---
title: "Lumexa Imaging vendor data disclosure"
description: "Evidence-backed account of Lumexa Imaging vendor data disclosure, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/lumexa-imaging-vendor-data-disclosure-2026"
markdown_url: "https://www.ally.security/incidents/lumexa-imaging-vendor-data-disclosure-2026.md"
stix_url: "https://www.ally.security/incidents/lumexa-imaging-vendor-data-disclosure-2026/stix.json"
---

# Lumexa Imaging vendor data disclosure

Unauthorized access to an unnamed contracted vendor's systems used to support Lumexa Imaging and affiliated imaging practices. Electronic patient data extracted from an unnamed contracted vendor's information technology systems.

Last modified Aug 9, 2026 · 6 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to an unnamed contracted vendor's systems used to support [Lumexa Imaging](https://www.lumexaimaging.com/) and affiliated imaging practices. [3](#source-3) [5](#source-5) [6](#source-6)

## Impact

Electronic patient data extracted from an unnamed contracted vendor's information technology systems. [1](#source-1) [3](#source-3) [6](#source-6)

Documented data types include:

- Social Security numbers — The information varied by document and individual and may have included this category. [3](#source-3) [6](#source-6)
- Patient account numbers — The information varied by document and individual and may have included this category. [3](#source-3) [6](#source-6)
- Dates of birth — The information varied by document and individual and may have included this category. [3](#source-3) [6](#source-6)
- Health insurance information — The information varied by document and individual and may have included this category. [3](#source-3) [6](#source-6)
- Contact information — The information varied by document and individual and may have included addresses and phone numbers. [3](#source-3) [6](#source-6)
- Clinical information — The detailed notice says this information varied by document and individual; Lumexa's SEC filing separately confirms extraction of electronic patient data including protected health information. [3](#source-3) [6](#source-6)
- Names — The information varied by document and individual and may have included this category. [3](#source-3) [6](#source-6)

A cited record reports 157 individuals (Nebraska residents whose affected information met Nebraska's statutory definition of personal information; the notice says additional Nebraska residents also received notice; as of 2026-06-12). [1](#source-1) [3](#source-3) [6](#source-6)

A cited record reports 825 individuals (as of 2026-06-12). [1](#source-1)

A cited record reports 2,994 individuals (Individuals reported in the HHS OCR current investigation table; treated as a reported count, not an independently verified final total; as of 2026-05-15). [1](#source-1) [3](#source-3) [6](#source-6)

Electronic patient data was extracted from the information technology systems of an unnamed vendor contracted to provide non-clinical administrative services. [4](#source-4) [6](#source-6)

## Timeline

### March 31, 2026 — Activity began

Unauthorized access to an unnamed contracted vendor's systems used to support Lumexa Imaging and affiliated imaging practices. [3](#source-3) [5](#source-5)

### April 9, 2026 — Documented activity ended

Unauthorized access to an unnamed contracted vendor's systems used to support Lumexa Imaging and affiliated imaging practices. [3](#source-3) [5](#source-5)

### April 9, 2026 — Documented event

Vendor reports suspicious activity to Lumexa is recorded on this date. [3](#source-3)

### April 15, 2026 — Discovery

Date Lumexa became aware that patient data had been extracted; the vendor had reported suspicious activity on April 9. [3](#source-3) [6](#source-6)

### April 15, 2026 — Documented event

Lumexa learns patient documents may have been obtained is recorded on this date. [3](#source-3)

### May 15, 2026 — Documented event

Initial affected-individual notification mailing is recorded on this date. [3](#source-3)

### May 15, 2026 — Public disclosure

Date Lumexa began its first affected-individual notification mailing. [3](#source-3)

### June 12, 2026 — Documented event

Additional notification mailing including Nebraska residents is recorded on this date. [3](#source-3)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Lumexa immediately disconnected its systems from the vendor's network. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [3](#source-3)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/lumexa-imaging-vendor-data-disclosure-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<a id="source-2"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<a id="source-3"></a>

### Lumexa Imaging data breach notice and appendix

regulatory · Nebraska Attorney General

<https://www.nebraska.gov/ago/data-breach/documents/cb7ae6c6-2683-42e3-b5fe-0aa953fd982d.pdf>

<a id="source-4"></a>

### Lumexa Imaging notice of data incident

official · Lumexa Imaging

<https://oag.ca.gov/system/files/Lumexa%20-%20California%20Notification.pdf>

<a id="source-5"></a>

### Submitted Breach Notification Sample — Lumexa Imaging

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-623542>

<a id="source-6"></a>

### Quarterly Report on Form 10-Q for the period ended March 31, 2026

regulatory · Lumexa Imaging Holdings, Inc. · May 12, 2026

<https://www.sec.gov/Archives/edgar/data/2071288/000119312526219480/lmri-20260331.htm>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   March–April 2026 Lumexa vendor-system compromise: Lumexa affiliated-practice patient data extraction
2. **Occurred At · 100% confidence · current**  
   Additional notification mailing including Nebraska residents: 2026-06-12
3. **Exposed Data Category · 90% confidence · current**  
   Lumexa affiliated-practice patient data extraction: Social Security numbers
4. **Exposed Data Category · 90% confidence · current**  
   Lumexa affiliated-practice patient data extraction: Patient account numbers
5. **Affected Individual Count · 100% confidence · current**  
   Lumexa affiliated-practice patient data extraction: 157 individual
6. **Ended At · 100% confidence · current**  
   March–April 2026 Lumexa vendor-system compromise: 2026-04-09
7. **Exposed Data Category · 90% confidence · current**  
   Lumexa affiliated-practice patient data extraction: Dates of birth
8. **Discovered At · 100% confidence · current**  
   March–April 2026 Lumexa vendor-system compromise: 2026-04-15
9. **Resulted In · 100% confidence · current**  
   Vendor reports suspicious activity to Lumexa: Lumexa immediately disconnected its systems from the vendor's network.
10. **Exposed Data Category · 90% confidence · current**  
   Lumexa affiliated-practice patient data extraction: Health insurance information
11. **Affected Organization · 100% confidence · current**  
   March–April 2026 Lumexa vendor-system compromise: Lumexa Imaging Holdings, Inc.
12. **Began At · 100% confidence · current**  
   March–April 2026 Lumexa vendor-system compromise: 2026-03-31
13. **Affected Individual Count · 100% confidence · current**  
   Lumexa affiliated-practice patient data extraction: 825 individual
14. **Occurred At · 100% confidence · current**  
   Initial affected-individual notification mailing: 2026-05-15
15. **Exposed Data Category · 90% confidence · current**  
   Lumexa affiliated-practice patient data extraction: Contact information
16. **Occurred At · 100% confidence · current**  
   Lumexa learns patient documents may have been obtained: 2026-04-15
17. **Disclosed At · 100% confidence · current**  
   March–April 2026 Lumexa vendor-system compromise: 2026-05-15
18. **Occurred At · 100% confidence · current**  
   Vendor reports suspicious activity to Lumexa: 2026-04-09
19. **Resulted In · 100% confidence · current**  
   Lumexa affiliated-practice patient data extraction: Electronic patient data was extracted from the information technology systems of an unnamed vendor contracted to provide non-clinical administrative services.
20. **Exposed Data Category · 99% confidence · current**  
   Lumexa affiliated-practice patient data extraction: Clinical information
21. **Exposed Data Category · 90% confidence · current**  
   Lumexa affiliated-practice patient data extraction: Names
22. **Affected Individual Count · 100% confidence · current**  
   Lumexa affiliated-practice patient data extraction: 2,994 individual

</details>
