Doctors Imaging Group, a Florida-based provider of medical scanning services such as MRI and X-ray imaging, experienced a significant data breach in November 2024 that resulted in the theft of sensitive information belonging to 171,862 patients. The breach was not publicly disclosed until nearly a year later, after the company completed its internal investigation on August 29, 2025, and subsequently notified the Department of Health and Human Services. The compromised data included a wide range of personally identifiable information (PII), such as names, addresses, dates of birth, and Social Security numbers. In addition to PII, the attackers accessed financial account numbers and types, patient account numbers, medical record numbers, health insurance details, and information related to medical treatments and insurance claims. The nature of the attack has not been specified by Doctors Imaging Group, and no known ransomware group or cybercrime operation has claimed responsibility for the incident. The breach was discovered after suspicious activity was detected on the network, prompting a swift response from the organization to investigate and secure their systems. Federal law enforcement and relevant regulatory authorities were notified as part of the incident response process. Affected individuals were informed via mailed letters, provided their address information was available, and the company has committed to reviewing and enhancing its cybersecurity policies and tools to prevent future incidents. The breach is notable for the breadth and sensitivity of the data exposed, which could be exploited for identity theft, financial fraud, or insurance fraud. The incident occurred during a period when several other healthcare organizations in the region, including Medical Associates of Brevard and Wayne Memorial Hospital, also reported significant data breaches, highlighting a broader trend of cyberattacks targeting the healthcare sector. Despite the scale of the breach, there is no public evidence that the stolen data has been misused or leaked by the attackers as of the time of disclosure. The delay in notification has raised concerns about the timeliness of breach disclosures in the healthcare industry, especially given the potential risks to affected patients. Doctors Imaging Group has reiterated its commitment to information security and is taking steps to strengthen its defenses in response to the incident. The breach underscores the ongoing vulnerability of healthcare providers to cyberattacks and the critical importance of robust data protection measures. Patients affected by the breach are advised to monitor their financial and medical accounts for signs of misuse. The incident serves as a reminder of the high value of medical and financial data on the black market and the persistent threat posed by cybercriminals to the healthcare sector.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
After investigating the breach, Doctors Imaging Group concluded that patient information had been compromised. Reporting in October 2025 said more than 171,000 people were affected.
Doctors Imaging Group was attacked in late 2024, beginning an incident that disrupted the medical imaging business and led to a later investigation into possible data theft. The attack occurred roughly 10 months before the October 2025 reporting.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.