Breach taxonomy
Summary
The Oncology Institute disclosed under Item 1.05 that a cybersecurity incident at a software service provider (first voluntarily disclosed November 6, 2025) affected company information systems including patient data. On May 20, 2026, Kroll, the vendor's third-party administrator, notified the company that the vendor detected unauthorized third-party access to systems affecting patient data. The incident affected various other healthcare providers; operations continued in all material respects and credit monitoring is being offered.
Tagging rationale
ThreatUnknown
Filing does not attribute the incident to a specific actor -> UNKNOWN.
MethodsData ExfilSupply Chain
Incident originated at a software service provider (vendor) used by the company and affected patient data across multiple healthcare providers -> DATA-EXFIL + SUPPLY-CHAIN.
AssetsPersonal Data
Vendor 'detected unauthorized access by a third party to certain information systems of the Company, including systems affecting data of patients' -> PERSONAL-DATA.
EffectsInfo Privacy Loss
Patient healthcare/personal information was compromised while 'operations have continued in all material respects' -> INFO-PRIVACY-LOSS.
Business continuityEffective
Filing cites the company's 'technology security and continuity plan' and states 'its operations have continued in all material respects since the detection of the incident' -> Effective.
Impact
Patient data compromised via vendor at multiple healthcare providers, but no operational disruption for the company -> score 2.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 1.05 Material Cybersecurity Incidents. The Oncology Institute, Inc. (the "Company") is providing this disclosure, as a follow-up to its voluntary disclosure in Item 7.01 of a Current Report on Form 8-K filed on November 6, 2025, regarding a cybersecurity incident affecting a software service provider ("Vendor") utilized by the Company. At the time of the prior voluntary disclosure, the Vendor had indicated that investigation was still ongoing and it could not yet confirm any evidence that any patient personal information was compromised as a result of this incident. However, on May 20, 2026, Kroll, who is the third-party administrator for the Vendor, notified the Company that the Vendor had detected unauthorized access by a third party to certain information systems of the Company, including systems affecting data of patients. The Company believes that the cybersecurity incident has affected various other healthcare service providers, and the Vendor has set up a patient portal through which it intends to provide information and responses to inquiries. Because of the Company's technology security and continuity plan, the Company worked swiftly in response, and its operations have continued in all material respects since the detection of the incident.