Highlands Oncology Group PA
ent_6041ff1ee5bea29f
Disclosures
10
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
113,575
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Highlands Oncology Group PA
- Normalized
- highlands oncology— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- Texas State AGas victim2025-08-04
Highlands Oncology Group PA (“Highlands Oncology”) based in Springdale, Arkansas, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-06-02 and reported on 2025-08-04. 504 Texas residents were affected. 113,575 individuals affected in total. Types of information involved: Name of individual;Social Security Number Information;Driver’s License number;Government-issued ID number (e.g. passport, state ID card);Financial Information (e.g. account number, credit or debit card number);Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
- Massachusetts State AGas victim2025-08-01
Highlands Oncology Group PA reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-08-01. 8 Massachusetts residents were affected.
- ARKANSASHHS OCRas victim2025-08-01
Highlands Oncology Group PA reported to HHS on 2025-08-01 a Hacking/IT Incident affecting 111,766 individuals. Breached information located on Network Server.
- Illinois State AGas victim2025-08-01
HIGHLANDS ONCOLOGY GROUP PA (“HIGHLANDS ONCOLOGY”) filed a data-breach notice with the Illinois Attorney General in August 2025 (case 25-08-341). The register records the breach as discovered on June 2, 2025. Personal information types reported: drivers license, financial account number, medical information, passport number, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Nebraska State AGas victim2025-08-01
Highlands Oncology Group PA disclosed a ransomware incident discovered on June 2, 2025, affecting systems between January 21 and June 2, 2025. An unauthorized third party encrypted files and potentially exfiltrated personal information. The company notified law enforcement, engaged forensic investigators, and offered one year of Experian IdentityWorks credit monitoring to affected individuals.
- New Hampshire State AGas victim2025-08-01
Highlands Oncology Group PA reported a ransomware attack discovered on June 2, 2025, affecting 5 New Hampshire residents. The attacker exploited a vendor application vulnerability between Jan 21 and June 2, 2025, encrypting files and potentially exfiltrating PHI, SSNs, and financial data. Highlands engaged forensic experts, notified law enforcement, and offered 12 months of credit monitoring.
- Maine State AGas victim2025-08-01
Highlands Oncology Group PA reported a cyber-attack discovered on June 2, 2025, affecting 113,575 individuals. Unauthorized access occurred between Jan 21 and June 2, 2025, resulting in file encryption and potential data acquisition. The incident involved external hacking and ransomware activity. Affected data included personal identifiers. The company engaged forensic investigators, notified law enforcement, and offered 12 months of credit monitoring.
- Montana State AGas victim2023-12-29
Highlands Oncology Group PA notified Montana residents of a cyber-attack discovered on September 26, 2023. An unauthorized third party accessed systems between Sept 25-26, encrypted files (ransomware), and potentially exfiltrated personal information including names. The company engaged forensic investigators, notified law enforcement, and offered one year of Experian IdentityWorks credit monitoring.
- ARKANSASHHS OCRas victim2023-12-22
Highlands Oncology Group PA reported to HHS on 2023-12-22 a Hacking/IT Incident affecting 55,297 individuals. Breached information located on Network Server. The incident involved ransomware encrypting PHI including names, SSNs, and medical data.
- Illinois State AGas victim2023-01-01
HIGHLANDS ONCOLOGY GROUP PA filed a data-breach notice with the Illinois Attorney General during 2023 (case 23-872). The register records the breach as discovered on September 25, 2023. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.