Catalyst RCM, a Texas-based revenue cycle management company, experienced a data breach in late 2025. An unauthorized actor gained access to their secure file management system between November 8-9, 2025, and this activity was discovered on November 13, 2025. The Everest ransomware group claimed responsibility for the attack. Catalyst RCM did not begin notifying affected individuals until February 2026.
The compromised data for 139,964 individuals included names, dates of birth, payment card information with access codes, medical treatment history, diagnosis information, and health insurance information. This was a vendor breach affecting Catalyst RCM's healthcare clients, including Vikor Scientific (Vanta Diagnostics), KorGene, and KorPath. The specific US states affected have not been publicly disclosed.
It remains unclear if Catalyst RCM is a publicly traded company or what their revenue might be. Law firms are currently investigating potential class action lawsuits related to this incident.