Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationmass-credential-exposurethird-party-vendor-breach

Healthcare Sector Data Breach Disclosures Expand Victim Counts Across Multiple Incidents

Updated 3mo agoFirst seen Feb 26, 20264 sources

Multiple healthcare-related breach disclosures expanded significantly, led by TriZetto Provider Solutions reporting to regulators that 3,433,965 people were affected after an attacker used a web portal to access historical eligibility reports containing sensitive data (including SSNs and insurance information). Separately, Conduent Business Services told Wisconsin regulators that its incident now impacts “25 million-plus” people nationwide; the Xerox spinoff had previously reported ~15.5 million affected in Texas, prompting an investigation by Texas AG Ken Paxton, while reporting noted the event is still smaller than the largest U.S. health-data breach on record.

Reporting on the Change Healthcare ransomware incident reiterated that UnitedHealth estimated roughly 190 million people were affected, with congressional testimony attributing initial access to a Citrix remote access portal lacking MFA, followed by data theft and ransomware deployment; reporting also cited a $22 million ransom payment. In the Asia-Pacific region, a separate healthcare privacy incident involving New Zealand’s ManageMyHealth patient portal was cited as exposing data from ~120,000 people, and was used to underscore governance, access control, and third-party oversight gaps as recurring drivers of healthcare-sector exposure.

Share:
Healthcare Sector Data Breach Disclosures Expand Victim Counts Across Multiple Incidents
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Feb 25, 20264mo ago

TriZetto updated breach total to 3.43 million people

TriZetto updated its report to Oregon's Department of Justice to state that 3,433,965 people were affected and filed breach notifications in multiple states. Some private medical providers and several states also publicly confirmed victim counts.

Conduent reported at least 25 million people affected

In a filing to Wisconsin regulators, Conduent said the breach affects at least 25 million people nationwide, a major increase from earlier state-level disclosures. Texas and Montana officials were also investigating impacts tied to Blue Cross Blue Shield members.

Oregon counties warned residents about TriZetto impact

County governments in Oregon previously warned that the TriZetto incident affected hundreds of thousands of residents whose data was exposed through the compromised portal.

Feb 24, 20264mo ago

ManageMyHealth breach exposed about 120,000 people

A breach of New Zealand's ManageMyHealth patient portal exposed sensitive information for roughly 120,000 people, making it one of the country's most significant healthcare privacy incidents.

Dec 1, 20257mo ago

TriZetto began notifying customers about the breach

TriZetto began notifying customers in December after investigating the incident with law enforcement and Mandiant.

Oct 1, 20259mo ago

TriZetto discovered its 2024 breach

TriZetto discovered the breach in October 2024, according to later reporting cited in the update on the incident.

Apr 1, 20251y ago

Conduent publicly disclosed the breach in an SEC filing

Conduent first publicly disclosed the hacking incident in an SEC filing in April 2025, before later state notifications expanded the known scale of impact.

Jan 13, 20251y ago

Conduent discovered the hacking incident

Conduent said it discovered the breach on 2025-01-13 and later determined the compromise had been ongoing since October 2024.

Nov 1, 20242y ago

TriZetto attacker began accessing historical eligibility reports

At TriZetto Provider Solutions, malicious activity began in November 2024 when an attacker accessed historical eligibility reports through a web portal, exposing data later described as including Social Security numbers, addresses, and health insurance numbers.

Oct 21, 20242y ago

Conduent systems were accessed without authorization

Conduent said attackers had unauthorized access to its servers from 2024-10-21 through 2025-01-13, potentially exposing sensitive personal and health-related data affecting patients nationwide.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Threat actors
2 linked
Affected products
1 linked
Discord
Organizations
16 linked
Change HealthcareDiscordUnitedHealth GroupVolvoConduentInformation Security Media GroupBlue Cross Blue Shield of MontanaCognizantHumanaThe Clorox CompanyXeroxPremera Blue CrossBlue Cross Blue ShieldTriZetto Provider SolutionsGoogleRansomware.live
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.