Pinehurst Radiology Associates closed indefinitely after cyberattack

Organization
Pinehurst Radiology Associates, PLLC
Exploit
Hacking
Industry
Healthcare

Pinehurst Radiology Associates, an independent imaging practice serving the Sandhills region of North Carolina, detected suspicious activity on its network around January 20, 2025. The intrusion took core systems offline and the practice shut its doors, telling patients through a recorded phone message that it would remain closed for the foreseeable future.

With scheduling systems unavailable, the practice could not book mammography or ultrasound appointments. Patients due for PET and MRI scans were redirected to an affiliated imaging provider. Pinehurst Radiology engaged outside legal counsel and cybersecurity specialists and notified law enforcement. It was still closed more than a month after the attack, and no ransomware group publicly claimed responsibility.

The forensic review of the affected systems concluded on April 7, 2025. Pinehurst Radiology announced the resulting data breach on May 22, 2025 and began mailing notification letters to affected individuals.

The practice said the exposed information could include names, addresses, dates of birth, medical record numbers, medical diagnosis and treatment details, health insurance information, Medicare and Medicaid numbers, and, in a limited number of cases, Social Security numbers. It offered 24 months of complimentary credit monitoring. Pinehurst Radiology did not publish a total count of the people notified at the time, and the incident had not appeared on the federal breach portal as of the spring reporting. The breach was later recorded as affecting 8,682 individuals.

Sources