social security numbers, dates of birth, driver's-license or state-identification numbers, medical information, and health-insurance information. No deduplicated national total was published, so pwnCount and totalRecords are zero, and importedRecordCount is zero.
How Was the Saint Pete MRI Breach Confirmed?
The primary source is Saint Pete MRI's official “Substitute Notice” PDF dated July 22, 2026 and linked directly from its homepage. The document explains the discovery date, system-security response, forensic finding, file-review and contact-verification dates, data classes, misuse assessment, HHS notification, and call center.
A Massachusetts consumer-notification file provides a separate official state record for the organization. Claim Depot connects the organization PDF and regulatory record and reports 107 people notified in Massachusetts and nine in Vermont. These are state subsets, not a national total. The sources align on the nature of the event, timeline, and core identity and health-information categories.
What Happened Around February 23, 2025?
After detecting suspicious network activity, Saint Pete MRI took steps to secure its internal systems and retained independent forensic experts to determine what happened and what data might have been affected. The specialists confirmed that the organization's electronic patient-care and medical-imaging systems were not accessed. They did, however, find that certain scanned data may have been acquired without authorization.
The public notice does not identify the initial access route, actor, malware, exact start and end times, ransom demand, or online publication of data. The finding that data “may have been acquired” warrants treating possible extraction seriously, but does not prove that every scanned document was copied or that every individual had the same fields present.
Why Did the Data Review Take So Long?
After the initial technical investigation, an independent team performed a comprehensive and time-intensive review to identify personal information within scanned files. That work concluded on April 7, 2026 that certain personal information may have been contained in the affected data. Saint Pete MRI then verified potentially affected individuals, gathered contact information, and assessed the information scope.
Identity and contact verification was completed July 15, 2026, about seventeen months after discovery. On July 22, the organization mailed letters by U.S. First-Class Mail to people whose addresses were available and posted a substitute notice for those it could not contact. LeakData presents these dates as stages of one review and notification process, not as separate attacks.
What Identity Information May Have Been Affected?
According to the official notice, names, Social security numbers, dates of birth, driver's-license numbers, or state-identification numbers may have been present. That combination creates long-term exposure to fraudulent credit, tax-identity misuse, government-document impersonation, and targeted social engineering. It should not be assumed that every individual had all fields affected.
Recipients should review credit reports for unfamiliar accounts or inquiries and consider free freezes or a fraud alert at all three major credit bureaus. When an SSN was involved, an IRS Identity Protection PIN can provide another safeguard. SSNs, identity images, passwords, and one-time codes should not be provided in unexpected messages claiming to come from Saint Pete MRI, an insurer, or a government agency.
How Were Medical and Health-Insurance Details Affected?
Scanned data could contain medical information and health-insurance information. Those categories can connect a person to an imaging center, sleep lab, or other care relationship and may support medical-identity fraud. The forensic finding that electronic patient-care and imaging systems were not accessed is important: the event should not be expanded to the complete contents of those systems.
The official PDF does not separately confirm diagnoses, treatment, images, test results, prescriptions, medical-record numbers, policy numbers, or member numbers. LeakData keeps the medical and insurance categories at the breadth disclosed. Individuals should review patient portals and explanation-of-benefits statements for unfamiliar services, imaging, providers, or contact changes and verify suspicious entries directly with the institutions.
How Many People Were Affected and How Did the Organization Respond?
The 107 Massachusetts residents and nine Vermont residents are notification subsets for those states. Because public sources do not provide a deduplicated nationwide total, LeakData does not add the figures, does not estimate a total, and keeps pwnCount and totalRecords at zero. Saint Pete MRI said it had no evidence at notification time of misuse or attempted misuse of the information.
The organization secured its systems, used independent teams for technical and document review, mailed notices, posted a substitute notice, and notified the HHS Office for Civil Rights. Its call center at 1-877-396-3217 is available weekdays from 9 a.m. to 9 p.m. ET. The time-bound “no evidence” assessment does not eliminate future risk. LeakData does not host incident files or patient records.