Radiology Associates of Richmond breach filing: access controls in imaging practices
Radiology Associates of Richmond filed a breach report with HHS OCR. The filing discloses no individual count. Role-based access and PHI monitoring are the controls most directly implicated by this kind of record.
What the source establishes
Unauthorized data exfiltration succeeds when access controls are too broad — when a single compromised credential can reach thousands of records because no role boundary stopped the lateral movement. Radiology and diagnostic imaging practices are a concentrated-risk environment: large volumes of structured clinical findings, referral-network connectivity to hospital systems, and PHI tied to specific diagnoses that carries elevated identity-theft and insurance-fraud potential. Recent reporting on the Radiology Associates of Richmond breach — in which threat actors exfiltrated files containing PHI belonging to approximately 266,000 individuals — illustrates exactly this pattern.
What HIPAA requires here
Two Security Rule provisions are directly implicated. §164.312(a)(1) — Access Control requires covered entities to assign unique user IDs, enforce role-appropriate system access, and limit PHI reachability to what each workforce role requires. §164.308(a)(1)(ii)(A) — Risk Analysis requires a documented, organization-wide assessment of risks to ePHI confidentiality, integrity, and availability. OCR breach investigations routinely open by requesting both: the access control matrix and the most recent written risk analysis. Neither can be reconstructed after the fact.
Patient Protect mapping
- Access Management with 8 defined user roles enforces role-based access boundaries across the practice, ensuring that clinical staff, billing personnel, and administrative accounts are provisioned only to the systems and data their role requires — directly reducing the records reachable through any single compromised credential.
- ePHI Audit Logging produces immutable, per-session access records across systems. Bulk or anomalous file access by any account is captured and reviewable, providing the early-detection signal that limits exfiltration volume.
- Security Alerts deliver real-time notifications on access anomalies and policy deviations, so unusual account behavior surfaces before an exfiltration event is complete rather than weeks later during forensic review.
- Security Risk Assessment (SRA) generates a written, facility-specific risk analysis — the first document OCR requests in any breach investigation — and recalculates risk profile as the environment changes, so the analysis is never stale at the moment it matters.
- BAA Management / Vendor Risk Scanner ensures that every business associate with connectivity to imaging systems, billing platforms, or patient records has a current, executed Business Associate Agreement on file, with security obligations documented.
Controls worth reviewing
- Audit every account with access to imaging and clinical systems in the near term — confirm that access maps to current role requirements and that inactive accounts are disabled.
- Review your most recent written risk analysis — if it predates significant system or workflow changes, initiate a refresh before OCR requests it.
- Verify that MFA is enforced on every remote-access and administrative account touching ePHI.
- Confirm your breach notification workflow is ready to execute — staff should know the 60-day clock, have access to HHS portal credentials, and have template notification letters reviewed before they are needed.
- Check that all imaging-system vendors and billing platforms have current BAAs — any gap creates independent regulatory exposure.
Corrections & Updates
Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.
