Saint Pete MRI, a diagnostic imaging and sleep lab based in St. Petersburg, Florida, recently notified patients that a security incident at the practice may have exposed their personal and protected health information.
Medical practices that handle sensitive patient records have a responsibility to keep that information secure, and when that responsibility isn’t met, patients are left to deal with the fallout.
Saint Pete MRI’s Data Breach Investigation
According to a notice posted by Saint Pete MRI, the company became aware of suspicious activity on its network on or around February 23, 2025. The company states that it immediately took steps to secure its internal systems and hired independent forensic experts to investigate what happened and whether any data had been affected. That investigation confirmed that the practice’s electronic patient care and imaging systems were not accessed, but determined that certain scanned data may have been acquired without authorization.
Saint Pete MRI then hired an independent team to conduct a comprehensive review of the affected files to determine what personal information they contained. That review was completed on April 7, 2026, more than a year after the suspicious activity was first detected, and determined that certain personal information may have been included in the affected data. The company then worked to verify potentially affected individuals, gather and validate contact information, and assess the scope of impacted information, a process it says was completed on July 15, 2026. Notification letters went out on July 22, 2026, and the company posted a substitute notice online for individuals whose contact information could not be located.
Long gaps between when a breach is first detected and when affected patients actually learn about it are common in incidents involving scanned records and archived files, since a forensic review of that kind of data can take many months to complete before a company can say with confidence whose information was actually involved. That doesn’t make the wait any easier for patients who are left wondering whether their information was exposed during the intervening period.
Health care providers, including imaging centers and diagnostic labs, are common targets for cyberattacks because the records they store, medical histories, insurance details, and government-issued identification, are especially valuable on the black market. Unlike a credit card number, which can be canceled and reissued, a Social Security number or a medical history cannot simply be replaced, which is part of why healthcare data breaches tend to carry long-term risk for the people affected.
The specific combination of data reportedly involved here, Social Security numbers, dates of birth, driver’s license or state ID numbers, and medical and health insurance information, is particularly useful to identity thieves because it can support both conventional identity theft and medical identity fraud. Medical identity fraud happens when someone uses a victim’s stolen information to obtain treatment, prescriptions, or medical equipment under that person’s name, which can also corrupt the victim’s own medical records with someone else’s treatment history.
Saint Pete MRI has stated that it currently has no evidence that any of the potentially affected information has been misused. Affected individuals who are unsure whether their information was involved, or who have questions about the scope of the incident, are encouraged to review any notice they received directly and to contact the toll-free call center the company has set up for this purpose.
Patients notified of a breach like this one are often advised to remain alert for follow-up phishing attempts in the weeks and months after a notification letter goes out. Scammers sometimes use news of a real data breach as cover to send fake account-verification emails or texts that mimic a legitimate follow-up from the breached company, hoping to trick recipients into handing over even more personal information. Anyone contacted about this incident should independently verify any communication referencing the breach before clicking links or providing information, ideally by calling the official call center number directly rather than a number or link provided in an unsolicited message.
When Did This Breach Occur?
Saint Pete MRI states that it became aware of suspicious network activity on or around February 23, 2025. A subsequent forensic review determined that certain scanned data may have been acquired without authorization during that incident. A follow-up review of the affected files, completed April 7, 2026, determined that personal information may have been included. The company finished verifying and notifying affected individuals on July 15, 2026, and mailed notification letters on July 22, 2026.
What Information Was Breached?
Saint Pete MRI states that the information involved may include names, Social Security numbers, dates of birth, driver’s license numbers or state identification numbers, medical information, and health insurance information. The company says its electronic patient care and imaging systems were not accessed during the incident.
What You Can Do
If you received notice that your information was involved in this breach, consider taking the following steps:
- Review your notice letter carefully for instructions specific to your situation.
- Review your medical records and health insurance statements for services you don’t recognize.
- Monitor your credit report and financial accounts for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the major credit bureaus.
- Contact the dedicated call center at 1-877-396-3217 with questions about your specific notice.
File a Data Breach Lawsuit Against Saint Pete MRI
If your Social Security number, medical information, or other personal data was exposed because of this breach, you may be entitled to compensation. Medical practices are expected to protect the sensitive information entrusted to them, and when a security failure exposes that data, affected patients often have legal options.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.