Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationhealthcare-sector-threatthird-party-vendor-breachmass-credential-exposure

Delayed patient notifications following healthcare data breaches at providers and vendors

Updated 3mo agoFirst seen Feb 3, 20263 sources

Multiple healthcare organizations and vendors reported delayed patient notifications after discovering unauthorized access to protected health information (PHI), in some cases more than a year after the underlying compromise. In Colorado, Alpine Ear, Nose, and Throat (Alpine ENT) notified 65,648 individuals that an attacker accessed and exfiltrated files containing PHI in an incident identified on Nov. 19, 2024; the BianLian ransomware group later claimed responsibility and posted the organization to its leak site. Exposed data was described as highly sensitive, including medical information and, for some individuals, financial account data and payment card details (including CVC/expiration) and Social Security numbers; Alpine ENT reported no confirmed identity theft at the time of notification and offered credit monitoring.

Separately, Bayada Home Health Care disclosed exposure risk tied to a third-party vendor (Doctor Alliance) after Doctor Alliance reported unauthorized network access during Oct.–Nov. 2025, potentially affecting Home Health Certification and Plan of Care forms containing patient identifiers and clinical/insurance details (and SSNs for a subset). Bayada said it discontinued using Doctor Alliance and reported the matter to regulators. In another vendor-related incident, TriZetto Provider Solutions (Cognizant)—an insurance verification provider—suffered a cyberattack impacting PHI across multiple states; Oregon providers began notifying additional patients after the breach was reported as occurring in Nov. 2024 but not discovered until Oct. 2, 2025, with no financial data reportedly compromised and no evidence of misuse so far; the incident has prompted class-action lawsuits, engagement of Mandiant, and law enforcement notification.

Share:
Delayed patient notifications following healthcare data breaches at providers and vendors
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
Feb 3, 20265mo ago

Marion County Public Health reports insider overaccess incident

Marion County Public Health Department in Indiana disclosed that an employee accessed more patient information than necessary, affecting 792 clients. The department said it found no evidence of misuse and responded with additional HIPAA training and stronger technical safeguards.

Bayada discloses Doctor Alliance third-party breach

Bayada Home Health Care disclosed that a breach at vendor Doctor Alliance may have exposed extensive medical, insurance, and in some cases Social Security information. Bayada said it stopped using the vendor and reported the incident to state attorneys general and HHS OCR.

Feb 2, 20265mo ago

Oregon providers notify patients tied to TriZetto breach

Deschutes County Health Services, Best Care, and La Pine Community Health Center sent breach notifications to thousands of Oregonians affected by the TriZetto incident.

Jan 26, 20265mo ago

Community Health Northwest Florida begins notifying patients

Community Health Northwest Florida started notifying affected individuals on January 26, 2026 after an extended review to determine whose data was impacted.

Jan 1, 20266mo ago

Alpine ENT, The Phia Group, and CHNW Florida notify affected individuals

In January 2026, Alpine ENT, The Phia Group, and Community Health Northwest Florida began notifying patients or other affected individuals about their 2024 incidents and offered credit monitoring or identity protection services.

Dec 1, 20257mo ago

Doctor Alliance suffers unauthorized network access windows

Doctor Alliance reported that an unauthorized party accessed its network during two separate periods in late 2025, creating possible exposure of patient forms and related protected health information handled for clients such as Bayada.

Oct 2, 20259mo ago

TriZetto discovers the 2024 breach

TriZetto Provider Solutions discovered the breach on October 2, 2025, indicating a lengthy gap between the intrusion and detection. Cognizant later engaged Mandiant and notified law enforcement.

Dec 24, 20241y ago

Community Health Northwest Florida identifies unauthorized access

Community Health Northwest Florida tied unauthorized access to patient files to suspicious activity identified on December 24, 2024.

Dec 1, 20242y ago

BianLian claims Alpine ENT attack

The BianLian ransomware group claimed responsibility for the Alpine ENT incident and posted the victim on its leak site in early December 2024.

Nov 19, 20242y ago

Alpine ENT identifies data exfiltration incident

Alpine Ear, Nose, and Throat identified a security incident on November 19, 2024 in which an unauthorized party accessed and exfiltrated patient files.

Nov 1, 20242y ago

TriZetto breach reportedly occurs in November 2024

TriZetto Provider Solutions said the underlying breach occurred in November 2024, exposing protected health information and other personal data of patients across multiple states.

Jul 9, 20242y ago

The Phia Group detects the intrusion

The Phia Group detected the network intrusion on July 9, 2024 and later began assessing what data may have been acquired.

Jul 8, 20242y ago

The Phia Group network intrusion occurs

The Phia Group said unauthorized access to its network occurred between July 8 and July 9, 2024, potentially exposing sensitive personal and health information.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

13 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
11 linked
Alpine Ear, Nose, and ThroatCommunity Health Northwest FloridaThe Phia Group, LLCDoctor AllianceCognizantBayada Home Health CareTriZetto Provider SolutionsGoogleDeschutes County Health ServicesBest CareCommunity Health Systems
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Delayed patient notifications following healthcare data breaches at providers and vendors | Mallory