← Blog

Rocky Mountain Care: Qilin Claims and Patient Watchlist

Share on X

Rocky Mountain Care, a Utah-based healthcare and senior-care organization, published a March 2026 data-event notice describing a cybersecurity incident with unauthorized access to files on its network. Public summaries tied the case to Qilin ransomware-style extortion and sample postings, with an activity window around late January through early February 2026.

What is still uncertain

As of the initial notice, the company described an ongoing review to determine whether protected health information and other personal data were involved, and had not always published a final individual count in early materials. Patients should rely on any direct notification letters and official state or HHS filings as the investigation matures.

Practical steps

Watch explanation-of-benefits statements for unfamiliar services, enable account alerts where offered, and treat unexpected messages about the incident as potential phishing.

Canonical record: Rocky Mountain Care 2026 on BreachHistory.

Sources: Rocky Mountain Care data event notice, Claim Depot summary