SimonMed Imaging, one of the largest outpatient medical imaging providers in the United States, experienced a significant data breach following a ransomware attack by the Medusa group. The incident resulted in unauthorized access to SimonMed’s systems between January 21 and February 5, 2025, as confirmed by both company statements and regulatory filings. The breach was initially discovered on January 27, 2025, after a vendor notified SimonMed of a security incident, prompting an immediate internal investigation. The attackers reportedly stole approximately 200 GB of data, impacting over 1.2 million individuals whose sensitive information was exposed. SimonMed Imaging provides a wide range of diagnostic services, including MRI, CT, X-ray, ultrasound, mammography, PET, nuclear medicine, bone density, and interventional radiology, and operates around 170 medical centers across 11 states. The compromised data includes names, addresses, birth dates, dates of service, and provider names, with the potential for even more sensitive medical information to have been accessed, given the nature of the business. In response to the breach, SimonMed took several remediation steps, such as resetting passwords, strengthening multi-factor authentication, implementing enhanced endpoint detection and response monitoring, removing direct vendor access, and restricting network traffic to trusted connections. The company also engaged data security and privacy professionals and notified law enforcement authorities. As of October 10, 2025, SimonMed stated there was no evidence that the stolen information had been misused for identity theft or fraud. The company emphasized that the investigation is ongoing to determine the full scope of the data affected. The breach highlights the persistent threat of ransomware attacks targeting healthcare organizations, which often store large volumes of sensitive patient data. SimonMed’s swift response included notifying affected individuals and regulatory bodies, as required by law. The Medusa ransomware group’s involvement underscores the increasing sophistication and impact of cybercriminal operations against critical healthcare infrastructure. The incident has raised concerns about third-party vendor security, as the initial alert came from an external partner experiencing its own security issues. SimonMed’s annual revenue exceeds $500 million, and the scale of this breach is among the largest in the healthcare sector for 2025. The company continues to monitor for any signs of misuse of the compromised data and is providing support to affected individuals. This event serves as a stark reminder of the importance of robust cybersecurity measures and incident response planning in the healthcare industry.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
In October 2025, SimonMed Imaging publicly disclosed that the January breach affected over 1.2 million individuals. Reports described the incident as impacting roughly 1.2 million patients and drew attention to the scale of the exposure.
SimonMed Imaging said a data breach occurred in January 2025, exposing patient information. Later reporting tied the incident to a breach claimed by the Medusa ransomware operation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.