Catalyst Physician Group

Dec 2025 · Graded Verified · Healthcare and Life Sciences · Government record
Catalyst Physician GroupDec 2025
A single compromised login let an unauthorized actor into a Catalyst RCM server over November 8 and 9, 2025, with no phishing lure or exploited flaw named, just a credential that should not have worked. Catalyst RCM processes billing and revenue cycle data for multiple healthcare clients, including Catalyst Physician Group and the lab now known as Vanta Diagnostics, so one login opened files belonging to entities that never chose that vendor's security posture. Personal details, medical data, and insurance information moved together because the billing pipeline treated them as one bundle worth protecting equally, which it wasn't. It took Catalyst nearly 10 months to report the incident, and they graciously give you only 3 months to sign up for identity protection. 3x less time for you to respond than it took them to respond.
California AG breach notification
Initial attack type compromised credentials confirmed · Impact data theft confirmed
Not yet quantified
VVerifiedHealthcare and Life Sciences
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.
← The complete On the Government Record ledger ← Back to the index