Northwest Radiologists and Mt. Baker Imaging Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
On October 29, 2025, the Oregon Attorney General posted a breach notice for Northwest Radiologists and Mt. Baker Imaging stating that personal information of 362,713 individuals had been exposed following an incident that occurred on January 20, 2025. Individuals should review the notice to determine whether their data was affected and follow the steps provided to protect themselves.
Northwest Radiologists and Mt. Baker Imaging notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 29, 2025. The filing places the incident itself on January 20, 2025, and states that 362,713 people were affected. Public detail beyond that notice remains limited.
The organization described the exposed material as personal information. For patients and others connected to a radiology and imaging practice, even a high-level confirmation of that kind of exposure raises practical questions about monitoring accounts, watching for misuse of identity details, and understanding what is and is not yet known.
What happened
According to the breach notice filed with the Oregon Attorney General’s office and reported on October 29, 2025, Northwest Radiologists and Mt. Baker Imaging experienced a data incident dated January 20, 2025. The filing indicates that 362,713 individuals were affected. The notice characterizes the exposed data as personal information.
The public record available from that filing does not describe the technical method of intrusion, the systems involved, how long unauthorized access lasted, or whether data was exfiltrated, encrypted, or merely accessed. No threat actor is named in the disclosed materials. Timing between the January incident date and the late-October reporting date is stated in the filing; further operational detail is undisclosed.
How a breach like this happens
Incidents affecting healthcare and diagnostic imaging providers commonly begin with commonplace entry points rather than exotic techniques. Attackers may obtain valid credentials through phishing, reuse of passwords from earlier breaches, or malware on a workstation. Once inside a network, they often move laterally to file shares, imaging archives, billing systems, or backup repositories that hold patient and administrative records.
In other cases, a vulnerable remote-access service, an unpatched application, or a misconfigured cloud storage location provides the initial foothold. Ransomware groups and data thieves alike have targeted medical practices because the combination of identity data and clinical context can be valuable for fraud and because operational disruption creates pressure to respond quickly. None of these patterns is attributed to the Northwest Radiologists and Mt. Baker Imaging event; they are the general pathways seen across the sector when similar notices appear.
Detection sometimes occurs only after unusual outbound traffic, ransom notes, or alerts from a security tool. Notification to regulators and affected people then follows internal investigation and legal review, which can span weeks or months depending on the scope of forensic work.
Northwest Radiologists and Mt. Baker Imaging and its sector
Northwest Radiologists and Mt. Baker Imaging operate in diagnostic radiology and medical imaging—services that produce and store studies such as X-rays, CT scans, MRIs, and related reports, and that handle scheduling, referrals, and billing. Organizations of this type routinely maintain demographic details, insurance information, and clinical records tied to individual patients, referring physicians, and staff.
Healthcare and imaging providers are frequent targets because they hold concentrated stores of personal and health-related data and because continuity of care depends on available systems. A breach in this setting is consequential not only for the volume of records that may be involved but also because the data can support medical identity fraud, insurance abuse, or further social-engineering attempts against patients. The Oregon filing establishes that this organization reported an incident affecting a large number of people; it does not itself establish negligence or specific security failures.
What data was at risk
The breach notification names the exposed material as personal information. It does not publish a fuller inventory of data elements in the summary available from the Oregon filing.
Organizations in radiology and imaging typically hold items such as names, addresses, dates of birth, contact details, insurance identifiers, medical record numbers, and clinical reports or images. Whether any or all of those categories were involved in this incident is unconfirmed beyond the notice’s reference to personal information. Exact contents therefore remain limited in the public disclosure.
What's at stake
For affected individuals, the primary risks are misuse of personal details for identity theft, fraudulent account openings, or targeted phishing that references a real medical relationship. Even when clinical images themselves are not confirmed as exposed, demographic and insurance data can be enough to support secondary fraud. People may face time spent monitoring credit, placing fraud alerts, and verifying that no unauthorized medical claims have been filed in their name.
For the organization, stakes include regulatory follow-up, the cost of investigation and notification, potential civil claims, and reputational harm among patients and referring providers. Large affected counts increase the scale of those obligations. Public detail does not quantify financial impact or list specific regulatory actions beyond the Oregon notice itself.
What to do if you're exposed
If you believe you may be among those notified, practical first steps include reading any letter or email from the organization carefully, documenting the date you received it, and following the specific instructions it provides for credit monitoring or call centers if those are offered. Consider placing a free fraud alert or credit freeze with the major credit bureaus, reviewing bank and insurance statements for unfamiliar activity, and being cautious of unsolicited calls or messages that claim to relate to the breach.
- Keep the official notice and any reference numbers; do not rely solely on third-party summaries.
- Monitor credit reports and explanation-of-benefits statements for unexpected entries.
- Use unique passwords and multi-factor authentication on email and patient-portal accounts where available.
- Treat unexpected requests for Social Security numbers, payment, or remote access as suspicious even if they mention the incident.
- You can run a free exposure scan of your email to check whether your information has surfaced in known breach data.
Public information on this incident is drawn from the Oregon Attorney General filing reported October 29, 2025. Further detail may appear in later updates from the organization or regulators; until then, treat unconfirmed claims about methods, additional data types, or responsible parties as unverified.
AICompiled with AI assistance from public sources and published under our editorial standards.
More recent breaches
Apro, LLC d/ Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)700Credit, LLC Data Breach Notice (Oregon Attorney General)American Association of Critical-Care Nurses Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.