Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Data Breach - SimonMed Confirms Cyberattack Exposed Data of 1.2M Patients
Data Breach Attacks Critical Infrastructure Security Latest News News & Analysis Security

SimonMed Confirms Cyberattack Exposed Data of 1.2M Patients

Kirsten DoyleBy Kirsten DoyleOctober 15, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
SimonMed Confirms Cyberattack
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

SimonMed Imaging, one of the largest outpatient medical imaging providers in the US, has confirmed that it fell victim to a cyberattack that potentially exposed sensitive patient information earlier this year. 

The company said it was first alerted on 27 January 2025, when one of its vendors reported a security incident. A day later, SimonMed detected suspicious activity within its own network, prompting what it describes as an immediate and comprehensive response. 

In a statement, the company said it “promptly began an investigation and took steps to contain the situation,” including resetting passwords, tightening multifactor authentication, enhancing endpoint monitoring, and blocking all non-whitelisted network traffic. Law enforcement and data security experts were also brought in to assist. 

The investigation determined that unauthorized access happened between 21 January and 5 February this year. During that period, attackers were able to reach systems containing patient data. 

A Wide Range of Identifiers 

The information potentially affected varies by individual but may include a wide range of identifiers and medical details: names, addresses, birth dates, service dates, provider names, medical records, imaging results, diagnoses, treatment details, medications, and health insurance information. 

For some, the exposure could extend to driver’s license or government ID numbers, Social Security or tax IDs, financial account details, authentication credentials, and biometric identifiers. 

SimonMed stressed that while this data was present in the affected systems, there is currently no evidence that any of it has been misused for fraud or identity theft. It began a thorough review to identify affected individuals and is notifying patients as that process continues. Relevant government agencies have been informed. 

“We take this incident and the security of the information in our care seriously,” the company said in its notice, adding that it had taken significant steps to contain and strengthen its environment and is continuing to work with cybersecurity professionals to ensure the integrity of its systems. 

The Culprits 

Damon Small, Board Member at Xcape, said that while the root cause of the breach is unknown, the available information shows that a third-party tool or service may have provided access to the network. 

“The incident affected more than 1.2 million patients. “The Medusa group, previously known for attacks on the Minneapolis Public Schools (MPS) system and Toyota Financial Services, claimed responsibility for the 212 GB data exfiltration, which leaked patient data, scans, other medical records, and financial information.”  

“SimonMed responded by immediately updating patient credentials and authentication methods, implementing endpoint detection and response capabilities, terminating third-party vendor access, and offering additional identity theft protection services free of charge to its clients,” Small added.  

“While the post-incident actions taken by SimonMed are appropriate, those are things that should’ve been in place from the start. This is a costly incident, especially when you consider potential HIPAA fines, ID Theft protection for 1.2 million patients, lawsuits, and increased cyber insurance premiums.”  

Guidance For Patients 

While the investigation is ongoing, SimonMed has advised patients to be vigilant against potential fraud. The company recommends that individuals regularly review their financial and health statements and monitor their credit reports for unauthorized activity. 

Under US law, consumers are entitled to one free credit report per year from each of the three major credit bureaus (Equifax, Experian, and TransUnion) available through AnnualCreditReport.com or by calling 1-877-322-8228. 

Patients who suspect suspicious activity can also consider placing a fraud alert or a security freeze on their credit files. A fraud alert requires creditors to verify identity before opening new accounts, while a freeze blocks access to a credit report without explicit consent. Both services are free. 

For additional protection, the company suggests that patients: 

  • Review their health insurance “explanation of benefits” statements carefully. 
  • Verify any unfamiliar medical claims or charges with their healthcare providers. 
  • Request a year-to-date summary of all services paid by their insurer to check for inconsistencies. 

Build Resilience 

Lydia Zhang, President & Co-Founder of Ridge Security Technology, comments:  “We have seen more and more healthcare organizations adopt continuous security posture testing as part of their defense strategy. Since advanced social engineering can bypass passwords and multi-factor authentication, organizations must build resilience into their internal systems by continuously reviewing policies, detecting threats, and patching critical vulnerabilities.”  

Hom Bahmanyar, Ridge Security Technology’s Global Enablement Officer, adds that adversary emulation is an important strategy for defending against the ongoing emergence of ransomware variants such as Medusa and Akira. “ AI attack simulation playbook libraries are equipped with the scripts to detect Medusa and Akira ransomware and it continues to get updated to detect new ransomware variants emerging in months ahead.”  

Bahmanyar says this incident highlights the need for robust vendor management policies and strict control of the resources that those tools are allowed to access. “A chain is only as strong as its weakest link; thoroughly vet your vendors, sandbox if appropriate, and review access controls often.”  

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories
  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

7-Eleven Notifies Franchise Applicants After Breach Exposes Personal Data

May 19, 20262 Mins Read

Canvas cyberattack disrupts universities as ShinyHunters threatens massive data leak

May 12, 20267 Mins Read

Zara Owner Inditex Confirms Customer Data Breach Affecting Nearly 200,000 People

May 11, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}