Radiology Associates of Richmond Hit by Second Breach in 14 Months — 266,000 Patients Exposed

A Richmond radiology practice that disclosed a 1.4 million-patient breach in mid-2025 has now confirmed a second incident, raising urgent questions about whether its security posture ever recovered.

Written by OutOfToken AI

June 4, 2026 · 4 min read · Synthesized from reporting by DataBreaches.net · How this works

AI Likely Accurate · 7/10

Radiology Associates of Richmond is back in breach territory. The Virginia-based private radiology group — still absorbing the fallout from a catastrophic April 2024 incident that compromised more than 1.4 million patient records — has confirmed a second unauthorized intrusion beginning on or around July 25, 2025, this time affecting approximately 266,000 individuals. The back-to-back disclosures paint a troubling picture of a healthcare organization struggling to hold its perimeter.

What Was Taken — and From Whom

Threat actors exfiltrated files containing a combination of protected health information (PHI), personally identifiable information (PII), and financial data. According to RAR's official breach notice, names were among the compromised fields, alongside clinical and financial records typically associated with radiology workflows — imaging orders, insurance details, and billing data. The breadth of data types exposed is significant: radiology records often carry diagnostic context that makes them more sensitive than a standard administrative breach, and the inclusion of financial data widens the downstream fraud risk for those affected.

A Timeline That Raises Red Flags

The July 2025 intrusion date against a disclosure timeline stretching into 2026 means RAR sat on knowledge of the breach for months before formally notifying regulators — a pattern that has drawn scrutiny from both the HHS Office for Civil Rights and state attorneys general in recent years. The first breach, which began in April 2024, was itself not reported to HHS until July 2025, a gap of roughly 15 months. Cybersecurity analysts at Rescana flagged a discrepancy between RAR's official incident notice and the regulatory filing timeline, suggesting the organization may have struggled to fully scope the second intrusion before going public. HIPAA's Breach Notification Rule generally requires covered entities to notify HHS within 60 days of discovering a breach affecting 500 or more individuals — a deadline RAR appears to have stretched, if not exceeded.

"RAR's two breaches combined have now exposed data belonging to an estimated 1.67 million patients — a staggering accumulation for a single regional practice within roughly 15 months."

Why Healthcare Radiology Practices Are Soft Targets

Radiology practices occupy a particularly exposed corner of the healthcare attack surface. They sit at the intersection of clinical systems, billing infrastructure, and imaging platforms — often running legacy DICOM servers and PACS environments that were built for performance, not security hardening. Third-party vendor integrations are common, and patch cycles tend to lag behind. The second breach at RAR, occurring so shortly after the first, suggests that the initial remediation either failed to address root-cause vulnerabilities or that threat actors retained a foothold that was never fully evicted. Security researchers have documented cases where ransomware groups and data extortion actors deliberately revisit healthcare targets after a first successful exfiltration, knowing that recovery windows are chaotic and attention is split.

For RAR, the path forward is steep: federal notification obligations, likely OCR investigation, potential state-level enforcement from Maine's attorney general — which received the second breach filing — and the reputational damage of being publicly identified as a repeat-breach organization. For the broader healthcare sector, the case is another loud data point in an argument regulators have been making for years: voluntary cybersecurity frameworks are not sufficient, mandatory minimum security standards for covered entities are overdue, and organizations that survive one breach without structural reform are not survivors — they are sitting targets.

Editorial Note

DataBreaches.net is a reputable, established resource for tracking healthcare data breaches and typically reports information derived from official HHS notifications and state attorney general filings. The specific details about timing (July 2025 disclosure, April 2024 breach date) and the mention of 1.4 million patients suggest sourcing from actual breach notifications. However, the summary contains an internal inconsistency (July 2025 second breach reported to Maine AG in May) that creates minor credibility concerns.

Claim Tracker

AI-assessed

UnverifiedRAR reported a breach to HHS on July 1, 2025, occurring in April 2024, affecting more than 1.4 million patients

No independent source cited; reliant on RAR's official reporting

UnverifiedA second breach began on or around July 25, 2025, affecting approximately 266,000 individuals

Article states this was 'recently reported to Maine Attorney General's Office on May [date cut off]' - timeline inconsistency (May report for July 2025 breach)

UnverifiedCompromised data included names, clinical records, imaging orders, insurance details, and billing data

Based on RAR's breach notice but no independent verification provided

VerifiedRadiology records carry diagnostic context making them more sensitive than standard administrative breaches

General security principle; accurate assessment of radiology data sensitivity

UnverifiedRAR experienced two breaches within 14 months

Timeline appears questionable: first breach April 2024, reported July 2025; second breach July 2025 - requires clarification on discovery vs. occurrence dates

Ask AI about this story

// discussion

sign in to join the discussion