Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationhealthcare-sector-threatmass-credential-exposurethird-party-vendor-breach

Large US Healthcare Data Breaches Impacting Millions of Patients

Updated 3mo agoFirst seen Jan 31, 20263 sources

Multiple healthcare-sector data breaches were disclosed with significant exposure of protected health information (PHI). TriZetto Provider Solutions (TPS), an insurance verification provider, reported a compromise that began in November 2024 and was not detected until nearly a year later; the threat was reportedly eradicated on Oct. 2, 2025. Notifications to affected healthcare provider customers across several states continued into late 2025 and early 2026, with one Oregon advisory estimating exposure affecting more than 700,000 people; impacted providers stated there was no current evidence of misuse and that financial details were not stolen.

Separately, Healthcare Interactive (HCIactive), an AI-powered insurance enrollment and benefits administration vendor, confirmed that an intrusion and data exfiltration tied to activity in mid-2025 ultimately affected 3,056,950 individuals, after earlier placeholder reporting while scope was still being determined; reported unauthorized access windows vary from July 8–12, 2025 to a broader June 17–July 22, 2025. Another incident involved AI care-coordination platform Lena Health, where a threat actor claimed exposure of patient data (including references to a Twilio call recording database) and alleged that 2,134 patients’ PHI was stored in an unencrypted export in a public-facing AWS S3 bucket, with follow-on reporting indicating exploitation after a publicly disclosed vulnerability and an available patch that was not applied in time.

Share:
Large US Healthcare Data Breaches Impacting Millions of Patients
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jan 30, 20265mo ago

Oregon providers prepare additional patient notices for TriZetto incident

By late January 2026, Oregon healthcare providers said they were preparing breach notification letters tied to the TriZetto incident, including about 1,300 patients at Deschutes County Health Services, 1,650 at Best Care, and 1,200 at La Pine Community Health Center. The providers said they had seen no evidence of misuse and that no financial data was stolen.

Jan 10, 20265mo ago

FulcrumSec says it contacted Lena Health with proof of breach

The threat actor told DataBreaches it contacted Lena Health on January 10, 2026 and initially received acknowledgment that proof files had been received. The actor said communications later stopped.

Jan 7, 20266mo ago

Healthcare Interactive reports 3,056,950 affected to Oregon

Oregon was notified on January 7, 2026 that Healthcare Interactive's 2025 security incident affected 3,056,950 individuals, far exceeding the initial placeholder report of 501. The compromised data included personal identifiers, insurance and billing information, and medical data such as diagnoses, prescriptions, lab results, and images.

Dec 15, 20256mo ago

Lena Health allegedly breached via exposed S3 bucket and Twilio data

A hacking-forum post attributed to FulcrumSec claimed Lena Health was breached in December 2025 through exploitation of an unpatched vulnerability, exposing PHI in a public-facing S3 bucket and Twilio call-recording data. The allegedly exposed information included patient identities, medical details, discharge documents, call recordings and transcripts, and possibly credentials or API keys.

Dec 1, 20257mo ago

Oregon providers are notified of the TriZetto breach

Deschutes County Health Services, Best Care, and La Pine Community Health Center said they were informed in early December 2025 that the TriZetto incident may have exposed patient PHI. Combined, the three providers said more than 700,000 people may have been affected.

Lena Health allegedly remains unpatched after December vulnerability disclosure

A major vulnerability that FulcrumSec said it later exploited against Lena Health was disclosed in early December 2025 and had a patch available. According to the actor, Lena Health had not applied the patch when it was attacked later that month.

Oct 2, 20259mo ago

TriZetto detects suspicious portal activity and contains incident

TriZetto Provider Solutions detected suspicious activity in a customer web portal on October 2, 2025 and said the threat was eliminated the same day. Cognizant engaged Mandiant and notified law enforcement, later stating the incident was not ransomware-related.

Jul 8, 20251y ago

Healthcare Interactive network intrusion exposes customer data

Healthcare Interactive reported unauthorized access and file exfiltration affecting its systems in mid-2025. Confirmed unauthorized access occurred between July 8 and July 12, 2025, though one notice suggested a broader window from June 17 to July 22, 2025.

Nov 1, 20242y ago

TriZetto intrusion begins with unauthorized access to provider systems

Attackers gained access to TriZetto Provider Solutions' environment in November 2024, potentially exposing protected health information and other sensitive data tied to multiple healthcare providers and policyholders.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Threat actors
1 linked
Affected products
1 linked
Chatgpt
Organizations
14 linked
CognizantThe Clorox CompanyTriZetto Provider SolutionsGoogleDeschutes County Health ServicesBest CareCommunity Health SystemsTwilioNorth Country CommunicationsCatholic HealthLena HealthServiceaide, Inc.Houston MethodistHealthcare Interactive
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Large US Healthcare Data Breaches Impacting Millions of Patients | Mallory