Northwest Radiologists and Mt. Baker Imaging Data Breach Notice (Oregon Attorney General)
If you received a notice from Northwest Radiologists and Mt. Baker Imaging, here’s what the filing says was exposed, and what to do about it.
Northwest Radiologists and Mt. Baker Imaging notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on October 29, 2025. The filing puts the incident itself on January 20, 2025.
The data breach at Northwest Radiologists and Mt. Baker Imaging means that personal information belonging to 362,713 people is now in the hands of an unknown party. The filing lists personal information as exposed in the incident that occurred on January 20, 2025. The organisation did not notify Oregon residents until October 29, 2025 — 282 days later.
That nine-and-a-half-month gap is the single most striking fact in the record. While notification deadlines vary by state and depend on when an investigation concludes, the interval is long enough to matter to anyone whose records were included.
Your Information Is Permanently Exposed
Because the exposed category is described only as personal information, the safest assumption is that details sufficient to support identity theft or insurance fraud are now outside the organisation’s control. Medical imaging providers hold names, dates of birth, addresses, and often Social Security numbers alongside imaging records and billing data. Once these leave the organisation’s systems they cannot be recalled.
No passwords were exposed. That is genuine good news. You do not need to change any password connected to Northwest Radiologists or Mt. Baker Imaging because none reached the attacker. The risk lies entirely in the non-credential personal data that cannot be reissued like a credit card.
What the 362,713 Figure Actually Represents
The scale — more than 362,000 individuals — reflects the large patient population served by these radiology practices across Oregon and surrounding areas. The number itself does not prove the breach was unusually sophisticated; it shows how many patient records were potentially accessible once the incident occurred.
The filing does not state exactly which specific fields each person lost, nor does it name the initial access method. What it does confirm is that personal information for this many people was involved on January 20, 2025.
How to Determine Whether You Were Affected
Northwest Radiologists and Mt. Baker Imaging are required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not part of this incident. However, if you have moved since January 20, 2025, a letter may have gone to an old address. In that case, contact the organisation directly to confirm whether you were included in the group of 362,713.
What This Exposure Enables Long-Term
Personal information from a radiology provider can be used to file fraudulent tax returns, open accounts in your name, or submit false medical claims for reimbursement. Because medical imaging records often contain diagnosis codes or treatment details, there is also a risk of insurance fraud or even blackmail in rare cases where sensitive conditions are involved.
Unlike a credit card number, none of this data can be cancelled or replaced. The exposure is permanent. The only remaining protection is vigilance: monitoring for misuse rather than prevention.
The Gap Between Incident and Notification
The 282 days between January 20 and October 29, 2025, is the interval the public record provides. The filing contains no discovery date, so it is impossible to know how long the data may have been accessible before the organisation became aware of the breach. What matters to you is that nearly ten months passed between the incident and the point at which patients could begin protecting themselves.
This delay does not automatically mean the organisation violated any specific law — different states apply different clocks — but it does mean many affected individuals had no practical way to respond for most of 2025.
Concrete Risks That Remain
With personal information exposed, the main ongoing threats are identity theft and medical fraud. Fraudsters can combine a name, date of birth, and Social Security number (if included) to impersonate you with insurers or government agencies. Medical identity theft can lead to incorrect information being added to your permanent health record, which can create problems when you later need care.
Because the record lists only the broad category of personal information, you should treat the worst plausible case as possible until your own notification letter clarifies exactly what was taken.
Practical Steps You Can Take Now
- Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion. This is the single most effective step to stop new accounts being opened in your name using any exposed identifiers.
- Review your Explanation of Benefits statements from every health insurer you use. Look for claims you do not recognise. Medical identity theft is often spotted first through insurance paperwork.
- Request your free annual credit reports and check for unfamiliar accounts or addresses. Do this every four months rotating across the three bureaus.
- Monitor tax transcripts from the IRS next year. Fraudulent tax returns filed with a stolen Social Security number are a common consequence of this type of breach.
- Contact Northwest Radiologists or Mt. Baker Imaging directly if you moved at any point after January 20, 2025, and have not received a letter. Confirm whether your specific record was in the affected group of 362,713.
The breach at Northwest Radiologists and Mt. Baker Imaging is now a permanent part of your risk profile. The data cannot be taken back. What you control is how quickly you respond and how closely you watch for the specific types of fraud this exposure makes easier. Start with the credit freeze and the insurance review — those two actions address the most immediate and damaging risks created by the January 2025 incident.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
Clinical Associates of the Finger Lakes (CAFL) Listed by Barracuda Ransomware Group
The company mishandled its clients' and employees' data, which is why it was leaked. We extracted al…