Incident · 8-K Item 7.01; Item 1.05
The Oncology Institute reports patient data exposure through a software vendor
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
The Oncology Institute, a community oncology practice group, first told investors on November 6, 2025 about a cybersecurity incident at a software provider that could delay some fee-for-service collections. More than six months later, on May 22, 2026, it filed under Item 1.05 after being told that patient data systems had been accessed.
November 2025, Item 7.01
The company's first filing framed the incident as a billing matter. At that time the vendor had not indicated any evidence of compromised patient information.
May 2026, Item 1.05
The later filing recorded new information from the vendor's administrator. The company said other health care providers were affected too, that operations continued, and that it would offer credit monitoring to affected patients.
Not named
Neither filing names the software vendor or gives a patient count. The company has since been renamed in EDGAR records; this entry uses the name on the filings.
Sources
- 2025-11-06 · AThe Oncology Institute, Inc., Form 8-K, Item 7.01 (SEC EDGAR), published November 6, 2025
- 2026-05-22 · AThe Oncology Institute, Inc., Form 8-K, Item 1.05 (SEC EDGAR), published May 22, 2026
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.