The Oncology Institute, Inc., a publicly traded cancer care provider, disclosed in May 2026 that patient data was compromised through a third-party vendor breach. This incident involved its software provider, likely TriZetto Provider Solutions, and was administered by Kroll. The company stated its own systems were not breached but confirmed data exposure due to the vendor incident.
While The Oncology Institute has not publicly disclosed the exact types of its compromised patient data, the broader vendor breach (TriZetto) is confirmed to have exposed names, addresses, dates of birth, Social Security numbers (SSNs), health insurance/Medicare numbers, medical history, diagnoses, and prescriptions. Financial data was not affected. The number of affected individuals has not been disclosed by The Oncology Institute; however, the broader vendor breach affected approximately 3.4 million patients nationwide. The company operates clinics in California, Oregon, Nevada, Arizona, and Florida, and patients in these states were likely impacted.
Details about data breaches can emerge over time, and notifications to affected individuals may be delayed.