Menu
Browse

Cyber Incident Victim: Saint Pete MRI

Date:

Feb 2025

Location:

United States of America

Summary

Saint Pete MRI, a diagnostic imaging and sleep lab in St. Petersburg, Florida, disclosed a data breach after discovering that certain scanned files may have been accessed without authorization. An investigation found that the exposed files could have contained patient information such as names, Social Security numbers, dates of birth, driver's license or state identification numbers, medical details and health insurance information. The organization completed its review before notifying affected individuals and reported the incident to the Health and Human Services Office for Civil Rights. It stated there is no evidence the data has been misused and set up a call center to assist those impacted, available weekdays from 9 a.m. to 9 p.m. Eastern Time, excluding major U.S. holidays.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

Saint Pete MRI, a diagnostic imaging and sleep lab located in St. Petersburg, Florida, experienced a data breach that occurred on or around February 23 2025. The organization’s administrators became aware of the incident at an unspecified time after the breach and subsequently engaged independent forensic experts to investigate the cause and determine what information might have been exposed. The forensic review concluded that, although the center’s clinical and imaging systems remained secure, certain scanned files had been accessed without authorization. A follow‑up review completed on April 7 2026 identified that the affected files potentially contained patient names, Social Security numbers, dates of birth, driver’s license or state identification numbers, medical information, and health insurance details.

Cyber Incident Image

The company finalized its internal review and verification process on July 15 2026, after which it began notifying affected individuals on July 22 2026. Notification letters were mailed to patients whose contact information could be verified, while a substitute notice was posted on the organization’s website for those whose contact details could not be confirmed. Saint Pete MRI also reported the breach to the Health and Human Services Office for Civil Rights. In its communications, the organization stated that it has no evidence that the potentially exposed information has been misused.

To assist affected individuals, Saint Pete MRI established a dedicated call center operating Monday through Friday from 9:00 a.m. to 9:00 p.m. Eastern Time, excluding major U.S. holidays, reachable at 877‑396‑3217. The notice accompanying the outreach emphasized that the privacy and security of patient data is of utmost importance to the organization and expressed regret for any concern or inconvenience caused by the incident. No further details about the breach’s origin, attacker identity, or specific technical vulnerabilities were disclosed in the available source material.

Sources
Sources available to members
1 source