Lumexa Imaging Data Breach Affected 5.8 Million Individuals
The diagnostic imaging service provider Lumexa Imaging has been affected by a security incident involving one of its vendors. FMRS Health Systems, a West Virginia-based provider of mental health services, is investigating a January 2026 data breach. Lumexa Imaging Lumexa Imaging, a diagnostic imaging provider that, together with its affiliates, has the second-largest diagnostic imaging footprint in the United States, has notified regulators about a data security incident after being alerted about the incident by one of its vendors. The unnamed vendor provided non-clinical support services in connection with the administrative services Lumexa Imaging provided to its affiliated radiology practices. On April 9, 2026, the vendor notified Lumexa Imaging that it was investigating suspicious activity within part of its computer network. Lumexa Imaging immediately terminated the vendor’s access to its systems while the incident was investigated and remediated. The investigation confirmed a breach of the vendor’s systems between March 31, 2026, and April 9, 2026. On April 15, 2026, Lumexa...
Patients Want to Know When and How AI is Used in Healthcare
A recent survey has revealed that patients are concerned about the use of AI tools by doctors’ offices and other healthcare providers, and the vast majority of patients believe that they should be informed if their healthcare provider is using AI tools in connection with their healthcare. The survey also indicates that more than half of patients are unaware whether AI is currently being used in relation to their healthcare. The survey was conducted on almost 5,000 U.S. adults in late June 2026 by the Pew Research Center. The survey revealed that 72% of patients believe it is extremely important or very important for their healthcare providers to disclose whether they are using AI tools in connection with healthcare, with 16% of respondents believing that it is somewhat important. Only 7% of respondents said they are not too bothered or not at all bothered about being informed about the use of AI. Concern varied across different uses of AI, with the greatest concern expressed about AI being used to make diagnostic decisions (81%), analyze medical scans (81%), explain medical test...
SonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 Appliances
Two remotely exploitable zero-day vulnerabilities in SonicWall SMA1000 appliances are being chained together to achieve remote code execution, according to a recent SonicWall security alert. SMA1000 appliances are used for secure remote access and VPN connections and, as such, are commonly exposed to the Internet. One of the vulnerabilities, tracked as CVE-2026-83548, is a critical pre-authentication server-side request forgery issue in the Appliance Work Place interface that allows command injection. The vulnerability has been assigned a maximum CVSS v 3.1 severity score of 10. Successful exploitation allows a remote attacker to access sensitive functions and perform unauthorized actions. The vulnerability is being chained with an exploit for a high-severity (CVSS v3.1: 7.8) OS command injection vulnerability – CVE-2026-83549 – in the Appliance Management Console. Attackers with admin privileges can exploit the vulnerability and execute OS commands. The vulnerability is due to improper neutralization of special elements used in an OS command. The SonicWall PSIRT has...
Resource Center of Dallas Notifies 12,500 Patients About Cyber Incident
Data breaches have been announced by Resource Center of Dallas, Kern Psychiatric Health and Wellness Center, The Asthma Center, Integrative Emergency Services, and Psychiatry of Texas (PsychPlus). Resource Center of Dallas Resource Center of Dallas, Inc., a provider of health, wellness, and advocacy services to the LGBTQIA+ community in North Texas, is notifying 12,490 individuals about a data security incident earlier this year. Third-party cybersecurity professionals were engaged to investigate suspicious network activity and determined that certain systems within its computer network were accessed by an unauthorized third party between February 4, 2026, and February 12, 2026. The threat actor accessed or removed files that contained personal and/or protected health information. The data review was completed on or around July 2, 2026, when it was confirmed that the impacted data included names, dates of birth, medical information, health insurance information, financial account information, and other identification information. For certain individuals, the exposed data included...
Midwest Spine and Brain Institute Impacted by Vendor Ransomware Attack
Data breaches have been announced by Midwest Spine and Brain Institute, Brookhaven ENT Allergy and Facial Surgery, Digestive Disease Center and Heart Vascular & Leg Center, Premier Medical Group of the Hudson Valley, Risk Program Administrators, and Telus Health (US). Midwest Spine and Brain Institute (3C Care Systems) Midwest Spine and Brain Institute (MSBI), an independent medical clinic serving patients in Minnesota and Wisconsin, has alerted patients about a historic data breach at one of its service providers, the healthcare IT company 3C Care Systems. According to the MSBI notification letters, MSBI recently learned that patient data was accessed and/or obtained from 3C Care Systems. 3C Care Systems is a managed service provider that specializes in workflow automation, cloud-hosted platforms, and data integration services for healthcare organizations. 3C Care Systems conducted its own investigation into the data breach, and MSBI conducted an independent internal investigation. The MSBI investigation confirmed its larger network was not impacted, only data provided to 3C...



