← The Oncology Institute

2026 The Oncology Institute — vendor breach confirmed; patient data potentially accessed

2026 Unknown records affected Share on X

Data compromised

Patient data categories under investigation; Oncology Institute systems not directly compromised per SEC filings

Technical writeup

The Oncology Institute (TOI), a publicly traded U.S. cancer-care provider serving ~2 million patients across 100+ clinics, confirmed in May 2026 SEC filings that patient data was potentially accessed via a November 2025 cybersecurity incident at an unnamed third-party IT software vendor (media linked TriZetto Provider Solutions). Kroll notified TOI on May 20, 2026 that vendor systems containing TOI patient data were subject to unauthorized third-party access; TOI stated its own systems were not compromised and is arranging credit monitoring. A consolidated victim count had not been published at catalog time.

Root cause

Third-party IT software vendor security incident

References