SimonMed Imaging and Doctors Imaging Group, two major radiology practices in the United States, have reported significant data breaches impacting nearly 1.5 million individuals. The cybercrime group known as Medusa has claimed responsibility for the attack on SimonMed Imaging, which occurred in January. Initially, SimonMed reported the breach to federal authorities with a placeholder estimate of 500 affected individuals, but later filings with the Maine attorney general revealed the true scope, with nearly 1.28 million patients impacted. The compromised data reportedly includes highly sensitive health information, such as a spreadsheet containing records of over 1 million mammograms performed by SimonMed. Medusa threatened to leak the stolen data on the dark web, escalating concerns about patient privacy and potential misuse of the information. The breach has already led to at least four proposed federal class action lawsuits against SimonMed, with plaintiffs alleging inadequate protection of patient data and highlighting the cybercriminal gang's public claims of exfiltrating 212 gigabytes of data. Doctors Imaging Group was also affected by a separate hacking incident, contributing to the total number of nearly 1.5 million individuals notified. Both organizations have begun notifying affected patients, as required by law, and are working with authorities to investigate the incidents. The attacks underscore the ongoing threat posed by ransomware and data extortion groups targeting healthcare providers, who often hold large volumes of sensitive personal and medical information. The Medusa group’s tactics include not only stealing data but also threatening public exposure to pressure victims into paying ransoms. The breach at SimonMed has drawn attention from regulators and the legal community, with scrutiny over the timeliness and accuracy of breach notifications. The incident highlights the importance of robust cybersecurity measures and incident response planning in the healthcare sector. Both radiology practices are likely to face increased regulatory oversight and potential financial penalties as investigations continue. The exposure of mammogram records and other health data raises significant concerns about patient safety, identity theft, and fraud. Healthcare organizations are being urged to review their security postures and ensure compliance with data protection regulations in light of these breaches. The Medusa group’s involvement in these attacks is part of a broader trend of cybercriminals targeting critical infrastructure and healthcare entities for financial gain.

See attribution, scope, and your downstream exposure.
1 event from the most recent confirmed update back to the earliest known activity.
Two radiology practices reported separate hacking incidents that together affected nearly 1.5 million patients or individuals, according to the referenced coverage. The available references indicate public notification and disclosure of the breaches but provide no additional dated milestones.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.