A ransomware group says it stole 655 gigabytes of data from a radiology practice that serves more than 50 clinics in Washington and Idaho. Weeks later, Radia, Inc., P.S. still hasn’t confirmed a breach happened at all.
On July 16, 2026, the ransomware group Chaos posted Radia to its dark web leak site, claiming it had gained full access to the internal network and data infrastructure behind radiax.com and had already published an initial sample, roughly 5%, of the data it says it took, according to a July 16, 2026 incident report from cybersecurity monitoring platform DeXpose.
As of the most recent public reporting, in early August 2026, Radia had not confirmed that any breach occurred and had not issued its own notice describing what happened. Because Radia hasn’t spoken publicly, none of the details below, including the exact data taken and how many people are affected, come from the company itself. They come from the ransomware group’s own claim and outside reporting on it.
Washington Law Gives Companies 30 Days to Report but Radia Hasn’t Said a Word
Washington’s data breach law requires an organization to notify the state Attorney General’s Office within 30 days of discovering a breach that affects 500 or more Washington residents. Radia serves patients across more than 50 clinics in Washington and Idaho, so a breach of the size Chaos is claiming would likely clear that threshold. More than three weeks passed between the ransomware group’s claim and the most recent public reporting on this incident, with no confirmed notice from Radia to patients, employees, or regulators.
Ransomware groups have an incentive to exaggerate what they’ve taken to pressure a victim into paying, so Chaos’s claim alone isn’t proof the data was actually stolen. But it does mean that, right now, patients and employees connected to Radia have no official source of information about whether their own records were involved.
What Information May Have Been Exposed?
The data categories reported in connection with this incident include:
- Full names
- Social Security numbers
- Medical record numbers
- Account numbers
- Patient history questionnaires
- Diagnostic imaging reports
- Full medical billing records
- Dates of birth
- Home addresses
- Sex
- Email addresses
- Home phone numbers
- Corporate financial records
- Legal documents
- Human resources and employee records
This list reflects the categories reported in connection with the incident, not a confirmed notice from Radia.
How Many People Are Affected?
Radia has not disclosed a number. Chaos’s claim of 655 gigabytes of stolen data doesn’t translate directly into a count of affected individuals, and no state attorney general filing from Radia has been identified as of this writing.
What Is Radia Offering Affected Individuals?
Nothing has been disclosed yet. Because Radia hasn’t confirmed the breach, there is no credit monitoring offer, enrollment code, or deadline to report. Anyone who later receives a formal notice from Radia should follow the instructions in that letter and keep a copy for their records.
Your Information Is at Risk
The data categories connected to this incident combine medical and financial information with the kind of identifiers, Social Security numbers, dates of birth, home addresses, that make identity theft easier to carry out. Medical record numbers and diagnostic imaging reports can also be used for medical identity theft, where someone uses another person’s identity to obtain care or prescriptions and corrupts the victim’s own medical records in the process. Employees whose human resources and payroll information may have been exposed face a separate risk of tax fraud and employment-related identity theft. If you’re a current or former Radia patient or employee, watch for unfamiliar activity on financial accounts or insurance statements, pull a free credit report, and be cautious of unexpected calls, texts, or emails that reference Radia or a medical appointment.
Do You Have Legal Options?
Medical groups that collect Social Security numbers, medical records, and financial information have a legal duty to secure that data and to notify affected individuals without unreasonable delay.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you believe your information was involved in the Radia data breach.
FAQ
Who is affected by the Radia data breach?
Current and former patients and employees of Radia, Inc., P.S. and its affiliated clinics across Washington and Idaho, if the ransomware group’s claim is accurate. Radia has not confirmed the breach or disclosed who was affected.
What information was exposed?
Reported categories include full names, Social Security numbers, medical record numbers, account numbers, patient history questionnaires, diagnostic imaging reports, medical billing records, dates of birth, addresses, sex, email addresses, phone numbers, corporate financial records, legal documents, and employee records. This comes from public reporting on the ransomware group’s claim, not a confirmed notice from Radia.
Why hasn’t Radia notified patients and employees yet?
Radia has not explained any delay because it has not confirmed the incident at all. Washington law generally requires notice to the state Attorney General within 30 days of discovering a breach affecting 500 or more residents, but no such notice from Radia has been identified as of this writing.
Is Radia offering credit monitoring?
Not that has been disclosed. Because Radia hasn’t confirmed the breach, there is no announced credit monitoring service, enrollment code, or deadline.
My child was a patient at a Radia-affiliated clinic. Should I be concerned?
It’s worth paying attention. A minor’s Social Security number and date of birth are especially valuable to identity thieves because the fraud can go undetected for years, often until the child applies for credit as an adult.
Do I have a legal claim?
You may. Medical groups that collect Social Security numbers, medical records, and financial information have a legal duty to secure that data and to notify affected individuals without unreasonable delay. If you’re a current or former Radia patient or employee, or you receive a Notice of Data Breach letter from Radia, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.