
The Oncology Institute, a cancer care provider operating more than 100 clinics across California, Oregon, Nevada, Arizona and Florida, has announced a data breach incident. Contact our data breach lawyers to learn more and to consider legal action.
The Oncology Institute disclosed the incident in a filing with the U.S. Securities and Exchange Commission in November 2025, and at that point the company acknowledged a cybersecurity incident at one of its third-party information technology software vendors and noted the vendor's investigation was still ongoing.
According to a follow-up SEC filing, Kroll, the third-party administrator handling disclosures on behalf of the vendor, notified third parties on May 20, 2026 that unauthorized access had in fact occurred to certain Oncology Institute systems, including systems containing patient data.
Reports indicate the vendor involved may be TriZetto, a healthcare technology company whose separate data breach reportedly affected multiple healthcare clients and approximately 3.4 million individuals nationwide.
The breach appears to have impacted other healthcare service providers through the same vendor, and a patient portal has been established to provide information to affected individuals.
The organization has not released a full accounting of what patient data was compromised,but third-party vendor breaches in the healthcare space typically involve data stored on administrative systems. Based on the nature of TriZetto's platform, the types of information potentially at risk may include:
Under the California Consumer Privacy Act (CCPA) and the California Confidentiality of Medical Information Act (CMIA), healthcare organizations and their business associates are required to implement reasonable security measures to protect patient information. When they fail to comply, affected individuals may have grounds to pursue legal action.
California also imposes strict data breach notification timelines, and under state law, healthcare providers are required to notify the California Department of Public Health within 15 business days of discovering a breach.
HIPAA, the federal law governing the privacy and security of protected health information, also applies here. When covered entities and their business associates fail to maintain adequate safeguards, they may face regulatory enforcement and civil liability.
Joe Lyon has personally helped secure millions in settlements and protections for patients affected by medical data breaches. The firm represents individuals in class action and individual litigation against healthcare providers and insurers who may not properly protect patient data.
If your information was compromised in the Oncology Institute data breach, contact our attorneys at The Lyon Firm for a free, confidential consultation. There are no upfront costs, and you will receive honest guidance on your legal options. Call us at (513) 381-2333 or submit a confidential consultation request online.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: