SimonMed Data Breach Exposes 1.2 Million Patients Sensitive Information
SimonMed Imaging, a prominent provider of outpatient medical imaging services in the United States, reported a significant cybersecurity breach that affected the personal and health data of approximately 1.2 million patients.
SimonMed Imaging, a prominent provider of outpatient medical imaging services in the United States, reported a significant cybersecurity breach that affected the personal and health data of approximately 1.2 million patients.
The breach was linked to a ransomware attack perpetrated by the Medusa group, underscoring vulnerabilities within the healthcare sector.
Notifications to affected individuals commenced on Tue, Oct 10, 2025, following an investigation to determine the full extent of the breach.
The incident was detected in late January 2025 when SimonMed received an alert from a third-party vendor about a potential security issue on January 27. The company then conducted a system review and uncovered unauthorized access that began on January 21 and continued until February 5.
Forensic experts confirmed that cybercriminals accessed the network and extracted files containing sensitive patient information over a two-week period.
SimonMed operates more than 170 imaging centers across 11 states, providing services such as MRI, CT scans, ultrasounds, and mammograms. The company reported annual revenue exceeding $500 million.
The Medusa ransomware group was identified as responsible for stealing approximately 212 gigabytes of data. They demanded a $1 million ransom and posted sample data on a dark web site to pressure the company.
SimonMed has not confirmed whether the ransom was paid or disclosed details about the breach's entry point, which may have involved a vendor. The incident highlights the risks associated with supply chain attacks in healthcare.
In response, SimonMed implemented several measures, including resetting passwords, enhancing multifactor authentication, deploying endpoint detection and response tools, severing direct vendor access to internal systems, and restricting network traffic to approved sources.
The company also notified law enforcement and privacy specialists, reporting the breach to relevant authorities, including the U.S. Department of Health and Human Services' Office for Civil Rights.
The breach was linked to a ransomware attack perpetrated by the Medusa group, underscoring vulnerabilities within the healthcare sector.
The exposed data varied among individuals, involving details such as full names, addresses, dates of birth, service dates, provider names, medical records and patient numbers, diagnoses, treatment histories, prescribed medications, health insurance details, and driver’s license numbers.
This data exposure poses risks of identity theft, medical fraud, and phishing schemes as health records are valuable on underground markets.
SimonMed reports no confirmed cases of data misuse for fraud or identity theft related to the breach. However, the nine-month delay in notifications has drawn criticism from cybersecurity experts and patient advocates.
An initial report to regulators estimated 500 affected individuals, but the actual number of 1,275,669 was confirmed after comprehensive file reviews.
Data Type Description Potential Risk
Personal Identifiers Names, addresses, DOB, driver’s licenses Identity theft, stalking
Medical Records Diagnoses, treatments, medications Medical fraud, blackmail
Insurance & Financial Health insurance info, patient numbers Billing scams, unauthorized claims
This table summarizes the key categories of compromised data, illustrating the multifaceted threats posed to patients' privacy and security.
The breach has led to at least one class-action lawsuit against SimonMed, alleging negligence in protecting patient data and insufficient transparency during the response.
Law firms are investigating claims on behalf of affected customers, potentially resulting in broader litigation as more details emerge.
As a mitigation measure, SimonMed is offering complimentary 24-month memberships to Experian IdentityWorks, providing fraud detection, credit monitoring, and identity restoration services.
Patients are encouraged to enroll promptly using unique activation codes provided in notification letters and to regularly review credit reports via AnnualCreditReport.com. They should also consider placing fraud alerts with major credit bureaus like Equifax, Experian, and TransUnion.
The incident reflects a rise in ransomware attacks targeting the healthcare sector, with Medusa claiming over 300 victims across critical sectors in 2025, as noted in an FBI advisory from March 2025.
SimonMed's ongoing security enhancements, including advanced monitoring and vendor audits, aim to prevent future incidents, highlighting the need for robust defenses against evolving cyber threats in the industry.
Based on reporting by Cyber Security News.
