Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
HIPAA ResponseBreach FilingVerified

Radiology Associates of Richmond breach filing: access controls in imaging practices

Radiology Associates of Richmond filed a breach report with HHS OCR. The filing discloses no individual count. Role-based access and PHI monitoring are the controls most directly implicated by this kind of record.

Source of record: HHS OCRMay 26, 2026Last verified August 22, 2026

What the source establishes

Unauthorized data exfiltration succeeds when access controls are too broad — when a single compromised credential can reach thousands of records because no role boundary stopped the lateral movement. Radiology and diagnostic imaging practices are a concentrated-risk environment: large volumes of structured clinical findings, referral-network connectivity to hospital systems, and PHI tied to specific diagnoses that carries elevated identity-theft and insurance-fraud potential. Recent reporting on the Radiology Associates of Richmond breach — in which threat actors exfiltrated files containing PHI belonging to approximately 266,000 individuals — illustrates exactly this pattern.

What HIPAA requires here

Two Security Rule provisions are directly implicated. §164.312(a)(1) — Access Control requires covered entities to assign unique user IDs, enforce role-appropriate system access, and limit PHI reachability to what each workforce role requires. §164.308(a)(1)(ii)(A) — Risk Analysis requires a documented, organization-wide assessment of risks to ePHI confidentiality, integrity, and availability. OCR breach investigations routinely open by requesting both: the access control matrix and the most recent written risk analysis. Neither can be reconstructed after the fact.

Patient Protect mapping

  • Access Management with 8 defined user roles enforces role-based access boundaries across the practice, ensuring that clinical staff, billing personnel, and administrative accounts are provisioned only to the systems and data their role requires — directly reducing the records reachable through any single compromised credential.
  • ePHI Audit Logging produces immutable, per-session access records across systems. Bulk or anomalous file access by any account is captured and reviewable, providing the early-detection signal that limits exfiltration volume.
  • Security Alerts deliver real-time notifications on access anomalies and policy deviations, so unusual account behavior surfaces before an exfiltration event is complete rather than weeks later during forensic review.
  • Security Risk Assessment (SRA) generates a written, facility-specific risk analysis — the first document OCR requests in any breach investigation — and recalculates risk profile as the environment changes, so the analysis is never stale at the moment it matters.
  • BAA Management / Vendor Risk Scanner ensures that every business associate with connectivity to imaging systems, billing platforms, or patient records has a current, executed Business Associate Agreement on file, with security obligations documented.

Controls worth reviewing

  • Audit every account with access to imaging and clinical systems in the near term — confirm that access maps to current role requirements and that inactive accounts are disabled.
  • Review your most recent written risk analysis — if it predates significant system or workflow changes, initiate a refresh before OCR requests it.
  • Verify that MFA is enforced on every remote-access and administrative account touching ePHI.
  • Confirm your breach notification workflow is ready to execute — staff should know the 60-day clock, have access to HHS portal credentials, and have template notification letters reviewed before they are needed.
  • Check that all imaging-system vendors and billing platforms have current BAAs — any gap creates independent regulatory exposure.

Sources

Source of record. Radiology Associates of Richmond appears in the HHS OCR breach portal, reported May 26, 2026, with no individual count disclosed. Where this page and the OCR record disagree, the OCR record is correct. The filing does not publish root cause, whether data was exfiltrated, or which categories of PHI were involved; those remain unknown unless a source establishes them.

Secondary reporting. Security Week. Reporting can establish that something happened; it does not establish what was filed. Written with AI assistance under Patient Protect’s editorial standards.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →