Rocky Mountain Associated Physicians, P.C. experienced a hacking incident that began by October 30, 2025. The company discovered the unauthorized activity on February 2, 2026, and publicly disclosed the incident in April 2026. The PEAR ransomware group claimed responsibility.
The breach involved sensitive personal and medical data for 50,640 patients. Exposed data types include names, dates of birth, Social Security numbers, addresses, contact details, medical record numbers, diagnosis and treatment information, insurance information, credit/debit card numbers, PINs, and in some cases, financial account information. The company, based in Utah, has begun notifying affected individuals and filed notice with the U.S. Department of Health and Human Services (HHS) on April 3, 2026. Rocky Mountain Associated Physicians is offering 12 months of complimentary credit monitoring and identity restoration services.
More information about this event may become available as investigations continue. Affected individuals should review their accounts, protect their credit, and keep records of any suspicious activity.