US Radiology Specialists, Inc. Data Breach
US Radiology Specialists Network Server Breach Affects 87,552
What happened in the US Radiology Specialists, Inc. data breach?
The US Radiology Specialists, Inc. data breach was reported on February 18, 2022 and affected 87,552 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in North Carolina. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
US Radiology Specialists, Inc. Breach Details
US Radiology Specialists Network Server Breach Report
Opening Summary
US Radiology Specialists, Inc., a North Carolina-based radiology services provider, experienced a significant data breach involving unauthorized access to its network server infrastructure. The breach was discovered and reported to the U.S. Department of Health and Human Services on February 18, 2022, affecting 87,552 individuals. The incident involved a hacking or IT-related attack that compromised protected health information (PHI) stored on the organization's network servers. This breach represents a substantial security incident affecting a large patient population across the radiology services sector.
Discovery and Response Timeline
US Radiology Specialists identified the unauthorized access to its network server through security monitoring systems and incident detection protocols. Upon discovery, the organization initiated a comprehensive investigation to determine the scope of the breach, identify affected individuals, and assess what types of patient information may have been accessed. The entity worked to contain the breach, secure its systems, and prepare notifications for affected patients as required under the Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule. The submission date of February 18, 2022, indicates the organization met its obligation to report the breach to HHS within 60 days of discovery, as mandated by federal regulations.
Technical Details of the Breach
The breach occurred through unauthorized access to the organization's network server infrastructure, which typically serves as a centralized repository for patient records, imaging data, appointment information, and associated clinical documentation. Network server breaches of this nature commonly result from vulnerabilities such as unpatched software, weak authentication credentials, phishing attacks targeting employee credentials, or exploitation of misconfigured network access controls. The fact that a business associate was involved in this incident suggests that the compromised network may have included systems shared with or accessed by third-party vendors, contractors, or service providers who handle radiology data on behalf of the primary organization. This multi-party access environment increases the complexity of breach investigation and remediation efforts.
Organizational Context
US Radiology Specialists, Inc. operates as a radiology services provider in North Carolina, offering diagnostic imaging and related clinical services to patients throughout the state. Radiology practices typically maintain extensive digital records including medical images (X-rays, CT scans, MRI images), radiologist reports, patient demographics, insurance information, and clinical histories. The organization's size—affecting nearly 88,000 individuals—indicates it likely operates multiple facilities or serves a substantial regional patient population. As a healthcare entity handling sensitive diagnostic information, US Radiology Specialists is subject to HIPAA regulations and must maintain appropriate safeguards to protect patient privacy and data security.
Patient Impact and Affected Population
The breach affected 87,552 individuals whose information was stored on the compromised network server. These patients likely include individuals who underwent radiology services at US Radiology Specialists facilities or affiliated healthcare providers over an extended period. The compromised data may have included names, dates of birth, medical record numbers, insurance information, Social Security numbers, and detailed clinical information related to radiology procedures and diagnoses. Patients were notified of the breach through written notification letters as required by HIPAA regulations, which mandate that covered entities inform affected individuals of breaches without unreasonable delay and no later than 60 days after discovery. The notification process for nearly 88,000 individuals represents a significant administrative undertaking requiring coordination of mailing lists, letter preparation, and call center resources to handle patient inquiries.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule, covered entities and business associates must notify affected individuals, the media (for breaches affecting more than 500 residents of a state or jurisdiction), and the Secretary of HHS when unsecured PHI is accessed, acquired, used, or disclosed in a manner not permitted by the Privacy Rule. Network server breaches represent a significant category of healthcare data incidents, accounting for a substantial portion of reported breaches in the healthcare sector. According to HHS breach notification data, hacking and IT incidents have consistently ranked among the top causes of healthcare data breaches, often resulting in large-scale exposures due to the centralized nature of network infrastructure. The involvement of a business associate in this incident underscores the importance of vendor management and third-party risk assessment in healthcare organizations. Covered entities remain liable for breaches involving business associates' systems, making it essential to establish strong contractual safeguards, security requirements, and incident response protocols with all vendors handling PHI.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the US Radiology Specialists, Inc. Breach
Obtain free credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) at annualcreditreport.com and review them carefully for unauthorized accounts or inquiries. Consider placing a fraud alert or credit freeze with each bureau to prevent unauthorized credit applications.
Monitor financial accounts, credit card statements, and bank accounts regularly for unauthorized transactions. Set up account alerts with your financial institutions to receive notifications of unusual activity. Consider enrolling in credit monitoring services if offered by US Radiology Specialists as part of their breach response.
Review your medical records and explanation of benefits (EOB) statements from your health insurance provider to verify that only authorized services appear. Contact your healthcare providers if you notice unfamiliar charges or medical services you did not receive.
Change passwords for any online healthcare portals, patient account systems, or related accounts, using strong, unique passwords. Enable multi-factor authentication where available to add an additional layer of security to your accounts.
Consider placing a security freeze on your credit file with all three credit bureaus to prevent unauthorized access to your credit information. While this may inconvenience legitimate credit applications, it provides strong protection against identity theft.
File a report with the Federal Trade Commission (FTC) at IdentityTheft.gov if you suspect any fraudulent activity related to this breach. Keep documentation of all breach-related communications and any suspicious activity.
Remain vigilant for phishing emails, suspicious phone calls, or mail claiming to be from healthcare providers or financial institutions. Do not click links or provide information in response to unsolicited communications.
Contact US Radiology Specialists directly using contact information from official sources (not from breach notification letters) to inquire about additional protective measures, credit monitoring services, or identity theft protection resources they may be offering.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More North Carolina Breaches
Search all breaches reported in North Carolina
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits