Menu
Browse

Catalyst RCM

Primary URL Location Industry
catalystrcm[.]com
Country United States of America
Healthcare Icon
Healthcare
Profile

Catalyst RCM operates as a medical coding and billing service provider. The company’s primary activity is to convert clinical documentation from healthcare providers into standardized coding systems used for insurance reimbursement. These coding systems include, but are not limited to, the Current Procedural Terminology (CPT) and International Classification of Diseases (ICD) code sets. By assigning appropriate codes, Catalyst RCM enables its clients to submit accurate claims to public and private payers. The firm’s client base consists of diagnostic laboratories. Through its billing services, Catalyst RCM assists these laboratories in managing the full revenue cycle, from charge entry to payment posting and follow‑up on denials. The organization is headquartered in the United States of America, placing it within the U.S. healthcare services market.

In performing these functions, Catalyst RCM routinely handles protected health information that includes names, dates of birth, payment card details, medical data and health insurance records. This handling subjects the company to federal privacy and security regulations such as the Health Insurance Portability and Accountability Act (HIPAA). On 1 November 2025, Catalyst RCM detected suspicious activity within its secure file management system. Investigation revealed that attackers had gained access by using compromised credentials. The unauthorized access exposed files containing the personal and health information of individuals whose data the company managed while providing coding and billing services for Vikor Scientific, KorPath and Korgene. A notice posted on the company’s website stated that the breach affected nearly 140,000 individuals, although the exact total remains uncertain. Following the incident, the Everest ransomware group listed the affected laboratories on its leak site and published data that it claimed had been taken from the compromised files.

Incidents
Linked incidents available to members
1 incident