Radiology Associates of Richmond, Inc. Data Breach Notice (Massachusetts Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Radiology Associates of Richmond, Inc. notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on May 21, 2026, and the notice lists medical records and financial account numbers among the information exposed.
The filing from Radiology Associates of Richmond, Inc. means that medical records and financial account numbers belonging to 81 Massachusetts residents were exposed. If you received a letter from the organisation, your information is among them. The notice lists only these two categories.
Medical records cannot be replaced
Once medical records leave an organisation’s control they remain sensitive for life. They contain details of diagnoses, treatments, medications, and test results that can be used for insurance fraud, prescription fraud, or to build a profile for identity theft. Unlike a credit card, you cannot cancel or reissue your medical history. The exposure of these records therefore creates a permanent risk that requires ongoing vigilance rather than a one-time fix.
Financial account numbers add a more immediate layer of concern. With access to account numbers and related medical context, someone could attempt fraudulent wire transfers, open new accounts in your name, or file false tax returns using your health information as supporting “proof” of identity. The combination of clinical data and financial identifiers is particularly valuable to fraudsters because it allows them to impersonate you across both healthcare and banking systems.
What the limited scope of the filing tells you
The record names only medical records and financial account numbers. No passwords, no Social Security numbers, and no permanent government identifiers such as driver’s license numbers appear in the filing. This is genuinely good news. You do not need to change any passwords because of this incident, and the absence of Social Security numbers removes the most common trigger for full identity-theft monitoring.
Because the filing does not state when the incident occurred, only the filing date of May 21, 2026 is known. The organisation is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not included. However, if you have moved since receiving care from Radiology Associates of Richmond, contact the organisation directly to confirm whether you were affected.
How medical records are typically misused
Thieves who obtain medical records often pursue two main paths. The first is healthcare fraud: using your insurance information to obtain services or prescription drugs that are then billed to you or your insurer. The second is synthetic identity fraud, where fragments of your medical history are combined with other stolen data to create a convincing fake identity for larger financial crimes.
Financial account numbers accelerate both types of abuse. A fraudster who already holds an account number can use details from your medical records to answer security questions or provide “proof of relationship” when calling banks or insurers. This is why the pairing of these two categories matters more than either one alone.
The practical limits of what you can control
You cannot erase the exposed medical records, but you can reduce what a criminal can do with them. Monitoring your Explanation of Benefits statements from every health insurer remains the single most effective way to catch fraudulent claims early. Similarly, reviewing bank and credit-card statements for unfamiliar transactions tied to the exposed account numbers gives you the best chance of stopping fraud before it grows.
Credit monitoring and fraud alerts provide an extra early-warning layer even without a Social Security number exposed. A fraud alert forces creditors to verify your identity before opening new accounts, adding friction that many opportunists will avoid.
Placing this breach in context
With only 81 people named in the filing, this is a narrowly targeted incident rather than a mass compromise. The small number does not reduce the seriousness for those affected, but it does mean the organisation’s overall patient population was not broadly swept up. The record itself discloses nothing about how the exposure happened, whether data was copied or simply viewed, or how long any unauthorised access lasted. Those details remain unknown.
What is certain is that medical records and financial account numbers retain their value long after most other stolen data loses relevance. The lifelong sensitivity of health information is why this filing, though small, still requires deliberate follow-up from anyone who was notified.
Actions that address this specific exposure
- Review every Explanation of Benefits statement you receive from insurers. Look for claims you did not file or services you did not receive. Report discrepancies to your insurer immediately.
- Check bank and credit-card statements monthly for any transaction linked to the exposed account numbers. Set up account alerts for transfers or charges above a low threshold.
- Place a fraud alert with the three major credit bureaus. This forces lenders to contact you before opening new accounts and is free for one year.
- Contact Radiology Associates of Richmond directly if you have changed addresses since receiving treatment there. Confirm whether your records were part of the 81 affected individuals.
- Keep records of the notification letter and all follow-up communications. Documentation helps if you later need to dispute fraudulent activity tied to this incident.
The letter you may have received is the most reliable indicator of whether your information was exposed. Absence of a letter usually means you were not in the affected group, but anyone uncertain should reach out to the organisation. Medical records and financial account numbers do not expire; the protective habits you adopt now will serve you for years to come.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Radiology Associates of Richmond, Inc..
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Clinical Associates of the Finger Lakes (CAFL) Listed by Barracuda Ransomware Group
The company mishandled its clients' and employees' data, which is why it was leaked. We extracted al…
el-group Listed by Inc Ransom Ransomware Group
el-group was listed on the Inc Ransom ransomware leak site. The group claims to have stolen internal…
Aquamar Inc Listed by metaencryptor Ransomware Group
Aquamar, Inc. specializes in providing high-quality, wild-caught seafood products that are both deli…