Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Unauthorized access to an unnamed contracted vendor’s systems used to support Lumexa Imaging and affiliated imaging practices. [3][5][6]
Impact
Electronic patient data extracted from an unnamed contracted vendor’s information technology systems. [1][3][6]
Documented data types include:
- Social Security numbers — The information varied by document and individual and may have included this category. [3][6]
- Patient account numbers — The information varied by document and individual and may have included this category. [3][6]
- Dates of birth — The information varied by document and individual and may have included this category. [3][6]
- Health insurance information — The information varied by document and individual and may have included this category. [3][6]
- Contact information — The information varied by document and individual and may have included addresses and phone numbers. [3][6]
- Clinical information — The detailed notice says this information varied by document and individual; Lumexa’s SEC filing separately confirms extraction of electronic patient data including protected health information. [3][6]
- Names — The information varied by document and individual and may have included this category. [3][6]
A cited record reports 157 individuals (Nebraska residents whose affected information met Nebraska’s statutory definition of personal information; the notice says additional Nebraska residents also received notice; as of 2026-06-12). [1][3][6]
A cited record reports 825 individuals (as of 2026-06-12). [1]
A cited record reports 2,994 individuals (Individuals reported in the HHS OCR current investigation table; treated as a reported count, not an independently verified final total; as of 2026-05-15). [1][3][6]
Electronic patient data was extracted from the information technology systems of an unnamed vendor contracted to provide non-clinical administrative services. [4][6]
Timeline
Documented event
Vendor reports suspicious activity to Lumexa is recorded on this date.
[3]Documented event
Lumexa learns patient documents may have been obtained is recorded on this date.
[3]Documented event
Initial affected-individual notification mailing is recorded on this date.
[3]Public disclosure
Date Lumexa began its first affected-individual notification mailing.
[3]Documented event
Additional notification mailing including Nebraska residents is recorded on this date.
[3]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Lumexa immediately disconnected its systems from the vendor’s network. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3]
