2026 Rocky Mountain Care — Qilin ransomware (Jan 30–Feb 2; PHI scope under review)
Data compromised
Under review per company; may include PHI/PII—full categories and counts pending regulatory filings
Technical writeup
Utah-based Rocky Mountain Care disclosed a cybersecurity incident in which an unauthorized third party accessed files on its network. Public materials dated March 27, 2026 summarized activity between approximately January 30 and February 2, 2026, and referenced claims by the Qilin ransomware group (sample data and extortion messaging reported in late February 2026). The organization stated it secured its network, engaged forensics, and was reviewing whether protected health information and other personal data categories were involved; state-specific consumer notice language was included for multiple jurisdictions. A dedicated assistance line and mailing address were published for inquiries.
Root cause
Ransomware / extortion (Qilin group cited in public disclosure summaries); unauthorized network access