Lumexa Imaging Data Breach: What the Court Record Actually Shows
Three federal lawsuits are now consolidated in North Carolina, and the published victim counts contradict each other. Here is what the notice letter confirms, what nobody has confirmed, and why there is nothing to file yet.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened
Lumexa Imaging, Inc. provides administrative services to affiliated radiology practices and imaging centers. An outside vendor Lumexa used for non-clinical business support was compromised, and patient documents were taken from that vendor's environment between March 31 and April 9, 2026. The vendor told Lumexa on April 9 and Lumexa disconnected from the vendor's network; on April 15 it confirmed patient documents were involved. The vendor has never been publicly named. Note what is NOT alleged: no source describes imaging files themselves — MRI, CT or other scans — being taken. The records at issue came from an administrative system, not the image archive.
Case Details
Three putative class actions were filed on May 19, 2026 in the U.S. District Court for the Eastern District of North Carolina (Nos. 5:26-cv-00339, 5:26-cv-00340 and 5:26-cv-00341) against Lumexa Imaging, Inc. They have since been consolidated into a single proceeding — confirmed both by Law360 reporting of July 21, 2026 and by the parent company's own quarterly report to the SEC. This is an in-district consolidation, not a JPML multidistrict litigation. Reported plaintiff surnames are Lawrence, Ellison and Moreno, but published sources disagree on which name belongs to which case number, so we do not assign them.
Where the Case Stands Today
Who Was Affected
Patients of radiology practices and imaging centers served by Lumexa Imaging. The company's notice letter lists name, date of birth, address, phone number, patient account number, health insurance information and clinical information such as visit dates and diagnoses. Social Security numbers were involved for only a limited subset of people — and it is that subset, not everyone, that was offered free Kroll credit monitoring. The victim count is genuinely unsettled and we will not pretend otherwise: the federal HHS breach portal has been reported at 2,994 people, while state attorney general filings add up to more than that on their own (Washington 3,632, Massachusetts 825, Texas 251, Nebraska 157, Vermont 98). Those numbers cannot all describe the same final total. The notice letter itself says Lumexa anticipated notifying additional individuals, so the early figures were expressly not final. Treat any single headline number with caution.
What a Case Like This Pays
Timeline
- 1
March 31 to April 9, 2026 — unauthorized access
An outside vendor Lumexa used for non-clinical business support is accessed without authorization. Patient documents are taken during this window.
- 2
April 9, 2026 — vendor notifies Lumexa
The vendor reports suspicious activity in its environment. Lumexa disconnects its systems from the vendor's network the same day.
- 3
April 15, 2026 — patient documents confirmed
Lumexa confirms that documents containing patient information were involved and begins reviewing what was affected.
- 4
May 15, 2026 — notice filed and letters mailed
Lumexa files its breach notification with the California Attorney General and begins mailing notice letters. Washington residents are reported to have been notified on June 12, and letters reached residents of additional states, including Montana, in the following weeks.
- 5
May 19, 2026 — three lawsuits filed
Three putative class actions are filed the same day in the Eastern District of North Carolina against Lumexa Imaging, Inc.
- 6
By July 21, 2026 — cases consolidated
The three cases are consolidated into a single proceeding. The company confirms the consolidation in its own quarterly filing with the SEC. No settlement has been reached.
How to Spot a Fake Lumexa Claim Site
There is no claims process for this breach. That single fact is the most reliable test you have — anything offering you one is either mistaken or trying to harvest your data.
Any site with a Lumexa claim form or filing deadline
No settlement exists, so no legitimate claim form or deadline can exist either. A countdown clock on a Lumexa claim page is a red flag by itself.
Calls or texts asking you to verify your Social Security number
Lumexa's notice letters went out by mail. The company's stated contact route is its dedicated line, (844) 959-7072, open Monday to Friday, 8:00 a.m. to 5:30 p.m. Central. Nobody legitimate will cold-call you for your full SSN over the phone.
Lookalike web addresses
Search results contain unrelated businesses with similar names. Lumexa's own site is lumexaimaging.com; the company behind it is Lumexa Imaging Holdings, Inc., based in Raleigh, North Carolina. Check the address bar before entering anything.
Frequently Asked Questions
Can I file a claim right now?
No. There is no settlement, no claims administrator and no claim form. The consolidated lawsuit is still in an early stage, and it may be a long time before there is anything to file — or there may never be.
How many people were actually affected?
Nobody has published a reliable final number. The federal HHS breach portal has been reported at 2,994, but individual state filings already exceed that on their own. Lumexa's own letter said it expected to notify more people later, so the early counts were not final. We would rather show you the contradiction than invent a clean figure.
Were my MRI or CT scans stolen?
Nothing in the notice letter or the reporting says imaging files were taken. What was described is administrative and clinical record data — names, dates of birth, contact details, account numbers, insurance information, visit dates and diagnoses.
I got a letter offering credit monitoring. Do I have to accept it?
Accepting free monitoring does not waive your right to join a class action. The Kroll offer went to the smaller group whose Social Security numbers were involved. Important: the activation deadline and the length of coverage were printed individually on each letter, so there is no single public date — check your own letter rather than a date you read online.
Do I need a lawyer?
Class actions do not require you to hire anyone; if a class is certified and later settles, affected people are typically notified. Several firms are publicly investigating and recruiting clients. If you have suffered actual identity theft or financial loss traceable to this breach, that is the situation where individual legal advice is worth getting.
Which company is actually being sued?
The defendant is Lumexa Imaging, Inc., the operating entity that provides administrative services to affiliated radiology practices. Its parent, Lumexa Imaging Holdings, Inc., is publicly traded as LMRI. The vendor whose systems were actually breached has not been publicly identified in any source we could find.
What should I do in the meantime?
Read your notice letter and note whether it says your Social Security number was involved, since that determines whether the monitoring offer applies to you. Placing a free credit freeze with the three bureaus is worth doing regardless. Keep the letter — if a settlement ever happens, it is the cleanest proof that you are in the class.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.