DisclosureLens
FEDERALItem 1.05 · mandatoryHackingHealthcareHealthcareSupply Chain (3P Vendor)Business Associate (HIPAA)Customer Data InvolvedDownstream VictimsDelayed DiscoveryPHIPIIHealth (basic)Identity (basic)LowActive

The Oncology Institute, Inc.

bd_383278f2de77324b · schema v1 · pii pii-v1

Severity

Low

Discovered

May 20, 2026

Filed

May 22, 2026

To disclose

2 days

Affected

Not disclosed

Confidence

81%
Full breach record for The Oncology Institute, Inc.2 incidents on file

The Oncology Institute, Inc. filed an Item 1.05 8-K supplementing its November 6, 2025 voluntary 7.01 disclosure regarding a cybersecurity incident at a software service provider (Vendor). On May 20, 2026, Kroll, the Vendor's third-party administrator, notified the Company that an unauthorized third party had accessed certain Company information systems, including systems containing patient data. The Company states operations continued in all material respects and it will work with the Vendor to offer credit monitoring to impacted patients.

SEC clockMateriality determined May 20, 2026Filed May 22, 20262d SEC 4-day OK2 days discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

discovery → filing · 2 days

May 20, 2026

Discovered

May 22, 2026

Filed

vs. sector median

11 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.