Advanced Radiology Services, P.C., a Michigan healthcare provider, reported a data breach affecting 826 individuals to the U.S. Department of Health and Human Services on September 16, 2026. The report classifies the incident as a hacking or IT incident involving a network server.
Advanced Radiology Services’ Data Breach Investigation
Advanced Radiology Services, P.C. is listed on the U.S. Department of Health and Human Services (HHS) Office for Civil Rights breach portal as a healthcare provider located in Michigan. The practice describes itself on its own website as a Grand Rapids-based radiology group whose radiologists read imaging studies such as X-rays, CT scans and MRIs for hospitals and health systems across the state. The portal is the public list of breaches of unsecured protected health information that affect 500 or more people, and entities covered by HIPAA must report to it when such an incident occurs.
According to the portal entry, Advanced Radiology Services submitted its breach report on September 16, 2026. The entry states that 826 individuals were affected. It classifies the type of breach as a hacking or IT incident, which is the category regulators use when an outside party gains access to a computer system or network. It identifies the location of the breached information as a network server and as an additional location labeled other.
The portal entry is short by design. It does not describe how the intrusion happened, how long an unauthorized party had access, whether any files were copied or only viewed, or which categories of personal or health information were stored on the affected server. Because those details have not been published in the sources reviewed for this page, this page does not guess at them. Anyone who receives a letter from the practice should treat that letter as the most reliable account of what applies to them.
Radiology practices hold a distinctive mix of information. Imaging orders and reports are tied to a patient’s name, date of birth and contact details, and they often reference the reason a scan was ordered, which can reveal a diagnosis or a suspected condition. Billing and registration records add insurance details and, in many cases, Social Security numbers. Whether any of those categories were present on the server at issue here has not been disclosed, and nothing in this page should be read as confirming that they were.
Healthcare organizations are frequent targets of network intrusions because medical records are valuable and because a single server can hold records for many patients at once. A hacking or IT incident entry does not by itself say whether the activity involved ransomware, stolen credentials, a vulnerability in software, or something else. Each of those scenarios leads to different risks for patients, which is another reason the details in the company’s own notice matter.
Under HIPAA, covered entities generally must notify affected individuals without unreasonable delay, and no later than 60 days after discovering a breach. Notice letters usually explain what happened, what information was involved and what steps the organization is taking, and they often include an offer of credit monitoring or identity protection. If you receive a letter, keep it, along with any activation code or enrollment deadline it lists, and keep the envelope, since the postmark can help document when notice was sent.
Organizations that handle health information are expected to protect their servers and networks with measures such as access controls, multi-factor authentication, network monitoring, timely software updates and encryption of stored records. Whether and how those safeguards were applied at Advanced Radiology Services has not been disclosed. The regulator’s review of reports like this one can take a long time, and the public portal may not be updated with additional details for months.
For patients, the practical takeaway is to stay alert. Medical identity theft, where someone uses another person’s identity to obtain care or file insurance claims, can be hard to spot because the first sign is often an unfamiliar bill or explanation of benefits. Reviewing those documents regularly, and checking credit reports for accounts you did not open, are sensible habits after any healthcare breach, whether or not you have yet received a notice letter.
When Did This Breach Occur?
The HHS portal lists a breach submission date of September 16, 2026. The portal entry does not state when the unauthorized access began or when the practice discovered it, so the dates of the underlying events have not been confirmed.
What Information Was Breached?
The HHS portal lists a network server and an additional location labeled other as the places where the breached information was held, and it classifies the incident as hacking or an IT incident. It does not say which kinds of personal or health information were involved. Advanced Radiology Services has not publicly disclosed a specific list of affected data types in the sources reviewed for this page.
What You Can Do
If you received a notice from Advanced Radiology Services, consider these steps:
- Read the notice carefully and note any enrollment deadline or activation code for free credit monitoring or identity protection.
- Place a free fraud alert on your credit file, or consider a credit freeze, with Equifax, Experian and TransUnion.
- Review explanation of benefits statements, insurance statements and bank accounts for anything you do not recognize, and check your credit reports for free at annualcreditreport.com.
- Report suspected identity theft to the Federal Trade Commission at identitytheft.gov and to your state Attorney General.
File a Data Breach Lawsuit Against Advanced Radiology Services
If you received a notice about this incident, or believe your personal or health information was exposed, you may have legal options. Healthcare organizations are expected to safeguard patient information, and a class action can help hold them accountable when they fail to do so.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.