All Breaches
July 11, 2025 Verified Sensitive Record Healthcare

Triad Radiology Associates 2025 Data Breach

The Triad Radiology Associates 2025 data breach was linked to suspicious activity involving an employee email account. The organization said it discovered the event around July 30, 2025, secured the account, and began an investigation with outside specialists. The investigation found that a limited amount of information may have been accessed during the period from July 11 through September 8, 2025.

The U.S. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person.

How Was the Triad Radiology Incident Verified?

The primary source is the “Notification of Data Security Incident” dated February 8, 2026. It describes suspicious activity in an employee email account, the July 30 discovery, the possible July 11-September 8 access window, data categories, no known misuse, complimentary credit monitoring, and the 1-800-405-6108 assistance line.

The second source is the HHS/OCR federal row reported February 6, 2026 for 11,011 people. ClaimDepot's incident page connects the same official notice and HHS total, providing an independent check on the organization, timeline, and scope. No threat-actor name, malware, credential-compromise method, or data-sale claim is added because those details are not supported across the three sources.

How Should the Timeline Be Read?

The official notice gives a possible access period from July 11 through September 8, 2025 and says suspicious activity was discovered around July 30. The incident date is based on the earliest technical activity that can be verified from public sources. September 8 is the end of the access range identified by the investigation, not the notification date.

The organization says it immediately secured the account after discovery, while its investigation also states that information may have been accessed in a range ending September 8. LeakData preserves both official statements without claiming that access was continuous, that the account was compromised again, or that the containment failed. February 6 and 8, 2026 represent the regulator-reporting and public-notice stages, respectively.

What Information May Have Been Involved?

According to Triad's scope review, the combination varied by individual and may include a name together with one or more of the following: address, Social Security number, driver's license number, bank account information, date of birth, medical information, and health insurance information. The official text does not say that every category applied to every person.

It would be inaccurate to assign every data type to all 11,011 individuals. The organization says a limited amount of information may have been accessed and that it issued notices because it could not rule out that possibility. Each individual letter is the primary reference for determining which fields relate to a specific recipient; the general incident page alone cannot establish personal scope.

How Should the Affected-Person Count Be Interpreted?

11,011 is the official affected-person count in the HHS/OCR portal; it is not a number of emails, files, or data rows. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person. The fact that the incident involved one employee email account also does not mean only one person was affected, because an account can hold messages or documents concerning many individuals.

This field and the public affected-person total measure different things.

Identity, Financial, and Health Risks

Social security numbers, dates of birth, and driver's license information can increase the risk of identity theft and fraudulent account opening. People whose bank account details may be involved should monitor unfamiliar transactions, recipients, or automatic-payment changes. Unexpected messages claiming to be from Triad, a bank, or a credit provider should be verified through a known official number, and users should not disclose a one-time code, password, or full identifier.

Medical and health insurance information can be used for targeted healthcare scams, fraudulent bills, or medical identity theft. Recipients should review explanations of benefits, health claims, and unfamiliar services. If care they did not receive appears, they should contact the provider and insurer directly rather than relying on a link in the email.

What Did the Organization Do and What Can Users Do?

Triad said it secured the account, conducted an investigation with outside specialists, and reviewed its data-security policies and procedures. Potentially affected individuals were offered complimentary credit monitoring and identity-protection services. The organization stated that it was not aware of evidence of fraudulent misuse but notified people out of caution because it could not rule out possible access.

The assistance and enrollment line at 1-800-405-6108 is available weekdays from 8:00 a.m. to 8:00 p.m. Users can review credit reports and account statements, consider a fraud alert or credit freeze, and monitor health insurance statements. Unverified person counts, data fields, and threat-actor claims are not treated as part of the public incident scope.

11 Thousand
Affected Accounts
8
Data Types
Medium
Severity
Yes
Verification

Exposed Data Types

8
Names
Physical addresses
Social security numbers
Driver's license numbers
Bank account information
Dates of birth
Medical information
Health insurance information

Additional Information

Added DateJuly 27, 2026
Breach DateJuly 11, 2025
Domaintriadradiology.com
SourceOfficial Triad notice, HHS/OCR breach report, and independent incident reporting
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information