Lumexa Imaging Data Breach: What Happened and What to Do

Lumexa Imaging provides administrative services to affiliated radiology practices and imaging centers, and it had contracted with a vendor for non-clinical operational support. That vendor held patient information on its own systems. According to the notification letter, this was a third-party vendor breach: an unauthorized individual gained access to a portion of the vendor’s network and may have viewed or copied documents containing patient information. The vendor first flagged suspicious activity on April 9, 2026, and Lumexa Imaging says it immediately disconnected its systems from the vendor’s environment. On April 15, 2026, Lumexa Imaging learned that the unauthorized person may have viewed or obtained documents that were accessible between March 31, 2026 and April 9, 2026.

The letter is addressed to patients of Lumexa Imaging’s affiliated radiology practices and imaging centers whose records passed through this vendor’s system. The company states that the specific information involved varied by document and by individual, meaning not everyone who received a letter had every category of data exposed. No total number of affected patients was included in the notification text provided.

What information was exposed?
  • Full name
  • Date of birth
  • Home address
  • Phone number
  • Social Security number
  • Patient account number
  • Insurance information
  • Clinical information, including visit dates, diagnoses, or other health information related to radiology services

Lumexa Imaging is offering identity monitoring through Kroll at no cost, covering single bureau credit monitoring, fraud consultation, and identity theft restoration. To activate, visit https://enroll.krollmonitoring.com. The letter references a personal membership number and an enrollment deadline specific to each recipient, so check your printed letter for those exact details since they were not filled in on the template version reviewed here.

What should you do now?
  • Activate the free Kroll identity monitoring at https://enroll.krollmonitoring.com using the membership number printed on your letter, before whatever deadline is listed there.
  • Because your Social Security number and health information may have been exposed, place a fraud alert or a credit freeze with Equifax, Experian, and TransUnion — both are free.
  • Request your free annual credit reports at www.annualcreditreport.com and review them for accounts you don’t recognize.
  • Watch statements from your healthcare providers and health insurer closely, and contact the issuing entity right away if you spot unfamiliar charges or services.
  • Consider signing up for a service like Aura or LifeLock, which can alert you if your information appears elsewhere, especially given the mix of SSN, insurance, and medical data involved here.
  • If you notice signs of misuse, file a report with the FTC at www.identitytheft.gov and consider filing a police report so you have documentation for creditors.
  • Keep the breach letter and any Kroll enrollment confirmation somewhere safe, in case you need to reference them later when disputing fraudulent activity.

If you have questions, Lumexa Imaging can be reached at (844) 959-7072 (Monday through Friday, 8:00 a.m. to 5:30 p.m. Central Time) or at (919) 763-1100.

Leave a Comment