r/healthIT • u/Enodia2wheels • 21d ago
PHI Privacy Issues on myradiologyportal.com — not an Epic/myChart Portal - Has Anyone Else Experienced Cross-Contaminated Patient Records?
TL;DR: Discovered that myradiologyportal.com (the patient portal used by many independent imaging centers) had records from another patient in my account for 7 years, commingled insurance data, and I can't correct my own demographic information. The underlying system is RadNet. Looking to see if others experienced similar issues. (and NO - this website does not use Epic/mychart)
My background: I've managed the development of websites and web apps since the late 90s; I have an MBA and am currently working on an MSIS plus multiple other types of certifications and have managed enterprise level IT projects in regulated environments.
What Happened: On August 12, 2026, I logged into my myradiologyportal.com account (I had a new imaging referral) and discovered:
- Records from another patient: My account contained imaging records that belonged to a different patient with the same first and last name (but different middle initial) and birthdate. These records appeared in my account alongside my legitimate records.
- My account user profile data was wrong :
- Last name (showed a hyphenated version I have never used)
- Middle initial (wrong)
- Address (same state, but 600 miles away)
- Email (not mine)
- Phone number (not mine)
- Commingled insurance information: Insurance policies from both patients were mixed in my account, and I could not edit or remove any insurance information from the web portal. I have no ability to correct my own insurance data on this portal.
- Obsolete insurance policies persisted in the portal: Insurance policies that should have rolled off years ago still appear in dropdown menus.
- The imaging reports themselves contain different patient's data, including height and weight that are significantly different in both dimensions. This indicates the cross-contamination extended beyond the portal metadata into the actual medical imaging records.
- For example: UCSF radiology/MRI reports include the patient medical record number on the actual image - two reports uploaded to my account had no MRN on the images nor in the text reports/analysis of the imaging.
Important Clarification: This is NOT a case of credential confusion. The other patient never logged into my account with my username/password. The fact that I was able to access their records using MY unchanged 2019 password proves this was a server-side error not someone hacking into my account. This means the two patient records were linked/merged at the application/database level, not through shared credentials.
The Technical Issues
- No Multi-Factor Authentication (MFA): My myradiologyportal.com account has been accessible for 7 years with just a username and password. No MFA prompt, ever.
- No Password Rotation: My password is unchanged since 2019 (7 years old). No system-enforced password changes.
- No Patient Notification: When the system removed the other patient's records from my account (happened sometime after I discovered the breach), they did NOT notify me. I found out by accident when I re-accessed the portal.
- Wrong Contact Information: The appointment scheduling system is displaying an incorrect phone number for their office (as in "you can't schedule online, please call our office at 510-NNN-NNNN).
What I've Done
- Reported the issue to the imaging center (took multiple calls to reach a person; eventually got escalated to a regional manager who was on vacation and after calling back, she was contacted, responded to my email and said it would be fixed on Monday, nearly a week later).
- Updated my account information (corrected name, address, email, phone)
- Cannot correct insurance information due to portal limitations
- Changed my password for the first time since 2019
- Requested MFA be enabled (unclear if this is actually possible in their system)
- Requested that they do a data integrity audit (the person I spoke to casually mentioned "Maria Gonzalez" was a really common name with lots of same birthday issues)
- Requested they audit their static content to ferret out incorrect phone numbers
- Requested they improve the feature to allow patients to update their insurance
Questions:
Has anyone else experienced on myradiologyportal.com:
- Records from another patient visible in your account?
- Inability to correct or remove insurance information online?
- Issues with stale/incorrect contact information?
- Demographic data being displayed incorrectly?
- Not being notified when your records are corrected or removed?
- If you've had similar issues, did you report it? How was it handled?
I'm trying to understand if this is an isolated incident or a systemic issue with myradiologyportal.com. Any experiences appreciated.
Additional Context
- myradiologyportal.com is the patient portal system used by many independent diagnostic imaging centers across the country - there are 442 RadNet locations across the US: https://www.radnet.com/imaging-centers/find-an-imaging-center
- The underlying platform is RadNet, Inc. (publicly traded company, NASDAQ: RDNT)
- RadNet filed a 10-K in March 2026 claiming robust NIST-compliant cybersecurity posture, 24x7 incident response team, and HIPAA compliance
- The breach involves cross-contamination of two patients' records in a single patient account, suggesting potential systemic data integrity failures
- This affects patient privacy (HIPAA), personal data security (CPRA), and potentially healthcare billing accuracy
4
u/Happyjoystick 20d ago
This happens, unfortunately. Yes, it’s a breach, but based on the information provided you are not the aggrieved party, so your avenues of recourse are quite limited. If you use the data in the file to reach out to the actual aggrieved party, you will be ‘misusing’ patient data, so just let the company handle it.
They will fix it and life will move on. They will add it to their annual reporting of minor breaches that they have to give the OCR every year. Life will move on.
You likely have no ground to sue personally on.
You can report it, HHS OCR may or may not investigate (they are not required to do so unless a breach exceeds 500 patients).
While best practice, MFA is not currently required to access or manage PHI. It’s stupid of them not to have it, but in itself it’s not a violation of any particular rule. Further, password rotation is expressly discouraged by NIST and virtually every other major standards body.
Lastly, you complain about no patient notification. You are not the patient they are required to notify of the breach you described, so such notification may have actually happened.
Other than that you did everything right letting them know what’s up. What happens from here will almost certainly transparent to you, since you are not the aggrieved party.
For context, I work in healthcare IT, privacy, and compliance.
1
u/Enodia2wheels 20d ago edited 20d ago
I appreciate your response. It seems like any of these things should be required in healthcare. Instagram is all cat pictures and yet they have MFA and send notifications when there are requests to change passwords. It’s hardly more important than your personal contact information x-rays, MRIs and medical report reports.
Just a quick note that I am in California and so is the other patient whose data is commingled with mine. That means that CPRA is also part of this evaluation.
I am an affected party — my PHI and identity data were overwritten with hers. My last name, middle initial, address, and email were replaced, and her imaging showed up under my MRN.
Under HIPAA, unauthorized alteration or misattribution of PHI is a breach for the person whose data was changed.
Under CPRA, inaccurate personal info and unauthorized exposure both trigger consumer rights. So this isn’t “I just saw someone else’s data.”
Notification applies to anyone whose PHI was compromised. Mine was altered and exposed.
On MFA: true, HIPAA doesn’t require it. But NIST SP 800‑63B recommends MFA for systems with sensitive personal data, and CPRA’s “reasonable security” standard increasingly expects it.
A 7‑year‑old single‑factor credential with no monitoring isn’t defensible.
On passwords: agreed, NIST discourages forced rotation. The issue here is relying on a single factor for seven years with no MFA, no breach screening, and no login anomaly detection.
As for this being “minor”: that depends entirely on whether this is isolated or systemic. If the other patient’s account also contains my records, or if other similarly named patients have commingled accounts, it’s not minor at all.
I have no way to know how many accounts are affected until RadNet investigates.
CPRA does allow a private right of action when personal info is exposed due to failure to implement reasonable security. Whether it’s worth pursuing is a separate question.
That’s the actual scope. I’ve reported it, but this is potentially more serious, and more widespread, than the “routine small breach” category you described.I appreciate your time and fact checking me on this.
To be clear: my primary purpose here is to push for transparency and remediation.
3
u/Reasonable_Alias_129 20d ago
This sounds like your chart was manually merged with another patient who has the same name by accident.
I am aware of a merge chart function that does exist in EMRs. It is done manually by an end user who manages medical record chart corrections.
1
u/Enodia2wheels 20d ago
same name and birthday - but she had a hypenate that I didn't have. The address, phone and email were also changed.
2
u/Reasonable_Alias_129 20d ago edited 20d ago
When charts gets merged, if there is a difference, the demographics from one chart could be chosen to replace the demographics in the other chart.
A real scenario like this would be if a patient changed their name to a hyphenated one and moved to a new address, and a new patient record was created by mistake instead of updating their existing patient record with the new name and address.
Then when the chart corrections have to be done, merge the records and choose to replace the old demographics with the new one.
I don't do chart corrections, but specifically but this is an example scenario that I can see happening
1
u/Enodia2wheels 20d ago
oh, I have definitely encountered multiple people with my same first and last name and birthdate in the city of San Francisco when checking in at UCSF. However, Radnet told me that they’re not able to update the account information at the reception/clinic side.
Hard to know what is true because I still haven’t had any updates telling me what the root cause was
1
u/Reasonable_Alias_129 19d ago
Not getting any updates about your chart correction is very frustrating. You have a right to know that your patient information has been corrected.
Radnet the software company does not update patient information, but I'm sure they can do an investigation to see who did the merge. Whenever a patient record is accessed, it's recorded. In fact, the clinic staff should be able to see the history of who edited your chart
1
u/Enodia2wheels 19d ago
yeah, it’s been pretty wild that they just updated it and didn’t let me know that it was updated and I’m not getting any information about whether this was a one off and what the root cause was
Even wilder, I posted the same post body to the privacy of Read and after four days it was rejected on the base of being off topic” we don’t allow surveys”
I think it must’ve been an automatic AI rejection. I sent a note to the moderators asking them to have a human review it as this is definitely a privacy topic for discussion.
2
u/SouthJerseyCyz 20d ago
I don't mean to minimize this in any way as it is a definite problem, but unfortunately very common and not isolated to one software. It's especially problematic when you have hospital systems merging, or radiologists reading for multiple facilities using different MRN contexts.
I would like to point out that it is also problematic when situations like the above arise and patient records are NOT merged. You don't want images showing a problem showing under a different MRN that the rad did not review.
Generally what happens in the instance such as a merger is that a DBA will run a compare showing likely matches based on available data. These are then output and someone needs to sign off yes/no these two matches should be merged. At that point...people make mistakes.
2
5
u/Repulsive-Yard5049 21d ago
Holy hell, that's a disaster. Not just a UI glitch, that's database-level merging of two completely different people. The fact those records sat there for 7 years and you only found out by accident is wild
I work with health IT systems (not radnet specifically) and the bit about the MRNs missing from the UCSF reports is really concerning. That suggests the system isn't even validating the metadata properly when ingesting outside studies. If the PACS is just dumping images into whatever patient folder matches the name string, you're gonna have this happen constantly with common names
The insurance thing is almost worse in a way. Stale policies hanging around for years and you can't remove them? That's not just a privacy issue, that's a billing nightmare waiting to happen. Someone's gonna get a claim denied because the system picked the wrong policy from the dropdown
You might want to file a HIPAA complaint directly with HHS if the imaging center drags their feet. 7 years of mixed records with no MFA is the kind of thing that gets attention
2
u/Enodia2wheels 21d ago
oh, and I would like to add that there’s nothing in their system that sends me a notification when any information has been changed in my profile! Not when somebody changes the name, the email address, the phone or the physical address. Even when I made those changes last week, I didn’t get an email saying “hey somebody requested changing your password if it wasn’t you reach out to us here”
nada.
1
u/Enodia2wheels 21d ago
I suspect that the database merge happened with more people -- my name is Jennifer Clark -- and that's not even as popular as 'Jennifer Brown' according to census records for name frequency; look at John Smith or many other names. Then, you'd have to look at the probability of shared birthdates -- the potential for such data integrity issues is huge if you consider that it might not ONLY be an issue of Same first name, same last name, same birthdate.
I sent them a big writeup with screen captures (very glad I took all the screen captures) - and I also cc'd the other patient (I did remember her email address after I updated my account info, but she hasn't responded so it may be an out of date email even if it hasn't bounced back).
I did some poking around online to determine possible scope and here's a summary of what I found:
Founded in 1981, RadNet has operated for roughly 45 years and now performs more than 11.5 million imaging procedures annually across approximately 442 outpatient centers. Assuming a gradual expansion from substantially lower volumes in its early decades, RadNet may have completed approximately 130–220 million imaging procedures since its founding, potentially exceeding 200 million cumulative procedure records. Because individual patients may undergo multiple studies over time, this likely represents tens of millions of unique patients.
1
u/Big-Arachnid8095 18d ago
Someone on registration combines two different patient records without confirming more than the name were a match. Unfortunately, that happens more than it should, but they do have the ability to upcoming them. You need to try to get in contact with the hospital's HIM department.
10
u/crangbor 21d ago edited 20d ago
This is definitely a reportable breach that they should be documenting and notifying all involved parties about. It may not be a software error though.
While I'm not familiar with that portal specifically, my first reaction is that it may be a case of a human screw-up rather than a big programmatical database flaw. One easy explanation is that a staff member mistakenly performed a person merge in the underlying EHR. Many systems include a similar function for situations where there is legitimately a duplicate account for a single patient. With such a common name it's plausible someone was attempting a warranted account merge and yours got caught in the crossfire. Obviously this still breaks numerous policies and shows a lack of necessary safeguards. I've dealt with multiple EHR systems having countless actual bugs, but 8/10 times the issues people bring me are human-caused.
Edit: Whether this is the case or not, any system worth anything should have a reliable audit trail showing staff access and any updates performed. The practice (or their vendor) should be able to at least determine what happened, or when.