Rocky Mountain Oncology Care
ent_e9470e5e074db643bc68c8d2
Disclosures
6
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
10,268
nationwide · HHS OCR WY
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Rocky Mountain Oncology Care
- Normalized
- rocky mountain oncology care— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- Montana State AGas victim2025-10-29
Rocky Mountain Oncology Care notified Montana residents of unauthorized system access between March 31 and April 10, 2025. The incident, detected on April 11, 2025, compromised patient names. Law enforcement was notified, and security protocols are being enhanced.
- WYOMINGHHS OCRas victim2025-10-24
Rocky Mountain Oncology Care (WY) reported to HHS on 2025-10-24 a Hacking/IT Incident affecting 5,615 individuals. The breach occurred at a business associate's network server. PHI exposed included clinical and demographic information. The CE notified HHS, affected individuals, and media, and offered credit monitoring. The BA implemented additional administrative, technical, and security safeguards.
- Illinois State AGas victim2025-10-01
ROCKY MOUNTAIN ONCOLOGY CARE filed a data-breach notice with the Illinois Attorney General in October 2025 (case 25-10-558). The register records the breach as discovered on September 26, 2025. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Montana State AGas victim2025-07-15
Rocky Mountain Oncology Care notified Montana residents of a phishing incident. Unauthorized access to patient email and SharePoint accounts occurred Dec 13-16, 2024. The company discovered the incident on June 13, 2025. Patient PII and PHI were accessed. No evidence of misuse found. Staff cybersecurity training is being provided.
- Illinois State AGas victim2025-07-01
ROCKY MOUNTAIN ONCOLOGY CARE filed a data-breach notice with the Illinois Attorney General in July 2025 (case 25-07-301). The register records the breach as discovered on June 13, 2025. Personal information types reported: medical information. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- WYOMINGHHS OCRas victim2025-06-27
Rocky Mountain Oncology Care reported to HHS on 2025-06-27 a Hacking/IT Incident affecting 10,268 individuals. Breached information located on Email. A business associate's employees were subjected to an email phishing scheme, compromising clinical, demographic, and financial PHI. The CE provided credit monitoring and implemented additional safeguards.