DisclosureLens
HackingHealthcareHealthcareSupply Chain (3P Vendor)Customer Data InvolvedDelayed DiscoveryPHIIdentity (basic)Government IDHealth (basic)MediumContained

Open Door Community Health Centers

bd_23ee99883ba7111c · schema v1 · pii pii-v1

Severity

Medium

Discovered

Oct 2, 2025

Filed

Jan 8, 2026

To disclose

14 weeks

Affected

Not disclosed

Confidence

66%
Full breach record for Open Door Community Health Centers2 incidents on file

Open Door Community Health Centers notified patients of a data security incident involving their vendor, TriZetto Provider Solutions. An unauthorized third party accessed TriZetto's network on or about November 2024; TriZetto discovered the incident on October 2, 2025, and contained it on the same day. Affected data includes names, addresses, dates of birth, SSNs, and health insurance information. TriZetto engaged cybersecurity experts, notified law enforcement, and is offering 12 months of credit monitoring.

California clockDiscovered Oct 2, 2025Notified Jan 7, 202697d CA 60-day late14 weeks discovery → filing

Incident timeline

undetected · 335 days
discovery → filing · 14 weeks / 98 days

Nov 1, 2024

Begins

Oct 2, 2025

Discovered

Jan 8, 2026

Filed

vs. sector median

+1 wks slower

Part of TriZetto Provider Solutions supply-chain incident (2025) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.