
East River Medical Imaging, a New York-based provider with multiple locations, disclosed a potential data breach impacting nearly 606,000 individuals, both patients and staff. The incident adds to a string of cyberattacks affecting medical imaging facilities nationwide.
The organization detected suspicious activity in its IT network on Sept. 20 and promptly launched an investigation with cybersecurity experts involving law enforcement. The probe revealed unauthorized access to their system, with certain documents viewed and copied between Aug. 31 and Sept. 20, 2023.
While ERMI reported the breach to the Department of Health and Human Services on Nov. 22 as a hacking incident impacting 605,809 individuals, it remains unclear whether this figure includes employees and patients. Queries for further details from ERMI have yet to be answered.
Similarly, South Austin Health Imaging, operating as Longhorn Imaging Center in Texas, reported a hacking incident on Nov. 3 affecting around 100,643 individuals, also involving a network server and additional IT components.
Notably, HHS OCR records show several significant breaches among medical imaging providers in 2023, with ERMI’s incident being the largest reported to date this year.
Cybersecurity experts emphasize the attractiveness of medical imaging centers as targets, citing the value of medical data and images for potential fraud and privacy breaches. The evolving landscape of healthcare technology has expanded the attack surface, making identity- and vulnerability-based attacks more prevalent.
Specialty healthcare providers, often assuming immune to cyber threats due to their size or profile, face substantial risks due to comparatively immature cybersecurity measures. This vulnerability makes them lucrative targets for cybercriminals seeking quick gains.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543