Skip to main content
Jump to a category page

Mountain Rheumatology, a Colorado specialty rheumatology practice, reported a hacking incident affecting 5,378 patients to federal health regulators — with few other details made public so far.

Mountain Rheumatology Professional, LLC, a specialty rheumatology practice in Colorado, submitted a breach report to the U.S. Department of Health and Human Services Office for Civil Rights on August 14, 2026. The report describes a hacking or IT incident involving a network server and affecting 5,378 individuals. No state attorney general filing or company notice letter has been independently located to supplement the federal report.

Source: HHS Office for Civil Rights breach portal (submission dated 08/14/2026, Hacking/IT Incident, Network Server, 5,378 individuals).

A Thin Public Record So Far

The HHS breach portal entry confirms the type of incident and the number of people affected, but it does not itemize the specific categories of information involved, and it does not disclose when the incident occurred, when it was discovered, or what Mountain Rheumatology is offering affected patients. Federal law requires healthcare providers to notify HHS within 60 days of discovering a breach, which means the underlying discovery date is no later than roughly mid-June 2026 if this filing was made on time.

What Information Was Exposed?

Mountain Rheumatology has not confirmed the specific categories of information involved. As a specialty medical practice, the records it maintains typically include names, dates of birth, and medical and insurance information related to rheumatology treatment.

How Many People Are Affected?

5,378 individuals, according to Mountain Rheumatology’s HHS filing.

What Is Mountain Rheumatology Offering Affected Individuals?

Mountain Rheumatology has not publicly disclosed whether it is offering credit monitoring or identity protection services. Anyone who received a notice letter should review it directly for enrollment instructions or contact information specific to the offer made to them.

Your Information Is at Risk

Even without a confirmed list of exposed data categories, a hacking incident at a medical practice commonly puts patients at risk of identity theft and medical identity theft, including someone using stolen insurance information to obtain treatment in your name. Affected individuals should watch for a notice letter and monitor financial accounts and insurance statements for unfamiliar activity.

Do You Have Legal Options?

Healthcare providers that collect and store patient information have a legal duty under HIPAA and state law to secure that data and to notify affected individuals without unreasonable delay.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice letter from Mountain Rheumatology.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

FAQ

Who is affected by the Mountain Rheumatology data breach?

5,378 individuals, according to Mountain Rheumatology’s filing with HHS. The practice serves patients in Colorado.

What information was exposed?

That has not been publicly confirmed. Mountain Rheumatology’s federal breach report does not itemize specific data categories. If you received a notice letter, check it directly for the categories that applied to you.

When did the breach happen?

Mountain Rheumatology’s HHS filing does not disclose an incident or discovery date. Federal rules generally require notification within 60 days of discovery, which places the discovery date no later than roughly mid-June 2026 if the filing was timely.

Is Mountain Rheumatology offering credit monitoring?

That has not been publicly disclosed. If you received a notice letter, check it directly for enrollment instructions or contact information.

Do I have a legal claim?

Healthcare providers that collect and store patient information have a legal duty to secure that data and to notify affected individuals without unreasonable delay. If you received a notice letter from Mountain Rheumatology, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now