The Oncology Institute, Inc.
bd_383278f2de77324b · schema v1 · pii pii-v1
Full breach record for The Oncology Institute, Inc. →2 incidents on fileThe Oncology Institute, Inc. filed an Item 1.05 8-K supplementing its November 6, 2025 voluntary 7.01 disclosure regarding a cybersecurity incident at a software service provider (Vendor). On May 20, 2026, Kroll, the Vendor's third-party administrator, notified the Company that an unauthorized third party had accessed certain Company information systems, including systems containing patient data. The Company states operations continued in all material respects and it will work with the Vendor to offer credit monitoring to impacted patients.
J jump to incidentP pin to compareR raw source
Incident timeline
May 20, 2026
Discovered
May 22, 2026
Filed
vs. sector median
11 wks faster
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.