Key Takeaways
- Women’s Center for Radiology disclosed a data breach tied to legacy systems predating its acquisition by Solis Mammography.
- The incident highlights persistent cybersecurity gaps in imaging environments during M&A transitions.
- Regulatory expectations shaped by HHS and NIST guidance continue to influence how radiology groups respond to breaches.
The disclosure from the Women’s Center for Radiology (WCR) arrived as healthcare organizations navigate a dense threat landscape and a steady pace of acquisitions. The Orlando-based group, which was acquired by Solis Mammography in January, confirmed that an unauthorized user accessed portions of its legacy IT environment in late April. That environment remained active during the transition but was not fully migrated into Solis systems.
On April 29, the practice detected suspicious activity affecting its network. WCR contained the issue and engaged a cybersecurity firm to investigate the scope of the matter. Solis emphasized to Radiology Business that the IT outage only impacted legacy systems used by the Women’s Center for Radiology, reiterating that no Solis Mammography centers were affected.
Imaging environments draw threat actors due to data richness and interconnected systems that can be challenging to modernize. Guidance from the U.S. Department of Health and Human Services (HHS) warns of persistent risk across picture archiving and communication systems (PACS). In 2021, HHS reported that vulnerabilities in these systems left more than 275 million medical images exposed across 130 health systems, with breach reports consistently showing the sector trending toward more frequent hacking incidents.
According to the Women’s Center for Radiology, certain files were accessed without authorization. The information potentially viewed included names, dates of birth, contact details, health insurance data, and driver’s license numbers. These elements fall squarely within the protected health information categories set by the HIPAA Security Rule. The group notified federal law enforcement and regulatory authorities, aligning with breach response expectations from the Office for Civil Rights.
Historical analysis from HHS shows that imaging-related breaches from 2010 to 2020 exposed approximately 4.83 million patient records. Industry news has profiled several radiology groups navigating similar incidents, including US Radiology Specialists, which agreed to pay $450,000 and overhaul its security program after a ransomware-related breach affecting 198,260 patients in 2023. Radiology Associates of Richmond has also navigated significant data incidents, signaling that imaging enterprises face a sustained cybersecurity challenge in environments with aging infrastructure.
The Women’s Center for Radiology noted it is evaluating its internal processes to prevent repeat incidents. This mirrors recommendations from the HIPAA Security Rule as well as frameworks issued by the National Institute of Standards and Technology. NIST’s cybersecurity guidance for healthcare emphasizes asset visibility, access control, continuous monitoring, and structured incident response. The publicly available NIST materials give organizations a roadmap, although applying these frameworks to legacy imaging systems requires careful integration.
The Healthcare Information and Management Systems Society (HIMSS) has repeatedly noted that medical imaging devices and PACS environments often retain long lifecycles, which can outlast manufacturer support. That creates a situation where incremental security patches might not address deeper architectural vulnerabilities. HIMSS points out that healthcare acquisitions, particularly those involving older on-premises systems, introduce integration risk that acquirers sometimes underestimate.
Deloitte’s healthcare and life sciences analysis examines cybersecurity concerns in M&A integration, suggesting that organizations sometimes focus on clinical and financial blending while underinvesting in pre-acquisition cybersecurity due diligence. Radiology groups, with highly specialized IT stacks, are especially vulnerable during these stages. With consolidation accelerating in large outpatient specialties, gaps in transitional infrastructure create entry points for attackers.
The Women’s Center for Radiology is offering credit monitoring and identity protection to affected patients. Those steps align with common breach response practices and with recommendations from consumer protection regulators. The group also encouraged individuals to review statements and watch for suspicious activity to help prevent financial fallout.
Radiology practices operate within environments that need high availability. A disruption can affect scheduling, image access, report turnaround, and care coordination. While WCR kept systems functioning, unauthorized network access introduces operational risks to patient safety. Regulators, including HHS, have become increasingly vocal about treating cybersecurity as a clinical safety issue rather than simply an IT concern.
WCR is a longstanding private practice founded by Susan L. Curry, serving central Florida for more than 36 years. Solis Mammography, headquartered in Addison, Texas, has more than 150 locations and private equity backing. That structure places the combined enterprise within the ongoing consolidation of diagnostic imaging services. Integration of legacy systems is almost unavoidable, but the incident highlights why acquirers frequently need to revisit timelines and protocols for phasing out inherited infrastructure.
HHS reporting trends, analyst commentary, and high-profile enforcement cases indicate that healthcare organizations with distributed imaging assets encounter distinct security pressures. As radiology continues to integrate across networks, expectations around network segmentation, access governance, and continuous monitoring will likely become stricter.
The incident at the Women’s Center for Radiology illustrates the operational dependencies between M&A strategy, clinical care, and legacy IT security. Imaging environments require sustained cybersecurity investment, particularly during transition periods when legacy systems remain active and threat actors actively look for transitional vulnerabilities.
⬇️