Data Breach & Privacy
Blog > Data Breach & Privacy
Mountain Rheumatology Data Breach: What Patients Need to Know
Mountain Rheumatology Professional, a Denver-based rheumatology practice, reported a hacking incident involving a network server to federal regulators, with more than 5,000 individuals listed as affected. Here is what has been disclosed so far and what patients may want to consider.

What Happened in the Mountain Rheumatology Data Breach
A hacking incident reported to federal regulators
According to the U.S. Department of Health and Human Services Office for Civil Rights breach portal, Mountain Rheumatology Professional, LLC, a healthcare provider in Colorado, submitted a breach report on August 14, 2026. The portal categorizes the incident as a hacking/IT incident and lists the location of the breached information as a network server.
Federal law requires HIPAA-covered entities to report breaches of unsecured protected health information affecting 500 or more individuals, and the portal indicates the Mountain Rheumatology incident is among those currently under investigation. Beyond the portal listing, the practice has not published detailed public information about how the incident occurred, so the specifics reported at this stage are limited and may be supplemented as notifications are issued.
What Information May Have Been Involved
Protected health information that could be at risk
Because the incident was reported to the Office for Civil Rights as a HIPAA breach, it is understood to involve protected health information. However, the specific categories of data involved — such as names, dates of birth, Social Security numbers, diagnosis or treatment details, or insurance information — have not been publicly itemized as of the portal listing.
Rheumatology practices typically maintain sensitive medical records, including diagnoses, treatment plans, prescriptions, lab results, and insurance details, so patients may wish to treat the situation with appropriate caution until more is known. Where health-related information may have been exposed, there can be an increased risk of medical identity theft, fraud, or targeted phishing — even when a provider has not reported any known misuse.
Who May Be Affected by the Mountain Rheumatology Breach
Patients of the Denver-based practice
Mountain Rheumatology Professional, LLC is a medical group based in Denver, Colorado, that diagnoses and treats conditions affecting the joints, muscles, bones, and tendons. The individuals potentially affected are likely to be current and former patients whose records were maintained on the affected systems, though the practice has not published a breakdown.
The HHS Office for Civil Rights portal lists 5,378 individuals as affected. Patients whose information was involved would generally receive a written notification from the practice describing the specific information at issue and any resources being offered. If you are a current or former patient and receive such a letter, it may indicate your information was among the data reported to have been affected.
How Mountain Rheumatology Has Responded
What is known and what to watch for
Beyond the federal breach report, Mountain Rheumatology has not published a detailed public statement describing its response, and no notice about the incident was located on the practice’s website as of this writing. Providers responding to incidents of this kind commonly engage cybersecurity specialists, notify law enforcement, and review their security controls, but the practice has not publicly confirmed which steps it has taken.
If the practice is offering complimentary credit monitoring or identity protection services, those details would typically appear in individual notification letters. Affected patients may want to review any letter they receive carefully and follow its instructions for enrolling in any services offered before the stated deadline.
Steps You Can Take to Protect Yourself
Practical precautions while the situation is reviewed
While the details of the Mountain Rheumatology incident are still emerging, affected patients may wish to consider a few precautionary steps:
- Watch for a notification letter. It may describe the specific information involved and any services being offered.
- Review your Explanation of Benefits statements. Watch for medical claims or services you did not receive, which can be a sign of medical identity theft.
- Check your credit reports. You are entitled to free annual credit reports at annualcreditreport.com, and you can watch for accounts or inquiries you do not recognize.
- Consider a fraud alert or credit freeze. These are available at no cost through Equifax, Experian, and TransUnion and can add a layer of protection.
- Stay alert to phishing. Be cautious of unexpected emails, calls, or texts referencing the incident, and verify communications through official channels before sharing information.
This information is a general overview and is not legal advice; your situation may differ, and consulting a legal professional can help you understand rights that may apply to you.
Talk to Wilshire Law Firm
Were you affected by the Mountain Rheumatology data breach?
If your health information or personal data may have been involved in the Mountain Rheumatology data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.
Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.
FAQs
Mountain Rheumatology Professional, LLC submitted a breach report to the U.S. Department of Health and Human Services on August 14, 2026. The dates on which the unauthorized activity occurred or was discovered have not been publicly detailed.
The HHS Office for Civil Rights portal categorizes the incident as a hacking/IT incident involving a network server. The practice has not publicly described the specific method of access.
Because the incident was reported as a HIPAA breach, it is understood to involve protected health information, but the specific categories of data have not been publicly itemized. Individual notification letters would typically describe the information involved for each person.
The HHS Office for Civil Rights breach portal lists 5,378 individuals as affected by the Mountain Rheumatology Professional, LLC incident.
The practice has not publicly announced whether complimentary credit monitoring or identity protection services are being offered. Any such services would typically be described in the individual notification letter, so it is worth reviewing any notice you receive.
Watch for a notification letter, review your Explanation of Benefits statements and credit reports, consider a fraud alert or credit freeze, stay alert to phishing, and keep any notice you receive. You may also wish to speak with a legal professional about any rights or options that may apply to your situation.
Individuals who believe they were affected may have legal options, and data breaches involving protected health information can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts. A free case review with a legal professional can help you understand your potential rights.

