Onsite Mammography Data Breach
Onsite Mammography Email Breach Affects 357K Patients
What happened in the Onsite Mammography data breach?
The Onsite Mammography data breach was reported on April 21, 2025 and affected 357,265 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Massachusetts. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Onsite Mammography Breach Details
Onsite Mammography Data Breach Report
Incident Overview
Onsite Mammography, a Massachusetts-based healthcare provider specializing in breast imaging services, experienced a significant data breach involving unauthorized access to patient email systems. The breach was formally reported to the Massachusetts Attorney General on April 21, 2025, affecting 357,265 individuals. This hacking incident represents one of the larger healthcare data breaches reported in Massachusetts in recent years, exposing sensitive patient health information through compromised email infrastructure. The breach occurred within email systems maintained by the organization, suggesting attackers gained unauthorized access to electronic communications containing protected health information (PHI).
Discovery and Response Timeline
Onsite Mammography discovered the unauthorized access to its email systems through security monitoring and investigation protocols. Upon discovery, the organization initiated a comprehensive investigation to determine the scope of the breach, identify affected individuals, and assess what specific patient information may have been accessed or exfiltrated by unauthorized actors. The organization notified affected patients in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach affecting unsecured PHI. A business associate was involved in this incident, indicating that third-party vendors or service providers with access to patient data may have been implicated in the breach or its investigation. The notification process began immediately upon confirmation of the breach scope.
Technical Details of the Breach
The breach was classified as a hacking/IT incident, which typically involves unauthorized access to computer systems or networks through exploitation of security vulnerabilities, credential compromise, or social engineering tactics. Email systems are particularly attractive targets for healthcare hackers because they often contain unstructured PHI, clinical notes, appointment information, and communications between patients and providers. The involvement of a business associate suggests the breach may have originated through a third-party vendor's compromised systems or inadequate security controls at a service provider level. Email breaches of this magnitude typically indicate either a sustained unauthorized access period, broad credential compromise affecting multiple user accounts, or exploitation of a critical vulnerability in email infrastructure. The fact that 357,265 individuals were affected suggests the breach may have involved access to email archives, distribution lists, or shared mailboxes containing historical patient communications.
Organizational Context
Onsite Mammography operates as a specialized healthcare provider focused on mammography and breast imaging services in Massachusetts. The organization likely operates multiple imaging centers or facilities across the state to serve its patient population. As a diagnostic imaging provider, Onsite Mammography maintains extensive patient records including appointment histories, imaging results, clinical assessments, and communications with referring physicians. The scale of the breach—affecting over 357,000 individuals—suggests the organization has been operating for a substantial period and serves a significant geographic area within Massachusetts. The involvement of a business associate indicates the organization utilizes third-party vendors for services such as email hosting, IT support, billing services, or other healthcare operations. This multi-vendor environment increases the complexity of breach response and investigation.
Patient Impact and Affected Information
The breach potentially exposed protected health information for 357,265 patients who had communicated with Onsite Mammography through email or whose information was stored in email systems. Patients affected by this breach likely include individuals who scheduled mammography appointments, received imaging results via email, or had clinical communications with the organization's healthcare providers. The specific types of PHI that may have been accessed include patient names, contact information (email addresses, phone numbers, mailing addresses), dates of birth, medical record numbers, insurance information, and potentially clinical notes or imaging results related to breast health. Some patients may have had Social Security numbers or financial information exposed if such data was included in email communications or attachments. The breach notification process required Onsite Mammography to provide affected individuals with details about the breach, types of information exposed, steps the organization is taking to prevent future incidents, and recommended actions patients should take to protect themselves.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, Onsite Mammography was required to notify all affected individuals of this breach of unsecured PHI. The organization must also notify prominent media outlets in Massachusetts and the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) due to the number of affected individuals exceeding 500. Email-based breaches represent a significant portion of healthcare data breaches, accounting for approximately 20-25% of reported incidents in recent years. The involvement of a business associate in this breach highlights the importance of Business Associate Agreements (BAAs) and vendor security management—critical components of HIPAA compliance. Healthcare organizations are required to ensure that business associates implement appropriate administrative, physical, and technical safeguards to protect PHI. Email breaches of this scale typically trigger regulatory investigations and may result in corrective action plans, security assessments, and potential civil penalties if HIPAA violations are substantiated. The Massachusetts Attorney General's office will likely review the organization's security practices and breach response procedures as part of state-level oversight.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Onsite Mammography Breach
Monitor credit reports and consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent unauthorized account creation
Review explanation of benefits (EOB) statements and insurance claims for any unauthorized medical services or fraudulent activity, and report discrepancies to your insurance provider immediately
Change passwords for any online healthcare portals, email accounts, and financial accounts, using strong, unique passwords that are not reused across multiple platforms
Be vigilant against phishing emails and suspicious communications claiming to be from Onsite Mammography or healthcare providers; verify any requests for information by calling the organization directly using a known phone number
Consider enrolling in identity theft protection or credit monitoring services, particularly if Social Security numbers were potentially exposed
Request a copy of your medical records from Onsite Mammography to verify accuracy and identify any unauthorized access or modifications
Report any suspicious activity, unauthorized charges, or identity theft attempts to the Federal Trade Commission (FTC) at IdentityTheft.gov and file a police report if necessary
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Massachusetts Breaches
Search all breaches reported in Massachusetts
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits