Northwest Radiologists, Inc./Mount Baker Imaging Data Breach
Northwest Radiologists Network Breach Affects 362,713 Patients
What happened in the Northwest Radiologists, Inc./Mount Baker Imaging data breach?
The Northwest Radiologists, Inc./Mount Baker Imaging data breach was reported on October 28, 2025 and affected 362,713 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Washington. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Northwest Radiologists, Inc./Mount Baker Imaging Breach Details
Healthcare Data Breach Report: Northwest Radiologists, Inc./Mount Baker Imaging
Incident Overview
Northwest Radiologists, Inc., operating as Mount Baker Imaging, experienced a significant data breach affecting 362,713 individuals in Washington State. The breach was discovered and reported on October 28, 2025, and involved unauthorized access to the organization's network server infrastructure. This incident represents one of the larger healthcare data breaches in Washington State in recent years, exposing protected health information (PHI) of a substantial patient population to potential misuse. The breach was classified as a hacking/IT incident, indicating that external threat actors gained unauthorized access to the organization's systems rather than through physical theft or internal negligence.
Discovery and Response Timeline
The specific discovery date and investigation timeline have not been publicly detailed in available breach notification records, though the submission to regulatory authorities occurred on October 28, 2025. Healthcare organizations are required under HIPAA Breach Notification Rule to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach. Mount Baker Imaging's notification process would have followed this regulatory framework, requiring direct notification to all 362,713 affected individuals through mail, email, or telephone, depending on available contact information. The organization likely engaged forensic investigators to determine the scope of the breach, identify the attack vector, and implement remediation measures to prevent future incidents. As a healthcare entity handling sensitive medical imaging data and associated patient records, the organization would have been required to notify the U.S. Department of Health and Human Services (HHS) Office for Civil Rights and potentially the Washington State Attorney General's office.
Technical Details of the Breach
The breach occurred at the network server level, which typically indicates that attackers gained access to centralized systems where patient data is stored and processed. Network server compromises in healthcare settings often result from vulnerabilities such as unpatched software, weak authentication credentials, phishing attacks targeting employee credentials, or exploitation of remote access points. Radiological imaging centers maintain extensive databases containing diagnostic images, radiology reports, patient demographics, insurance information, and medical histories. The network server location suggests that the breach may have provided attackers with broad access to multiple data categories across the organization's patient population. Depending on the sophistication of the attack and the organization's security architecture, attackers may have accessed data across multiple years of patient records. Network-level breaches are particularly concerning because they can affect large numbers of records simultaneously and may go undetected for extended periods before discovery through security monitoring, system anomalies, or external notification.
Organizational Context
Northwest Radiologists, Inc., operating under the Mount Baker Imaging brand, is a diagnostic imaging provider serving the Washington State region. The organization provides radiological services including X-ray, CT scans, MRI, ultrasound, and other diagnostic imaging procedures. With 362,713 affected individuals, the organization represents a substantial regional healthcare provider with significant patient volume and operational scope. Mount Baker Imaging likely operates multiple imaging centers across Washington State, serving both hospital-affiliated and independent patient populations. The organization's size and scope indicate a well-established medical practice with years of accumulated patient records in their information systems. Radiological practices maintain particularly sensitive data, as imaging records often contain detailed medical information about serious health conditions, and are frequently cross-referenced with other healthcare providers' records.
Patient Population Impact and Notification
The breach affected 362,713 individuals, representing a substantial portion of the organization's patient database. This figure suggests the breach may have encompassed multiple years of patient records, potentially dating back several years depending on the organization's data retention policies. Affected individuals likely include patients who underwent imaging procedures at Mount Baker Imaging facilities, as well as patients whose imaging was ordered by referring physicians and processed through the organization's systems. The notification process required Mount Baker Imaging to provide detailed breach notification letters to all affected individuals, explaining the nature of the breach, the types of information exposed, the steps the organization was taking to address the incident, and recommended protective measures. Patients would have been advised to monitor their credit reports, consider credit monitoring services, and remain vigilant for signs of identity theft or fraudulent medical billing. The large number of affected individuals suggests the organization likely offered complimentary credit monitoring or identity theft protection services as part of their breach response, a common practice in major healthcare breaches.
Data Types and Exposure Risk
As a radiological imaging provider, Mount Baker Imaging's systems likely contained multiple categories of protected health information. Exposed data may have included patient names, dates of birth, Social Security numbers, insurance information, medical record numbers, imaging reports, diagnostic findings, and clinical notes. Radiological reports often contain sensitive information about serious medical conditions including cancer diagnoses, cardiac abnormalities, neurological conditions, and other significant health issues. Insurance information and financial data may have also been compromised, creating risk for fraudulent billing and identity theft. The combination of medical information with personal identifiers and financial data creates substantial risk for affected individuals, as this information can be used for medical identity theft, insurance fraud, or sold on dark web marketplaces to other threat actors. The sensitivity of radiological findings—which often relate to serious or life-threatening conditions—adds an additional layer of concern regarding privacy violations and potential misuse of sensitive health information.
HIPAA Compliance and Industry Context
This breach represents a violation of HIPAA Security Rule requirements, which mandate that covered entities implement appropriate administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). Network server breaches affecting over 360,000 individuals indicate potential deficiencies in access controls, encryption, vulnerability management, or incident response capabilities. Healthcare data breaches involving hacking/IT incidents have increased significantly in recent years, with network vulnerabilities and ransomware attacks representing leading causes of large-scale healthcare breaches. The HHS Office for Civil Rights has emphasized that healthcare organizations must implement multi-factor authentication, maintain current security patches, conduct regular security assessments, and maintain thorough audit logs to detect unauthorized access. Breaches of this magnitude typically result in regulatory scrutiny and potential civil penalties under HIPAA, in addition to reputational damage and increased liability exposure. The incident underscores the ongoing challenge healthcare organizations face in protecting patient data against sophisticated cyber threats while maintaining operational efficiency.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Northwest Radiologists, Inc./Mount Baker Imaging Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review healthcare bills and insurance statements carefully for unauthorized services, claims, or charges; contact providers immediately if suspicious activity is identified
Monitor financial accounts and bank statements for unauthorized transactions; consider placing alerts with financial institutions and reviewing account access logs
Enroll in complimentary credit monitoring and identity theft protection services offered by Mount Baker Imaging; maintain documentation of the breach notification and keep contact information for the organization's breach response team
Change passwords for healthcare portals, insurance accounts, and financial accounts; use strong, unique passwords and enable multi-factor authentication where available
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies; verify contact information independently before providing additional personal information
Consider obtaining identity theft insurance or monitoring services beyond those offered by the organization for long-term protection
Report any suspected identity theft or fraudulent activity to the Federal Trade Commission (FTC) at IdentityTheft.gov and file a police report if necessary
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Washington Breaches
Search all breaches reported in Washington
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits