CSIDB logo
Incident

Saint Pete MRI

Incident posture

Attack window
Feb 2025
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-07-26 06:17

Linked entities

Victim
Saint Pete MRI
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Saint Pete MRI, a diagnostic imaging and sleep lab in St. Petersburg, Florida, disclosed a data breach after discovering that certain scanned files may have been accessed without authorization. An investigation found that the exposed files could have contained patient information such as names, Social Security numbers, dates of birth, driver's license or state identification numbers, medical details and health insurance information. The organization completed its review before notifying affected individuals and reported the incident to the Health and Human Services Office for Civil Rights. It stated there is no evidence the data has been misused and set up a call center to assist those impacted, available weekdays from 9 a.m. to 9 p.m. Eastern Time, excluding major U.S. holidays.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Saint Pete MRI, a diagnostic imaging and sleep lab located in St. Petersburg, Florida, experienced a data breach that occurred on or around February 23 2025. The organization’s administrators became aware of the incident at an unspecified time after the breach and subsequently engaged independent forensic experts to investigate the cause and determine what information might have been exposed. The forensic review concluded that, although the center’s clinical and imaging systems remained secure, certain scanned files had been accessed without authorization. A follow‑up review completed on April 7 2026 identified that the affected files potentially contained patient names, Social Security numbers, dates of birth, driver’s license or state identification numbers, medical information, and health insurance details.

The company finalized its internal review and verification process on July 15 2026, after which it began notifying affected individuals on July 22 2026. Notification letters were mailed to patients whose contact information could be verified, while a substitute notice was posted on the organization’s website for those whose contact details could not be confirmed. Saint Pete MRI also reported the breach to the Health and Human Services Office for Civil Rights. In its communications, the organization stated that it has no evidence that the potentially exposed information has been misused.

To assist affected individuals, Saint Pete MRI established a dedicated call center operating Monday through Friday from 9:00 a.m. to 9:00 p.m. Eastern Time, excluding major U.S. holidays, reachable at 877‑396‑3217. The notice accompanying the outreach emphasized that the privacy and security of patient data is of utmost importance to the organization and expressed regret for any concern or inconvenience caused by the incident. No further details about the breach’s origin, attacker identity, or specific technical vulnerabilities were disclosed in the available source material.

Sources

Sources available to members: 2 sources.

CSIDB