---
title: "TriZetto Provider Solutions portal data incident"
description: "Evidence-backed account of TriZetto Provider Solutions portal data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/trizetto-provider-solutions-portal-data-incident-2024"
markdown_url: "https://www.ally.security/incidents/trizetto-provider-solutions-portal-data-incident-2024.md"
stix_url: "https://www.ally.security/incidents/trizetto-provider-solutions-portal-data-incident-2024/stix.json"
---

# TriZetto Provider Solutions portal data incident

Unauthorized access to insurance-eligibility verification records through a web portal used by some TriZetto healthcare-provider customers. Potential exposure of patient and primary-insured demographic, health, and insurance information.

Last modified Aug 9, 2026 · 6 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access exposed insurance-eligibility verification records through a web portal used by some [TriZetto Provider Solutions](https://tpsincident.kroll.com/) healthcare-provider customers. [1](#source-1) [2](#source-2)

## Impact

Potential exposure of patient and primary-insured demographic, health, and insurance information. [1](#source-1) [4](#source-4) [5](#source-5)

Documented data types include:

- Health insurance information [1](#source-1)
- Names [1](#source-1)
- Clinical information — Other demographic and health information may have been involved; categories varied by individual. [1](#source-1)
- Social Security numbers [1](#source-1)
- Dates of birth [1](#source-1)
- Contact information [1](#source-1)

A cited record reports 312,562 individuals (Texas residents according to report BR-0005084; not a national total; as of 2026-06-02). [1](#source-1) [4](#source-4) [5](#source-5)

A cited record reports 48,857 individuals (Massachusetts residents according to incident 2026-202; not a national total; as of 2026-02-11). [1](#source-1) [4](#source-4) [5](#source-5)

A cited record reports 3,433,965 individuals (Individuals in the HHS OCR report; regulator-reported and not independently verified; as of 2026-08-08). [1](#source-1) [4](#source-4) [5](#source-5)

A cited record reports 6,974,232 individuals (Total individuals affected according to Texas report BR-0005084; this conflicts with the HHS OCR count and is retained separately; as of 2026-06-02). [1](#source-1) [4](#source-4) [5](#source-5)

TriZetto says payment-card, bank-account, and other financial information were not affected. [1](#source-1)

TriZetto says an unauthorized actor accessed records related to insurance-eligibility verification transactions; it does not identify the actor or access method. [1](#source-1)

TriZetto said it was not aware of identity theft or fraud related to affected information at the time of notice. [1](#source-1)

## Timeline

### November 19, 2024 — Activity began

Start date listed by the California and Texas regulator records; TriZetto's notice describes the start only as November 2024. [2](#source-2)

### October 2, 2025 — Discovery

Date TriZetto says it became aware of suspicious portal activity. [1](#source-1)

### October 2, 2025 — Documented activity ended

End date listed by the California and Texas regulator records and date suspicious activity was discovered. [2](#source-2)

### November 28, 2025 — Documented event

Date the California sample notice says TriZetto learned what categories the affected data may have included. [3](#source-3)

### December 9, 2025 — Documented event

Date TriZetto says it began notifying affected healthcare providers and offering to notify on their behalf. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

TriZetto offered Kroll identity monitoring, credit monitoring, fraud consultation, and identity-theft restoration services. TriZetto says it mitigated the issue, engaged external experts, notified law enforcement, and implemented additional security protocols. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/trizetto-provider-solutions-portal-data-incident-2024/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Notice of Data Breach — hosted incident center

official · TriZetto Provider Solutions

<https://tpsincident.kroll.com/>

<a id="source-2"></a>

### Submitted breach notification sample — TriZetto Provider Solutions

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-618547>

<a id="source-3"></a>

### TriZetto Provider Solutions notice of data breach — California sample

official · TriZetto Provider Solutions

<https://oag.ca.gov/system/files/ELN-25764%20Sample%20TPS%20Adult%20Notification%20Letter.pdf>

<a id="source-4"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-5"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<a id="source-6"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Individual Count · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: 312,562 individual
2. **Resulted In · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: TriZetto says payment-card, bank-account, and other financial information were not affected.
3. **Resulted In · 100% confidence · current**  
   2024–2025 TriZetto provider-portal incident: TriZetto provider and affected-individual notifications
4. **Affected Individual Count · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: 48,857 individual
5. **Affected Organization · 100% confidence · current**  
   2024–2025 TriZetto provider-portal incident: TriZetto Provider Solutions
6. **Exposed Data Category · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: Health insurance information
7. **Exposed Data Category · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: Names
8. **Discovered At · 100% confidence · current**  
   2024–2025 TriZetto provider-portal incident: 2025-10-02
9. **Affected Individual Count · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: 3,433,965 individual
10. **Resulted In · 100% confidence · current**  
   TriZetto provider and affected-individual notifications: TriZetto offered Kroll identity monitoring, credit monitoring, fraud consultation, and identity-theft restoration services.
11. **Occurred At · 100% confidence · current**  
   TriZetto provider and affected-individual notifications: 2025-12-09
12. **Began At · 100% confidence · current**  
   2024–2025 TriZetto provider-portal incident: 2024-11-19
13. **Resulted In · 100% confidence · current**  
   2024–2025 TriZetto provider-portal incident: TriZetto says an unauthorized actor accessed records related to insurance-eligibility verification transactions; it does not identify the actor or access method.
14. **Exposed Data Category · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: Clinical information
15. **Occurred At · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: 2025-11-28
16. **Resulted In · 100% confidence · current**  
   2024–2025 TriZetto provider-portal incident: TriZetto insurance-eligibility data exposure
17. **Resulted In · 100% confidence · current**  
   TriZetto provider and affected-individual notifications: TriZetto said it was not aware of identity theft or fraud related to affected information at the time of notice.
18. **Resulted In · 100% confidence · current**  
   2024–2025 TriZetto provider-portal incident: TriZetto says it mitigated the issue, engaged external experts, notified law enforcement, and implemented additional security protocols.
19. **Exposed Data Category · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: Social Security numbers
20. **Exposed Data Category · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: Dates of birth
21. **Ended At · 100% confidence · current**  
   2024–2025 TriZetto provider-portal incident: 2025-10-02
22. **Exposed Data Category · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: Contact information
23. **Affected Individual Count · 100% confidence · current**  
   TriZetto insurance-eligibility data exposure: 6,974,232 individual

</details>
