Integrated Oncology Network
Disclosed Jun 27, 20251 year ago4,174 affectedConfirmed
The Business Associate (BA), Integrated Oncology Network, reported that employees were the targets of an email phishing scheme that affected the PHI of 4,174 individuals. The PHI involved demographic, clinical, and treatment information. The BA notified the Covered Entities, HHS, the affected individuals, the media and posted substitute notice. In response to the breach, the BA ensured that no unauthorized mailbox rules, forwarding settings, or persistence mechanisms existed in the email tenant, initiated a global password reset for its email tenant, implemented multifactor authentication for all email accounts, verbally counseled affected employees, implemented workforce training and simulated phishing tests, and reevaluated its administrative, technical, and workforce training controls.
What is known
| People affected | 4,174 (as reported to HHS) |
|---|---|
| Disclosed | Jun 27, 2025 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Integrated Oncology Network (Business Associate, TN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jun 27, 2025 | 4,174 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.