← Blog

The Oncology Institute Vendor Breach: What Cancer Patients Should Know

Share on X

Publicly traded cancer-care provider The Oncology Institute (TOI) confirmed in May 2026 that patient data was potentially accessed through a cybersecurity incident at an unnamed third-party IT software vendor tied to a November 2025 event. HIPAA Journal reported that Kroll notified TOI on May 20, 2026 that vendor systems containing patient information were subject to unauthorized access, while TOI emphasized its own networks were not compromised.

What we know

  • TOI serves roughly 2 million patients across 100+ clinics in California, Oregon, Nevada, Arizona, and Florida.
  • The vendor name was not disclosed in SEC materials; trade press linked TriZetto Provider Solutions as a likely upstream party.
  • TOI is arranging complimentary credit monitoring and identity theft protection; specific data categories and victim totals were still under review at disclosure time.

Patient action items

  1. Watch for official TOI notification letters rather than SMS or email links citing partial medical details.
  2. Enable fraud alerts or credit freezes if you received care at TOI-affiliated clinics.
  3. Report suspicious oncology-billing or insurance fraud referencing real treatment dates.

Canonical record: The Oncology Institute 2026 vendor breach on BreachHistory.

Sources: HIPAA Journal, TOI investor notice