HackingStolen CredentialsSupply Chain (3P Vendor)Business Associate (HIPAA)Customer Data InvolvedDelayed DiscoveryPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
LIFELONG MEDICAL CARE
bd_0aa3c63d661bbd3c · schema v1 · pii pii-v1
Full breach record for LIFELONG MEDICAL CARE →LifeLong Medical Care notified patients of a breach involving protected health information (PHI) accessed by an unauthorized actor via a TriZetto Provider Solutions web portal. The unauthorized access began in November 2024 and was discovered on October 2, 2025. Affected data included names, addresses, dates of birth, Social Security numbers, and health insurance information. LifeLong is working with its technical partner OCHIN and offering identity theft protection services.
California clockDiscovered Oct 2, 2025 → Notified Jan 14, 2026104d ✗ CA 60-day late15 weeks discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-617028
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 14, 2026
- Raw hash
- 4e497977ba7b21f067abe9fc6e81ef01dd5d1c762e0b01300e7c516d73ab2a15
Reporting entity
- Name
- LIFELONG MEDICAL CAREnorm: lifelong medical care
- Domain
- lifelongmedical.org
Victim entity
- Name
- LIFELONG MEDICAL CAREnorm: lifelong medical care
- Domain
- lifelongmedical.org
Incident
- Discovered
- Oct 2, 2025
- Materiality determined
- —
- Notification sent
- Jan 14, 2026
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified law enforcement
- Third party
- via TriZetto Provider Solutions
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 15 weeks(104 days from discovery to filing)
- Compliance flags
- CA 60-day late · 104dCA AG copy ≤15d · 0d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 2, 2025→ Notified: Jan 14, 2026104d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Jan 14, 2026→ AG copy submitted: Jan 14, 20260d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.