In February 2025, Pinehurst Radiology Associates, in Pinehurst, North Carolina, experienced a cyberattack that wwas discovered on January 20, 2025. As a result, certain systems were taken offline, and the practice was forced to close its doors "for the foreseeable future," unable to schedule patients for mammography or ultrasound services.
The breach exposed a wide range of sensitive information belonging to patients. The compromised data included both personally identifiable information (PII) and protected health information (PHI): name, address, date of birth, medical diagnosis and treatment information, medical record number, health insurance information, Medicare/Medicaid number, and Social Security numbers.
The breach was formally disclosed to the Massachusetts Attorney General’s office on May 22, 2025.
The incident’s severity is underscored by the fact that it forced the practice to shut down operations, indicating a substantial impact on both the company’s infrastructure and its patients. The company is working with federal, state, and local law enforcement agencies to address the breach. For more details and updates, affected individuals can visit the notice of data event posted on the Pinehurst Radiology Associates website.
In response to the cyberattack, Pinehurst Radiology Associates took immediate action to contain the incident. The practice engaged legal and cybersecurity experts to investigate the breach and is cooperating with law enforcement at multiple levels. While the practice’s own systems remain offline, their partner hospital, FirstHealth, was not impacted and has expanded its hours and appointment slots to accommodate displaced patients.
If you believe you may be affected by this breach, it is important to remain vigilant. Consider taking the following steps:
For more information about the company, visit the Pinehurst Radiology Associates website.