Breach taxonomy
Summary
The Oncology Institute disclosed under Item 1.05 that a cybersecurity incident at a software service provider (first voluntarily disclosed November 6, 2025) affected company information systems including patient data. On May 20, 2026, Kroll, the vendor's third-party administrator, notified the company that the vendor detected unauthorized third-party access to systems affecting patient data. The incident affected various other healthcare providers; operations continued in all material respects and credit monitoring is being offered.
Tagging rationale
ThreatUnknown
Filing does not attribute the incident to a specific actor -> UNKNOWN.
MethodsData ExfilSupply Chain
Incident originated at a software service provider (vendor) used by the company and affected patient data across multiple healthcare providers -> DATA-EXFIL + SUPPLY-CHAIN.