Mountain Rheumatology Professional, LLC, a rheumatology practice based in Denver, Colorado, has reported a data security incident affecting thousands of patients to the U.S. Department of Health and Human Services’ Office for Civil Rights (HHS OCR). The practice, which operates under the name Mountain Rheumatology, provides specialty care and treatment to patients throughout the Denver area, maintaining electronic health records and other sensitive personal information in the ordinary course of patient care.
Mountain Rheumatology’s Data Breach Investigation
Attorneys are investigating a data breach reported by Mountain Rheumatology Professional, LLC after the practice submitted a breach notification to HHS OCR on August 14, 2026. The filing classifies the incident as a hacking or IT incident involving the practice’s network server, and reports that 5,378 individuals were affected. As a healthcare provider covered by HIPAA, Mountain Rheumatology is required to report breaches of unsecured protected health information affecting 500 or more individuals to federal regulators, which is how this incident became publicly known.
Medical practices like Mountain Rheumatology maintain detailed patient records that typically include names, contact information, dates of birth, and clinical information related to diagnosis and treatment, sometimes alongside Social Security numbers or insurance and billing details. When a network server is compromised in a hacking incident, any of this information stored on that system can potentially be accessed or exposed, depending on the scope of the intrusion. The practice has not yet publicly detailed the specific categories of information involved or the technical circumstances of how the breach occurred beyond what was reported to HHS OCR.
Healthcare providers are common targets for cyberattacks because medical records carry significant value on the black market and often cannot be easily changed the way a password or credit card number can be. A patient whose Social Security number or health information is exposed in a breach like this faces a heightened and often long-lasting risk of identity theft, insurance fraud, or medical fraud committed in their name. Regardless of the size of the practice, healthcare organizations that collect and store this kind of sensitive information have a legal and ethical responsibility to implement reasonable safeguards to protect it from unauthorized access.
HIPAA’s Breach Notification Rule requires covered entities to notify affected individuals, HHS, and in some cases the media, following the discovery of a breach involving unsecured protected health information. The rule sets deadlines for these notifications but does not necessarily require the covered entity to publicly disclose every technical detail of how an intrusion occurred. As a result, affected patients often first learn only limited information from a public regulatory filing, with more specific details arriving later in an individual notification letter, if and when the practice sends one.
Because the full nature of what was accessed during this incident has not yet been made public, patients are encouraged to treat the exposure seriously and to watch for any signs of misuse of their personal or medical information. Attorneys who represent patients in data breach cases can help affected individuals understand their rights and pursue compensation for the risks and burdens created by a healthcare data breach, particularly where a provider may not have implemented adequate security measures to prevent unauthorized access to patient data.
When Did This Breach Occur?
Mountain Rheumatology Professional, LLC submitted its breach report to the HHS Office for Civil Rights on August 14, 2026. The practice has not publicly disclosed the specific date the intrusion was discovered or when it is believed to have first occurred.
What Information Was Breached?
According to the HHS OCR filing, the breach involved a hacking or IT incident affecting the practice’s network server and affected 5,378 individuals. The practice has not yet publicly specified the exact categories of patient data involved, though information stored on a medical practice’s network server commonly includes names, contact details, dates of birth, and protected health information related to diagnosis, treatment, and billing.
What You Can Do
If you are a patient of Mountain Rheumatology and are concerned that your information may have been involved in this incident, there are steps you can take now to help protect yourself:
Watch for a notification letter from the practice, which should provide more specific detail about what information of yours may have been affected. Monitor your medical bills and insurance statements (explanation of benefits) for any services or claims you don’t recognize, which can be a sign of medical identity theft. Consider requesting a copy of your medical records to check for inaccuracies that could result from fraudulent use of your identity. If Social Security numbers were involved, consider placing a fraud alert or credit freeze with the major credit bureaus. Be cautious of any calls, texts, or emails referencing this breach, as scammers sometimes exploit breach news to run phishing scams.
File a Data Breach Lawsuit Against Mountain Rheumatology
If your personal or medical information was compromised in the Mountain Rheumatology data breach, you may have legal options available to you. Healthcare providers are expected to maintain reasonable security measures to protect the sensitive data entrusted to them by patients.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.