
Loveland, Colorado-based Summit Pathology and Summit Pathology Laboratories suffered a significant data security incident that compromised the sensitive personal information of more than 1.8 million patients.
Headquartered in Loveland, Colorado, Summit Pathology serves hospital systems and physician offices in Colorado, Wyoming, and Nebraska. Its services include general surgical pathology as well as high level expertise in breast pathology, cytopathology, hematopathology and other fields.
In a data security incident notice, Summit said that on April 18, it identified suspicious activity in its internal network. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
“Based on this investigation, we identified files within our systems that may have been accessed or acquired by the unauthorised cybercriminal, and the impacted systems contained certain patient data,” reads the notice.
The compromised data included names, addresses, medical billing and insurance information, certain medical information such as diagnoses, and demographic information such as dates of birth, Social Security numbers, and financial information.
Summit’s filing with the U.S. Department of Health and Human Services Office for Civil Rights revealed that at least 1,813,538 individuals were impacted by the data security incident.
“Upon learning of the malicious activity, we promptly notified law enforcement and took steps to further secure our systems and investigate the event. As part of our ongoing commitment to the privacy of personal information in our care, we reviewed our existing policies and procedures and implemented additional administrative and technical safeguards to help prevent future attacks,” Summit added.
The company has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and state attorney general.
It has also offered complimentary identity protection and credit monitoring services through IDX to all affected individuals.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543