FEDERALItem 1.05 · mandatoryHackingHealthcareHealthcareSupply Chain (3P Vendor)Business Associate (HIPAA)Customer Data InvolvedDownstream VictimsDelayed DiscoveryPHIPIIHEALTH_BASICIDENTITY_BASICLowActive
Oncology Institute, Inc.
bd_383278f2de77324b · schema v1 · pii pii-v1
Full breach record for Oncology Institute, Inc. →The Oncology Institute, Inc. filed an Item 1.05 8-K supplementing its November 6, 2025 voluntary 7.01 disclosure regarding a cybersecurity incident at a software service provider (Vendor). On May 20, 2026, Kroll, the Vendor's third-party administrator, notified the Company that an unauthorized third party had accessed certain Company information systems, including systems containing patient data. The Company states operations continued in all material respects and it will work with the Vendor to offer credit monitoring to impacted patients.
SEC clockMateriality determined May 20, 2026 → Filed May 22, 20262d ✓ SEC 4-day OK2 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1799191/000107997326000721/toi_8k.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 22, 2026
- Raw hash
- 283426e44d27f447a868a528c6272add59ec8003e4a30992b631ddbe308875be
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Oncology Institute, Inc.norm: oncology institute
- SEC CIK
- 0001799191
Victim entity
- Name
- Oncology Institute, Inc.norm: oncology institute
- SEC CIK
- 0001799191
- Industry
- Healthcarellm
Incident
- Discovered
- May 20, 2026
- Materiality determined
- May 20, 2026
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIPIIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Initial access
- supply_chain
Compliance
- Time to disclose
- 2 days(2 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 2d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: May 20, 2026→ Filed: May 22, 20262d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.