Major Data Breaches Impacting US Healthcare Providers
Cognizant Technology Solutions, through its subsidiary TriZetto Provider Solutions, experienced a significant data breach that went undetected for nearly a year, exposing sensitive personal information such as Social Security numbers, financial account details, and home addresses. The breach, which affected at least 100 individuals across several states, led to multiple class-action lawsuits alleging delayed disclosure, insufficient notification to victims, and a lack of transparency regarding the incident's root cause and remediation. Plaintiffs argue that the delay in notification left affected individuals vulnerable to identity theft and financial fraud, while Cognizant and TriZetto have offered limited public comment due to ongoing litigation.
Separately, Covenant Health, a major healthcare provider operating in several northeastern US states, suffered a ransomware attack by the Qilin group in May 2025. The attack compromised the data of over 478,000 individuals, leading to system shutdowns across hospitals and clinics and prompting the organization to hire cybersecurity experts for containment and investigation. Covenant Health initially reported a smaller number of affected individuals but later updated the total to nearly half a million, subsequently notifying patients and offering credit monitoring and identity protection services. Both incidents underscore the persistent cybersecurity risks facing the healthcare sector and the significant impact of breaches on patient privacy and organizational trust.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
7 events from the most recent confirmed update back to the earliest known activity.
Class-action lawsuits filed against Cognizant over TriZetto breach
By January 2026, Cognizant was facing multiple U.S. class-action lawsuits over the TriZetto data breach. Plaintiffs alleged inadequate security, delayed notification, and lack of transparency that increased the risk of identity theft and fraud.
Covenant Health notifies affected individuals and offers protection services
Following its investigation and regulatory reporting, Covenant Health notified affected individuals, offered credit monitoring and identity protection, and set up a dedicated call center. The notifications were issued in compliance with HIPAA and state requirements.
Covenant Health revises breach impact to 478,188 people
After further investigation, Covenant Health updated the number of affected individuals in December 2025 from about 7,800 to 478,188. The compromised data included personal, health, insurance, and treatment information.
TriZetto discovers the data breach
TriZetto Provider Solutions discovered the breach on October 2, 2025, nearly a year after attackers first accessed its systems. The incident involved sensitive data including Social Security numbers, financial account details, and home addresses.
Qilin claims Covenant Health attack and data theft
In June 2025, the Qilin ransomware group publicly claimed responsibility for the Covenant Health incident and said it had stolen 850 GB of sensitive data. This added public attribution and indicated the scale of the data theft.
Qilin ransomware attacks Covenant Health
In May 2025, Covenant Health suffered a ransomware attack attributed to the Qilin group, causing system shutdowns across multiple hospitals and clinics in several states. Operations were affected, though the organization said services continued with minimal disruption.
Hackers begin unauthorized access to TriZetto Provider Solutions systems
Attackers gained unauthorized access to systems at TriZetto Provider Solutions, a Cognizant healthcare subsidiary, as early as November 2024. The intrusion reportedly left sensitive personal data exposed for an extended period before discovery.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


