Skip to main content

The Money Overview

Mt. Baker Imaging will pay $3.3 million to patients exposed in a data breach

A data breach at Northwest Radiologists Inc., doing business as Mt. Baker Imaging, exposed Social Security numbers, financial account details, and health insurance records for 348,118 Washington state residents between January 20 and January 25, 2025. The company reported the incident to the Washington Attorney General on July 10, 2025, and filed a parallel breach notification with California’s Attorney General tied to the same January 20 start date. No primary source document or official statement confirms a $3.3 million settlement or payment to affected patients based on available filings.

Why the Mt. Baker Imaging breach filing matters right now

The scale of exposed data is severe. Categories of compromised information include Social Security numbers, driver’s license and Washington state ID numbers, financial and banking data, dates of birth, military ID numbers, and health insurance details, according to the Washington breach listing. That combination gives identity thieves nearly everything needed to open fraudulent accounts, file false tax returns, or exploit medical benefits in someone else’s name.

The timing of the filings raises questions about how quickly affected patients learned their data was at risk. The breach itself ran for five days in late January 2025, but the formal report to Washington’s Attorney General did not arrive until July 10, 2025, nearly six months later. California’s Attorney General received a separate notification sample listing the same breach date of Monday, January 20, 2025. The gap between the breach window and the state filings means hundreds of thousands of patients went months without official notice that their sensitive records had been compromised.

The staggered filings across two states suggest the company focused on meeting multi-state regulatory requirements rather than racing to get remedies into patients’ hands. Washington and California each have distinct breach notification laws with different reporting thresholds and timelines. Satisfying both frameworks simultaneously can slow the process, but it also limits the company’s exposure to enforcement actions from multiple attorneys general. For patients, that compliance-first approach translates into delayed awareness and delayed access to protective steps like credit freezes or fraud alerts.

What official records show about the breach scope

Washington’s Attorney General office lists the breach under “Northwest Radiologists, Inc./Mount Baker Imaging” with a breach period running from January 20 through January 25, 2025, and a total of 348,118 affected Washingtonians. The California breach report confirms the organization submitted a data breach notification sample and lists the breach date as January 20, 2025. Both filings identify the same entity and the same incident, confirming the breach crossed state lines and affected residents beyond Washington.

Neither state filing includes details about the cause of the breach, whether it involved ransomware, unauthorized network access, or another attack vector. No direct statements from Mt. Baker Imaging or from regulators describing remediation steps, credit monitoring offers, or patient remedies appear in the cited filings. The California filing links to a notification sample document, but the underlying content of that notice and any settlement terms have not been disclosed in the public record reviewed for this report.

The absence of a confirmed $3.3 million payment in any primary source is a significant gap. While the headline figure has circulated in secondary discussions, no filing from either attorney general’s office, no court record, and no company statement available through official channels corroborates that amount as a paid settlement or fund for victims. Without a verifiable document, treating the $3.3 million claim as established fact would mislead patients who may already be struggling to understand what help, if any, they can expect.

Public accountability in this kind of incident depends on transparent, accessible records. State-level breach portals, including California’s broader OpenJustice resources, are designed to give residents insight into how often their data is compromised and how organizations respond. In the Mt. Baker Imaging case, those records confirm the scope and timing of the breach but stop short of detailing restitution, security upgrades, or regulatory penalties. That leaves a critical part of the story unresolved: what concrete consequences, if any, the company faces for exposing hundreds of thousands of highly sensitive records.

What patients can realistically do next

For affected patients, the lack of clarity around settlements does not change the immediate risk. With Social Security numbers, financial data, and insurance information potentially in circulation, the most practical steps remain defensive. Patients should consider placing fraud alerts or credit freezes with major credit bureaus, monitoring bank and credit card statements for unauthorized activity, and reviewing insurance explanations of benefits for unfamiliar charges. If Mt. Baker Imaging or regulators later confirm that free credit monitoring or identity theft protection is available, those services can supplement, but not replace, basic vigilance.

Patients who believe they were affected can also request in writing that Mt. Baker Imaging disclose what information the company holds on them and what was involved in the breach, referencing the dates and incident described in the state filings. While healthcare privacy laws limit some disclosures, organizations often provide at least a general description of compromised data categories for individual records. Keeping copies of any notices, along with dates and details of communications, may help if future legal or regulatory actions create avenues for restitution.

Ultimately, the Mt. Baker Imaging breach underscores how much power organizations wield over deeply personal data and how slowly official processes can move even when that data is exposed. Until regulators or the company release fuller documentation, the safest assumption for patients is to treat the incident as a serious, long-term identity risk and to act accordingly, rather than waiting for a settlement headline to translate into concrete protections.

Avatar photo

Daniel Harper

Daniel is a finance writer covering personal finance topics including budgeting, credit, and beginner investing. He began his career contributing to his Substack, where he covered consumer finance trends and practical money topics for everyday readers. Since then, he has written for a range of personal finance blogs and fintech platforms, focusing on clear, straightforward content that helps readers make more informed financial decisions.​


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.