Catalyst RCM
ent_ba38cf807d475d100e2f3666
Disclosures
3
State AG · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
292
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Catalyst RCM
- Normalized
- catalyst rcm— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- Massachusetts State AGas reporting2026-02-07
Catalyst RCM, a medical coding and billing provider for Vikor Scientific, KorPath, and Korgene, reported unauthorized access to its secure file management system. An attacker used valid credentials to access a server between November 8-9, 2025, and copied data containing explanation of benefits letters (PHI) and names. Catalyst discovered the suspicious activity on November 13, 2025. The incident is contained. Identity theft protection services are being offered to affected individuals.
- Vermont State AGas reporting2026-02-06
Vikor Scientific and its business partner Catalyst RCM disclosed a data breach where unauthorized access occurred via valid credentials between Nov 8-9, 2025. The incident exposed patient data including names and financial account numbers from Explanation of Benefits letters. Catalyst notified Vikor Scientific on Nov 13, 2025, and offered 12-24 months of identity theft protection. Approximately 88 Rhode Island residents were identified as impacted.
- California State AGas victim2026-02-06
Catalyst RCM notified individuals of a data privacy event where an authorized login was used to access a server and copy data without permission between November 8-9, 2025. The incident was discovered on November 13, 2025. Affected data included explanation of benefits letters containing names and other health-related information. Catalyst offered identity theft protection services.