
Radia Inc., P.S., one of the largest physician-owned radiology groups in the United States, has been claimed as the victim of a ransomware attack.
On July 16, 2026, a ransomware group called CHAOS posted a claim on Tor, a dark web network often used by cybercriminal organizations to publish stolen data. The group stated that it had carried out a ransomware attack on Radia Inc., P.S. and obtained 655 gigabytes of the organization's data.
The posting described a range of compromised files spanning patient records, corporate documents and employee information.
According to the dark web posting, the compromised data includes both personally identifiable information (PII) and protected health information (PHI). The claimed patient and clinical data includes patient full names, Social Security numbers, medical record numbers, dates of birth, account numbers, patient history questionnaires, diagnostic imaging reports and full medical billing records.
The group also claimed to have obtained database exports containing full PII records. These exports reportedly include patient names, dates of birth, addresses, sex, email addresses and home phone numbers.
Corporate financial records were also reportedly part of the stolen data. According to the posting, these include accounts receivable and payable records, business and occupation tax information, banking records, 1099 forms, budgets, CPA documents and fixed asset ledgers.
Legal documents were listed among the compromised files as well. The group claimed to have obtained high-level agreements, data access agreements, nondisclosure agreements, notary documents, W-9 forms and due diligence transaction reports.
Finally, the CHAOS group claimed to have obtained human resources and employee records. These reportedly include highly sensitive personal files such as Social Security numbers, dates of birth, addresses, 401(k) details, benefits information, I-9 forms, records related to the Family and Medical Leave Act and the Americans with Disabilities Act, and data from the ADP payroll system.
If the claims made by the CHAOS group are accurate, the breach would affect both patients and employees across the organization's broad network of hospital partnerships and imaging centers. The breadth of data described by the threat actor spans clinical records, financial documents, legal files and human resources information, making this a potentially wide-reaching incident for the western Washington health care community.
As of Aug. 1, 2026, no filings with state attorneys general or federal agencies have been identified in connection with this incident.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)