LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Northwest Radiologists and Mt. Baker Imaging Data Breach Notice (Oregon Attorney General)

MEDIUM severityConfirmedHow we verify

Northwest Radiologists and Mt. Baker Imaging Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·October 29, 2025
Northwest Radiologists and Mt. Baker Imaging Data Breach Notice (Oregon Attorney General)

Occurred January 20, 2025 · publicly disclosed October 29, 2025. Approximately 362713 people affected.

MEDIUM
Severity
362713
People affected
1
Data types exposed
October 29, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

On October 29, 2025, the Oregon Attorney General posted a breach notice for Northwest Radiologists and Mt. Baker Imaging stating that personal information of 362,713 individuals had been exposed following an incident that occurred on January 20, 2025. Individuals should review the notice to determine whether their data was affected and follow the steps provided to protect themselves.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
362713 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Northwest Radiologists and Mt. Baker Imaging notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 29, 2025. The filing places the incident itself on January 20, 2025, and states that 362,713 people were affected. Public detail beyond that notice remains limited.

The organization described the exposed material as personal information. For patients and others connected to a radiology and imaging practice, even a high-level confirmation of that kind of exposure raises practical questions about monitoring accounts, watching for misuse of identity details, and understanding what is and is not yet known.

What happened

According to the breach notice filed with the Oregon Attorney General’s office and reported on October 29, 2025, Northwest Radiologists and Mt. Baker Imaging experienced a data incident dated January 20, 2025. The filing indicates that 362,713 individuals were affected. The notice characterizes the exposed data as personal information.

The public record available from that filing does not describe the technical method of intrusion, the systems involved, how long unauthorized access lasted, or whether data was exfiltrated, encrypted, or merely accessed. No threat actor is named in the disclosed materials. Timing between the January incident date and the late-October reporting date is stated in the filing; further operational detail is undisclosed.

How a breach like this happens

Incidents affecting healthcare and diagnostic imaging providers commonly begin with commonplace entry points rather than exotic techniques. Attackers may obtain valid credentials through phishing, reuse of passwords from earlier breaches, or malware on a workstation. Once inside a network, they often move laterally to file shares, imaging archives, billing systems, or backup repositories that hold patient and administrative records.

In other cases, a vulnerable remote-access service, an unpatched application, or a misconfigured cloud storage location provides the initial foothold. Ransomware groups and data thieves alike have targeted medical practices because the combination of identity data and clinical context can be valuable for fraud and because operational disruption creates pressure to respond quickly. None of these patterns is attributed to the Northwest Radiologists and Mt. Baker Imaging event; they are the general pathways seen across the sector when similar notices appear.

Detection sometimes occurs only after unusual outbound traffic, ransom notes, or alerts from a security tool. Notification to regulators and affected people then follows internal investigation and legal review, which can span weeks or months depending on the scope of forensic work.

Northwest Radiologists and Mt. Baker Imaging and its sector

Northwest Radiologists and Mt. Baker Imaging operate in diagnostic radiology and medical imaging—services that produce and store studies such as X-rays, CT scans, MRIs, and related reports, and that handle scheduling, referrals, and billing. Organizations of this type routinely maintain demographic details, insurance information, and clinical records tied to individual patients, referring physicians, and staff.

Healthcare and imaging providers are frequent targets because they hold concentrated stores of personal and health-related data and because continuity of care depends on available systems. A breach in this setting is consequential not only for the volume of records that may be involved but also because the data can support medical identity fraud, insurance abuse, or further social-engineering attempts against patients. The Oregon filing establishes that this organization reported an incident affecting a large number of people; it does not itself establish negligence or specific security failures.

What data was at risk

The breach notification names the exposed material as personal information. It does not publish a fuller inventory of data elements in the summary available from the Oregon filing.

Organizations in radiology and imaging typically hold items such as names, addresses, dates of birth, contact details, insurance identifiers, medical record numbers, and clinical reports or images. Whether any or all of those categories were involved in this incident is unconfirmed beyond the notice’s reference to personal information. Exact contents therefore remain limited in the public disclosure.

What's at stake

For affected individuals, the primary risks are misuse of personal details for identity theft, fraudulent account openings, or targeted phishing that references a real medical relationship. Even when clinical images themselves are not confirmed as exposed, demographic and insurance data can be enough to support secondary fraud. People may face time spent monitoring credit, placing fraud alerts, and verifying that no unauthorized medical claims have been filed in their name.

For the organization, stakes include regulatory follow-up, the cost of investigation and notification, potential civil claims, and reputational harm among patients and referring providers. Large affected counts increase the scale of those obligations. Public detail does not quantify financial impact or list specific regulatory actions beyond the Oregon notice itself.

What to do if you're exposed

If you believe you may be among those notified, practical first steps include reading any letter or email from the organization carefully, documenting the date you received it, and following the specific instructions it provides for credit monitoring or call centers if those are offered. Consider placing a free fraud alert or credit freeze with the major credit bureaus, reviewing bank and insurance statements for unfamiliar activity, and being cautious of unsolicited calls or messages that claim to relate to the breach.

Public information on this incident is drawn from the Oregon Attorney General filing reported October 29, 2025. Further detail may appear in later updates from the organization or regulators; until then, treat unconfirmed claims about methods, additional data types, or responsible parties as unverified.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

More recent breaches

Apro, LLC d/ Data Breach Notice (Oregon Attorney General)December 29, 2025Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)December 29, 2025700Credit, LLC Data Breach Notice (Oregon Attorney General)December 12, 2025American Association of Critical-Care Nurses Data Breach Notice (Oregon Attorney General)August 29, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Northwest Radiologists and Mt. Baker Imaging Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram