Lumexa Imaging Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do
Lumexa Imaging has disclosed a data breach affecting 3,632 individuals that occurred on March 31, 2026. The Washington Attorney General’s office posted the notice on June 12, 2026, and anyone who received services from Lumexa Imaging should review the full notice to determine whether their information was exposed and what protective steps are recommended.
In early 2026, thousands of people connected to Lumexa Imaging learned that personal and medical details tied to their care may have been exposed in a data breach. For anyone whose name, Social Security number, date of birth, insurance identifiers, or medical information sat in the company’s systems, the practical stakes are concrete: those records can be misused for identity theft, insurance fraud, or targeted scams long after the initial incident.
According to a filing reported to the Washington State Attorney General on June 12, 2026, Lumexa Imaging notified Washington residents of the breach. The notice states that the incident itself occurred on March 31, 2026, and that 3,632 people were affected. Public detail beyond that filing is limited; what is known comes from the organization’s disclosure to the regulator.
Breaking down the breach
Lumexa Imaging reported the matter in a data breach notice filed with the Washington Attorney General on June 12, 2026. That filing places the incident on March 31, 2026, and lists 3,632 people as affected. The notice identifies the categories of information exposed as name, Social Security number, full date of birth, health insurance policy or ID number, and medical information.
The disclosure does not describe how the incident unfolded, whether systems were accessed remotely, how long unauthorized access lasted, or whether data was copied, viewed, or otherwise removed. No threat actor is named in the available record. Timing between the March 31, 2026 incident date and the June 12, 2026 regulatory filing is stated in the notice; other operational details remain undisclosed in the public summary.
How a breach like this happens
Incidents that expose patient and insurance records often follow familiar patterns in healthcare and diagnostic imaging environments, though none of the following should be read as a confirmed description of this specific event. Attackers commonly gain an initial foothold through stolen or phished credentials, unpatched remote-access software, or compromised vendor accounts that connect to clinical or billing systems. Once inside, they may move laterally to file shares, electronic health record modules, or backup stores where demographic, insurance, and clinical data are concentrated.
In other cases, misconfigured cloud storage, exposed databases, or malware that harvests files from workstations can lead to similar outcomes without a dramatic “break-in.” Healthcare organizations routinely hold dense combinations of identity and clinical data because imaging, scheduling, and reimbursement workflows require them. When those repositories are reached, the result is often a bundle of identifiers that remain useful to criminals for years. Without an attributed method in the Lumexa Imaging notice, these remain general industry patterns, not findings about this breach.
Who is Lumexa Imaging?
Lumexa Imaging operates in the medical imaging and diagnostics sector—the part of healthcare that produces and manages studies such as X-rays, CT scans, MRIs, and related reports. Organizations of this type typically maintain scheduling systems, radiology information systems, picture archiving, referral and ordering data, and billing interfaces that connect to insurers and referring clinicians.
That work requires holding patient identifiers, dates of birth, insurance policy or member numbers, and clinical details tied to exams and findings. A breach at an imaging provider is consequential because the same files that support accurate diagnosis and payment also form a high-value package for identity misuse and medical fraud. Patients may have little day-to-day visibility into how many downstream systems store copies of their imaging-related records, which can widen the impact when one organization reports an incident.
What was likely exposed
The Washington Attorney General filing names specific categories. According to Lumexa Imaging’s notice, the information exposed included:
- Name
- Social Security number
- Full date of birth
- Health insurance policy or ID number
- Medical information
The filing does not publish sample records, full data dictionaries, or a breakdown of how many people had each field present. “Medical information” is listed without further public elaboration in the summary, so the precise clinical fields involved are not detailed beyond that label. What is confirmed is the set of types the organization reported as exposed for the 3,632 people reflected in the notice.
What's at stake
For affected individuals, the combination of full name, Social Security number, and date of birth is sufficient raw material for new-account fraud, tax-related identity theft, and attempts to open credit in someone else’s name. Adding health insurance policy or ID numbers and medical information raises the risk of insurance fraud—such as false claims submitted under a real member’s coverage—and of highly tailored phishing that references real exams or conditions to build trust.
Medical details can also support blackmail-style scams or embarrassment-driven social engineering, even when no clinical narrative is published in the breach notice. Once Social Security numbers and insurance identifiers circulate, monitoring often needs to continue for years rather than weeks. For Lumexa Imaging, the stakes include regulatory follow-up, notification and support costs, potential contractual issues with partners and payers, and erosion of patient trust—outcomes common after healthcare data incidents, without any finding here that the organization was negligent as a matter of established fact.
Washington residents were among those notified through the Attorney General filing process; whether residents of other states were affected in the same count is not broken out in the facts provided. People who only interacted briefly with an imaging center—single referrals, second opinions, or one-time scans—can still appear in the affected population if their demographics and insurance data were stored for billing or clinical continuity.
Were you affected?
If you received a notice from Lumexa Imaging, treat it as the primary source for your status and follow the instructions it contains for credit monitoring or other support, if offered. If you are unsure, contact the organization through official channels listed on a notice or its public site, and keep records of any reference numbers. Place a fraud alert or credit freeze with the major credit bureaus if your Social Security number may be involved, and review explanation-of-benefits statements from your insurer for unfamiliar claims. Be cautious of unsolicited calls or messages that cite the breach and press for passwords, payment, or remote access to your devices.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets elsewhere online. That check does not replace official notice from Lumexa Imaging, but it can help you see whether the same address appears in other documented incidents and prioritize tighter monitoring where needed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Hibbett Retail, Inc. Data Breach Notice (Washington Attorney General)LHC Group, Inc. Data Breach Notice (Washington Attorney General)RB American Group LLC Data Breach Notice (Washington Attorney General)Pan American Group LLC Data Breach Notice (Washington Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.