Radius Global Solutions Data Breach
Radius Global Solutions Network Server Breach Affects 600K+
What happened in the Radius Global Solutions data breach?
The Radius Global Solutions data breach was reported on August 4, 2023 and affected 600,794 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Minnesota. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Radius Global Solutions Breach Details
Radius Global Solutions Data Breach Report
Breach Overview
Radius Global Solutions, a Minnesota-based healthcare organization, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to the U.S. Department of Health and Human Services on August 4, 2023, affecting approximately 600,794 individuals. This incident represents a substantial compromise of protected health information (PHI) stored on the organization's networked systems, likely resulting from exploitation of network vulnerabilities or inadequate access controls.
Discovery and Response Timeline
The specific date of breach discovery was not disclosed in the initial notification, though the submission to HHS occurred on August 4, 2023, which typically indicates discovery within 30-60 days prior to notification in accordance with HIPAA Breach Notification Rule requirements. Upon discovery, Radius Global Solutions initiated a forensic investigation to determine the scope of unauthorized access, identify affected individuals, and assess what categories of protected health information may have been compromised. The organization notified affected individuals through written correspondence and established a dedicated breach response program, including credit monitoring services where applicable. The involvement of a business associate in this breach suggests that Radius Global Solutions may have been processing or storing data on behalf of covered entities, making the breach notification requirements particularly stringent under HIPAA regulations.
Technical Breach Details
The breach occurred on a network server, which typically indicates that attackers gained unauthorized access to centralized data storage systems rather than individual workstations or portable devices. Network server breaches of this magnitude usually result from one or more of the following vectors: exploitation of unpatched software vulnerabilities, weak or compromised credentials, inadequate network segmentation, insufficient firewall rules, or social engineering attacks targeting administrative personnel. The fact that over 600,000 individuals were affected suggests either a prolonged period of unauthorized access before detection or a broad compromise affecting multiple data repositories on the network infrastructure. Network-based breaches often allow attackers extended dwell time—the period between initial compromise and detection—which can range from weeks to months, significantly increasing the volume of data potentially exfiltrated.
Organizational Context and Operations
Radius Global Solutions operates as a healthcare service provider in Minnesota, likely providing business services, data management, billing, or administrative support to healthcare entities across multiple states. The organization's classification as involving a business associate indicates it processes sensitive health information on behalf of covered entities such as hospitals, physician practices, or health plans. The scale of the breach—affecting over 600,000 individuals—suggests Radius Global Solutions maintains substantial databases of patient information, potentially including records from multiple healthcare organizations. This business model creates heightened responsibility under HIPAA, as business associates must maintain equivalent security standards to covered entities and are subject to direct enforcement by HHS Office for Civil Rights.
Impact on Affected Individuals
Approximately 600,794 individuals had their protected health information potentially accessed during this breach. While the specific data elements compromised were not detailed in the breach notification summary, network server breaches of this scope typically involve access to multiple categories of PHI, which may include names, dates of birth, Social Security numbers, medical record numbers, insurance information, clinical diagnoses, treatment histories, and financial account details. The notification process required Radius Global Solutions to contact all affected individuals, provide details about the breach, explain the types of information compromised, and offer complimentary credit monitoring and identity theft protection services for a specified period (typically 12-24 months). Individuals were advised to monitor their credit reports, review explanation of benefits statements, and remain vigilant for signs of identity theft or fraudulent medical billing.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, covered entities and business associates must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of a breach of unsecured PHI. Additionally, notification must be provided to the media if the breach affects more than 500 residents of a state or jurisdiction, and to HHS. Network server breaches represent a significant category of healthcare data breaches, accounting for a substantial percentage of incidents affecting large numbers of individuals. According to HHS breach statistics, hacking and IT incidents have consistently ranked among the top breach types by volume of affected individuals, often surpassing theft and loss incidents. The involvement of a business associate in this breach underscores the importance of vendor risk management and the extension of HIPAA security requirements throughout the healthcare ecosystem. Organizations that fail to implement adequate network security controls, including regular vulnerability assessments, patch management, intrusion detection systems, and access controls, face significant regulatory penalties and reputational damage.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Radius Global Solutions Breach
Enroll in the complimentary credit monitoring and identity theft protection services offered by Radius Global Solutions for the full duration provided (typically 12-24 months), and actively monitor credit reports from all three bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries
Place a fraud alert with the three major credit bureaus and consider implementing a credit freeze to prevent unauthorized credit applications; document all fraud alert and freeze requests with confirmation numbers and dates
Review all healthcare bills, explanation of benefits statements, and medical records for unauthorized services, claims, or entries; contact healthcare providers immediately if fraudulent medical services are identified and request correction of medical records
Monitor financial accounts, credit card statements, and banking records for unauthorized transactions; set up account alerts with financial institutions and consider changing passwords for sensitive accounts using unique, complex passwords
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if identity theft is suspected, and consider filing a police report to establish an official record; maintain documentation of all fraud incidents, communications, and remediation efforts
Contact Radius Global Solutions' breach notification hotline or website for specific information about which data elements were compromised and obtain copies of any breach notification letters for personal records
Request copies of medical records from all healthcare providers to verify accuracy and identify any fraudulent entries; work with providers to correct any inaccuracies or unauthorized information
Consider placing a security freeze on credit reports with the Social Security Administration's fraud hotline (1-800-269-0271) if Social Security number compromise is confirmed, and monitor Social Security earnings records at ssa.gov
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Minnesota Breaches
Search all breaches reported in Minnesota
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuitsTechnical Notes
Radius Global Solutions Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for Radius Global Solutions