Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Unauthorized access exposed insurance-eligibility verification records through a web portal used by some TriZetto Provider Solutions healthcare-provider customers. [1][2]
Impact
Potential exposure of patient and primary-insured demographic, health, and insurance information. [1][4][5]
Documented data types include:
- Health insurance information [1]
- Names [1]
- Clinical information — Other demographic and health information may have been involved; categories varied by individual. [1]
- Social Security numbers [1]
- Dates of birth [1]
- Contact information [1]
A cited record reports 312,562 individuals (Texas residents according to report BR-0005084; not a national total; as of 2026-06-02). [1][4][5]
A cited record reports 48,857 individuals (Massachusetts residents according to incident 2026-202; not a national total; as of 2026-02-11). [1][4][5]
A cited record reports 3,433,965 individuals (Individuals in the HHS OCR report; regulator-reported and not independently verified; as of 2026-08-08). [1][4][5]
A cited record reports 6,974,232 individuals (Total individuals affected according to Texas report BR-0005084; this conflicts with the HHS OCR count and is retained separately; as of 2026-06-02). [1][4][5]
TriZetto says payment-card, bank-account, and other financial information were not affected. [1]
TriZetto says an unauthorized actor accessed records related to insurance-eligibility verification transactions; it does not identify the actor or access method. [1]
TriZetto said it was not aware of identity theft or fraud related to affected information at the time of notice. [1]
Timeline
Activity began
Start date listed by the California and Texas regulator records; TriZetto’s notice describes the start only as November 2024.
[2]Discovery
Date TriZetto says it became aware of suspicious portal activity.
[1]Documented activity ended
End date listed by the California and Texas regulator records and date suspicious activity was discovered.
[2]Documented event
Date the California sample notice says TriZetto learned what categories the affected data may have included.
[3]Documented event
Date TriZetto says it began notifying affected healthcare providers and offering to notify on their behalf.
[1]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
TriZetto offered Kroll identity monitoring, credit monitoring, fraud consultation, and identity-theft restoration services. TriZetto says it mitigated the issue, engaged external experts, notified law enforcement, and implemented additional security protocols. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]
