DisclosureLens
HackingHealthcareHealthcareStolen CredentialsTargetedCustomer Data InvolvedPIIIdentity (basic)LowContained

Rocky Mountain Oncology Care

bd_f0e2c6deff7eafce · schema v1 · pii pii-v1

Severity

Low

Discovered

Apr 11, 2025

Filed

Oct 29, 2025

To disclose

29 weeks

Affected

10state residents only

Linked

2 filings

Confidence

64%
Full breach record for Rocky Mountain Oncology Care3 incidents on file

Rocky Mountain Oncology Care notified Montana residents of unauthorized system access between March 31 and April 10, 2025. The incident, detected on April 11, 2025, compromised patient names. Law enforcement was notified, and security protocols are being enhanced.

Incident timeline

undetected · 11 days
discovery → filing · 29 weeks / 201 days

Mar 31, 2025

Begins

Apr 11, 2025

Discovered

Oct 29, 2025

Filed

vs. sector median

+18 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
HHS OCROct 24 · first
Montana State AG+5d · this page

Pattern: first filing Oct 24 (WY), last Oct 29 (MT) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.