
New York-based diagnostic practice East River Medical Imaging said it suffered a significant data breach that compromised the sensitive personal information of more than 600,000 individuals.East River Medical Imaging is one of the most prominent diagnostic imaging and radiology practices in New York City. With almost 150 employees, the facility provides a range of services, including bone densitometry, CT scans, interventional radiology, MRI scans, and ultrasounds.In a data security incident notice posted on its website, East River Medical Imaging said that it identified suspicious activity within its internal network on September 20 and immediately launched an internal investigation with assistance from third party cyber security experts to understand the nature and scope of the incident.“The investigation determined that an unauthorised party accessed our network and, between August 31, 2023 and September 20, 2023, accessed and/or copied some documents on the system,” East River said.The firm said that information stolen by the threat actor included patients’ names, contact details, Social Security numbers, insurance information, exam and procedure information, referring physician, and imaging results. For affected employees, the compromised information includes names, contact information, Social Security numbers, financial account information, and driver’s license numbers.Though East River Medical Imaging did not mention the number of affected individuals in its incident notification, a filing with the U.S. Department of Health and Human Services Office for Civil Rights revealed that at least 605,809 individuals were impacted by the incident.“We have and will continue to take steps to enhance the security of our computer systems and the data we maintain. To help prevent something like this from happening again, we have enhanced our network monitoring capabilities, and will continue to assess and supplement our security controls going forward,” East River Medical Imaging added.The healthcare provider is yet to share details on who is behind the cyber attack or how the threat actors infiltrate its systems. It has, however, started notifying all affected individuals about the security incident since November 22.The medical diagnostics services provider is also providing complimentary credit monitoring services to individuals whose social security numbers or driver’s license numbers were compromised by the data security incident.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543