Lumexa Imaging vendor data disclosure

Unauthorized access to an unnamed contracted vendor's systems used to support Lumexa Imaging and affiliated imaging practices. Electronic patient data extracted from an unnamed contracted vendor's information technology systems.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to an unnamed contracted vendor’s systems used to support Lumexa Imaging and affiliated imaging practices. [3][5][6]

Impact

Electronic patient data extracted from an unnamed contracted vendor’s information technology systems. [1][3][6]

Documented data types include:

  • Social Security numbers — The information varied by document and individual and may have included this category. [3][6]
  • Patient account numbers — The information varied by document and individual and may have included this category. [3][6]
  • Dates of birth — The information varied by document and individual and may have included this category. [3][6]
  • Health insurance information — The information varied by document and individual and may have included this category. [3][6]
  • Contact information — The information varied by document and individual and may have included addresses and phone numbers. [3][6]
  • Clinical information — The detailed notice says this information varied by document and individual; Lumexa’s SEC filing separately confirms extraction of electronic patient data including protected health information. [3][6]
  • Names — The information varied by document and individual and may have included this category. [3][6]

A cited record reports 157 individuals (Nebraska residents whose affected information met Nebraska’s statutory definition of personal information; the notice says additional Nebraska residents also received notice; as of 2026-06-12). [1][3][6]

A cited record reports 825 individuals (as of 2026-06-12). [1]

A cited record reports 2,994 individuals (Individuals reported in the HHS OCR current investigation table; treated as a reported count, not an independently verified final total; as of 2026-05-15). [1][3][6]

Electronic patient data was extracted from the information technology systems of an unnamed vendor contracted to provide non-clinical administrative services. [4][6]

Timeline

  1. Activity began

    Unauthorized access to an unnamed contracted vendor’s systems used to support Lumexa Imaging and affiliated imaging practices.

    [3][5]
  2. Documented activity ended

    Unauthorized access to an unnamed contracted vendor’s systems used to support Lumexa Imaging and affiliated imaging practices.

    [3][5]
  3. Documented event

    Vendor reports suspicious activity to Lumexa is recorded on this date.

    [3]
  4. Discovery

    Date Lumexa became aware that patient data had been extracted; the vendor had reported suspicious activity on April 9.

    [3][6]
  5. Documented event

    Lumexa learns patient documents may have been obtained is recorded on this date.

    [3]
  6. Documented event

    Initial affected-individual notification mailing is recorded on this date.

    [3]
  7. Public disclosure

    Date Lumexa began its first affected-individual notification mailing.

    [3]
  8. Documented event

    Additional notification mailing including Nebraska residents is recorded on this date.

    [3]
  9. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Lumexa immediately disconnected its systems from the vendor’s network. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3]