Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationransomware-group-operationoperational-disruption

Major Data Breaches Impacting US Healthcare Providers

Updated 3mo agoFirst seen Jan 2, 20262 sources

Cognizant Technology Solutions, through its subsidiary TriZetto Provider Solutions, experienced a significant data breach that went undetected for nearly a year, exposing sensitive personal information such as Social Security numbers, financial account details, and home addresses. The breach, which affected at least 100 individuals across several states, led to multiple class-action lawsuits alleging delayed disclosure, insufficient notification to victims, and a lack of transparency regarding the incident's root cause and remediation. Plaintiffs argue that the delay in notification left affected individuals vulnerable to identity theft and financial fraud, while Cognizant and TriZetto have offered limited public comment due to ongoing litigation.

Separately, Covenant Health, a major healthcare provider operating in several northeastern US states, suffered a ransomware attack by the Qilin group in May 2025. The attack compromised the data of over 478,000 individuals, leading to system shutdowns across hospitals and clinics and prompting the organization to hire cybersecurity experts for containment and investigation. Covenant Health initially reported a smaller number of affected individuals but later updated the total to nearly half a million, subsequently notifying patients and offering credit monitoring and identity protection services. Both incidents underscore the persistent cybersecurity risks facing the healthcare sector and the significant impact of breaches on patient privacy and organizational trust.

Share:
Major Data Breaches Impacting US Healthcare Providers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 2, 20266mo ago

Class-action lawsuits filed against Cognizant over TriZetto breach

By January 2026, Cognizant was facing multiple U.S. class-action lawsuits over the TriZetto data breach. Plaintiffs alleged inadequate security, delayed notification, and lack of transparency that increased the risk of identity theft and fraud.

Dec 1, 20257mo ago

Covenant Health notifies affected individuals and offers protection services

Following its investigation and regulatory reporting, Covenant Health notified affected individuals, offered credit monitoring and identity protection, and set up a dedicated call center. The notifications were issued in compliance with HIPAA and state requirements.

Covenant Health revises breach impact to 478,188 people

After further investigation, Covenant Health updated the number of affected individuals in December 2025 from about 7,800 to 478,188. The compromised data included personal, health, insurance, and treatment information.

Oct 2, 20259mo ago

TriZetto discovers the data breach

TriZetto Provider Solutions discovered the breach on October 2, 2025, nearly a year after attackers first accessed its systems. The incident involved sensitive data including Social Security numbers, financial account details, and home addresses.

Jun 1, 20251y ago

Qilin claims Covenant Health attack and data theft

In June 2025, the Qilin ransomware group publicly claimed responsibility for the Covenant Health incident and said it had stolen 850 GB of sensitive data. This added public attribution and indicated the scale of the data theft.

May 1, 20251y ago

Qilin ransomware attacks Covenant Health

In May 2025, Covenant Health suffered a ransomware attack attributed to the Qilin group, causing system shutdowns across multiple hospitals and clinics in several states. Operations were affected, though the organization said services continued with minimal disruption.

Nov 1, 20242y ago

Hackers begin unauthorized access to TriZetto Provider Solutions systems

Attackers gained unauthorized access to systems at TriZetto Provider Solutions, a Cognizant healthcare subsidiary, as early as November 2024. The intrusion reportedly left sensitive personal data exposed for an extended period before discovery.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

4 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
2 linked
CognizantTriZetto Provider Solutions
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Major Data Breaches Impacting US Healthcare Providers | Mallory