PET Imaging of Tulsa Data Breach
PET Imaging of Tulsa Email Breach Affects 3,159 Patients
What happened in the PET Imaging of Tulsa data breach?
The PET Imaging of Tulsa data breach was reported on June 27, 2025 and affected 3,159 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Oklahoma. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
PET Imaging of Tulsa Breach Details
PET Imaging of Tulsa Email Security Breach
Opening Summary
PET Imaging of Tulsa, a diagnostic imaging facility located in Oklahoma, experienced a significant data breach involving unauthorized access to its email systems. The breach was reported to the U.S. Department of Health and Human Services on June 27, 2025, affecting 3,159 individuals. The unauthorized access to email systems represents a common but serious vulnerability in healthcare IT infrastructure, as email accounts frequently contain sensitive patient health information, appointment details, and administrative communications that may include protected health information (PHI).
Discovery and Response Timeline
While specific discovery dates are not provided in the breach submission, PET Imaging of Tulsa initiated an investigation upon detecting the unauthorized access to its email infrastructure. The organization's response included a comprehensive review of affected email accounts to determine the scope of compromised data and the individuals impacted. The breach was formally reported to HHS within the required 60-day notification window, indicating the organization followed HIPAA Breach Notification Rule requirements. The involvement of a business associate in this breach suggests that either the email system was managed by a third-party vendor, or that patient data may have been shared with affiliated entities whose systems were compromised.
Technical Details of the Breach
The breach occurred through a hacking or IT incident targeting the organization's email systems. Email-based breaches typically result from one or more of the following vectors: compromised user credentials (through phishing, credential stuffing, or weak password practices), unpatched email server vulnerabilities, inadequate multi-factor authentication implementation, or exploitation of email forwarding rules and delegation features. Email systems are particularly attractive targets for threat actors because they serve as central repositories for sensitive communications and often contain patient identifiers, clinical notes, appointment information, and other PHI. The fact that a business associate was involved suggests the breach may have originated from or propagated through a third-party email service provider or managed IT services vendor. Healthcare organizations increasingly rely on cloud-based email solutions and managed services, which can introduce additional security considerations if not properly configured and monitored.
Organizational Context
PET Imaging of Tulsa is a diagnostic imaging center specializing in Positron Emission Tomography (PET) scanning services. PET imaging is an advanced diagnostic tool used to detect cancer, cardiac disease, neurological conditions, and other serious health conditions. As a specialized imaging facility, PET Imaging of Tulsa likely serves patients across the Tulsa metropolitan area and potentially the broader Oklahoma region, accepting referrals from primary care physicians, oncologists, cardiologists, and other specialists. The organization maintains patient records, scheduling systems, billing information, and clinical communications—all of which may have been accessible through compromised email accounts. The involvement of a business associate indicates the organization's IT infrastructure includes third-party vendors, which is standard practice in modern healthcare but requires thorough vendor management and security agreements.
Patient Impact and Affected Individuals
The breach affected 3,159 individuals, representing a substantial portion of the facility's patient population. These patients likely include individuals who have undergone PET imaging procedures, those with scheduled appointments, and potentially individuals who were referred for imaging but had not yet completed their scans. The compromised email systems may have contained various categories of protected health information, including patient names, dates of birth, medical record numbers, insurance information, clinical diagnoses, imaging results, appointment details, and potentially Social Security numbers or financial account information used for billing purposes. Notification of affected individuals was required under HIPAA's Breach Notification Rule, which mandates that covered entities notify patients without unreasonable delay and no later than 60 calendar days after discovery of a breach. The organization was also required to notify prominent media outlets and the HHS Secretary given the number of affected individuals.
HIPAA Compliance and Industry Context
This breach highlights ongoing challenges in healthcare cybersecurity, particularly regarding email security. According to industry reports, email remains one of the most common vectors for healthcare data breaches, accounting for a significant percentage of reported incidents. The HIPAA Security Rule requires covered entities to implement administrative, physical, and technical safeguards to protect electronic PHI, including access controls, encryption, audit controls, and integrity controls. Email systems should be protected through measures such as multi-factor authentication, encryption of data in transit and at rest, regular security awareness training to prevent phishing attacks, and monitoring for suspicious access patterns. The involvement of a business associate in this breach underscores the importance of Business Associate Agreements (BAAs) and vendor security assessments. Healthcare organizations are responsible for ensuring that their business associates maintain appropriate security measures, and breaches involving business associates trigger the same notification requirements as breaches of the covered entity's own systems. Similar email-based breaches have affected numerous healthcare organizations, ranging from small clinics to large hospital systems, demonstrating that this vulnerability affects organizations of all sizes.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the PET Imaging of Tulsa Breach
Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) at annualcreditreport.com and review them carefully for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with each bureau to prevent unauthorized credit applications.
Monitor financial accounts, credit card statements, and insurance explanations of benefits (EOBs) regularly for unauthorized charges or claims. Set up account alerts with your financial institutions to notify you of suspicious activity, and consider enrolling in free credit monitoring services if offered by PET Imaging of Tulsa.
Contact your health insurance provider to report the breach and request monitoring of your account for fraudulent claims. Ask about any suspicious claims or coverage inquiries made in your name, and request a new insurance card if necessary.
Place a fraud alert with the Federal Trade Commission (FTC) at identitytheft.gov and consider filing a police report if you discover evidence of identity theft or fraud. Keep detailed records of all communications and documentation related to any fraudulent activity.
Review your medical records with PET Imaging of Tulsa and your other healthcare providers to ensure no unauthorized services were billed to your account or false information was added to your medical history. Request corrections to any inaccurate information.
Be cautious of unsolicited communications claiming to be from PET Imaging of Tulsa, your insurance company, or financial institutions. Verify the legitimacy of any communications by contacting the organization directly using phone numbers or websites you know to be legitimate, rather than using contact information provided in suspicious messages.
Consider enrolling in identity theft protection services if available through your employer or insurance plan. These services can provide additional monitoring and assistance in case of identity theft.
Document all expenses and time spent addressing the breach, as you may be entitled to reimbursement or compensation through a settlement or legal action if one is pursued on behalf of affected patients.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Oklahoma Breaches
Search all breaches reported in Oklahoma