Blog > Data Breach & Privacy

Mountain Rheumatology Data Breach: What Patients Need to Know

Mountain Rheumatology Professional, a Denver-based rheumatology practice, reported a hacking incident involving a network server to federal regulators, with more than 5,000 individuals listed as affected. Here is what has been disclosed so far and what patients may want to consider.

Mountain Rheumatology Data Breach: What Patients Need to Know

What Happened in the Mountain Rheumatology Data Breach

A hacking incident reported to federal regulators

According to the U.S. Department of Health and Human Services Office for Civil Rights breach portal, Mountain Rheumatology Professional, LLC, a healthcare provider in Colorado, submitted a breach report on August 14, 2026. The portal categorizes the incident as a hacking/IT incident and lists the location of the breached information as a network server.

Federal law requires HIPAA-covered entities to report breaches of unsecured protected health information affecting 500 or more individuals, and the portal indicates the Mountain Rheumatology incident is among those currently under investigation. Beyond the portal listing, the practice has not published detailed public information about how the incident occurred, so the specifics reported at this stage are limited and may be supplemented as notifications are issued.

What Information May Have Been Involved

Protected health information that could be at risk

Because the incident was reported to the Office for Civil Rights as a HIPAA breach, it is understood to involve protected health information. However, the specific categories of data involved — such as names, dates of birth, Social Security numbers, diagnosis or treatment details, or insurance information — have not been publicly itemized as of the portal listing.

Rheumatology practices typically maintain sensitive medical records, including diagnoses, treatment plans, prescriptions, lab results, and insurance details, so patients may wish to treat the situation with appropriate caution until more is known. Where health-related information may have been exposed, there can be an increased risk of medical identity theft, fraud, or targeted phishing — even when a provider has not reported any known misuse.

Who May Be Affected by the Mountain Rheumatology Breach

Patients of the Denver-based practice

Mountain Rheumatology Professional, LLC is a medical group based in Denver, Colorado, that diagnoses and treats conditions affecting the joints, muscles, bones, and tendons. The individuals potentially affected are likely to be current and former patients whose records were maintained on the affected systems, though the practice has not published a breakdown.

The HHS Office for Civil Rights portal lists 5,378 individuals as affected. Patients whose information was involved would generally receive a written notification from the practice describing the specific information at issue and any resources being offered. If you are a current or former patient and receive such a letter, it may indicate your information was among the data reported to have been affected.

How Mountain Rheumatology Has Responded

What is known and what to watch for

Beyond the federal breach report, Mountain Rheumatology has not published a detailed public statement describing its response, and no notice about the incident was located on the practice’s website as of this writing. Providers responding to incidents of this kind commonly engage cybersecurity specialists, notify law enforcement, and review their security controls, but the practice has not publicly confirmed which steps it has taken.

If the practice is offering complimentary credit monitoring or identity protection services, those details would typically appear in individual notification letters. Affected patients may want to review any letter they receive carefully and follow its instructions for enrolling in any services offered before the stated deadline.

Steps You Can Take to Protect Yourself

Practical precautions while the situation is reviewed

While the details of the Mountain Rheumatology incident are still emerging, affected patients may wish to consider a few precautionary steps:

  • Watch for a notification letter. It may describe the specific information involved and any services being offered.
  • Review your Explanation of Benefits statements. Watch for medical claims or services you did not receive, which can be a sign of medical identity theft.
  • Check your credit reports. You are entitled to free annual credit reports at annualcreditreport.com, and you can watch for accounts or inquiries you do not recognize.
  • Consider a fraud alert or credit freeze. These are available at no cost through Equifax, Experian, and TransUnion and can add a layer of protection.
  • Stay alert to phishing. Be cautious of unexpected emails, calls, or texts referencing the incident, and verify communications through official channels before sharing information.

This information is a general overview and is not legal advice; your situation may differ, and consulting a legal professional can help you understand rights that may apply to you.

Talk to Wilshire Law Firm

Were you affected by the Mountain Rheumatology data breach?

If your health information or personal data may have been involved in the Mountain Rheumatology data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.

Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.

FAQs

Mountain Rheumatology Professional, LLC submitted a breach report to the U.S. Department of Health and Human Services on August 14, 2026. The dates on which the unauthorized activity occurred or was discovered have not been publicly detailed.

The HHS Office for Civil Rights portal categorizes the incident as a hacking/IT incident involving a network server. The practice has not publicly described the specific method of access.

Because the incident was reported as a HIPAA breach, it is understood to involve protected health information, but the specific categories of data have not been publicly itemized. Individual notification letters would typically describe the information involved for each person.

The HHS Office for Civil Rights breach portal lists 5,378 individuals as affected by the Mountain Rheumatology Professional, LLC incident.

The practice has not publicly announced whether complimentary credit monitoring or identity protection services are being offered. Any such services would typically be described in the individual notification letter, so it is worth reviewing any notice you receive.

Watch for a notification letter, review your Explanation of Benefits statements and credit reports, consider a fraud alert or credit freeze, stay alert to phishing, and keep any notice you receive. You may also wish to speak with a legal professional about any rights or options that may apply to your situation.

Individuals who believe they were affected may have legal options, and data breaches involving protected health information can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts. A free case review with a legal professional can help you understand your potential rights.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,500+ reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance