
The Oncology Institute confirmed that a previously disclosed cybersecurity incident involving a third-party software services provider has affected patient information. The institute reported that Kroll, the third-party administrator for the vendor, notified it on May 20, 2026 of unauthorized access to certain information systems, including systems affecting patient data. The institute stated it believes the incident affected other healthcare service providers as well. The vendor has set up a patient portal intended to provide information and responses to inquiries. The institute did not name the vendor, but the timeline and reported multi-organization impact suggest a possible connection to TriZetto Provider Solutions, a Cognizant-owned healthcare technology company. It remains unclear who carried out the attack, and no ransomware group has claimed responsibility.
"However, on May 20, 2026, Kroll, who is the third-party administrator for the Vendor, notified [TOI] that the Vendor had detected unauthorized access by a third party to certain information systems of [TOI], including systems affecting data of patients,"
"It added, "[TOI] believes that the cybersecurity incident has affected various other healthcare service providers, and the Vendor has set up a patient portal through which it intends to provide information and responses to inquiries.""
"The healthcare organization told the SEC in November 2025 that it had learned of a cybersecurity incident affecting a third-party software services provider. At the time, the vendor's investigation was ongoing and it could not say whether patient information had been compromised."
"While TOI has not named the third-party software vendor, the timeline and the reported impact of the breach across multiple healthcare organizations point to Cognizant-owned healthcare technology company TriZetto Provider Solutions as a possible candidate."
#healthcare-cybersecurity #data-breach #third-party-vendor-risk #patient-notification #oncology-services
Read at SecurityWeek
Unable to calculate read time
Collection
[
|
...
]