DisclosureLens
HackingHealthcareHealthcareSupply Chain (3P Vendor)Customer Data InvolvedPHIGovernment IDIdentity (basic)Health (basic)MediumContained

Winters Healthcare

bd_44b716a170f9de05 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Dec 15, 2025

Filed

Jan 20, 2026

To disclose

5 weeks

Affected

Not disclosed

Confidence

66%
Full breach record for Winters Healthcare →

Winters Healthcare notified patients of a data security incident involving a third-party vendor, TriZetto, which works with their electronic medical record system (OCHIN). An unauthorized individual gained access to TriZetto's systems. The breach may have exposed sensitive personal information including names, social security numbers, dates of birth, contact information, and health-related or insurance information. Winters Healthcare was notified by OCHIN on December 15, 2025. The organization is working with OCHIN to ensure security measures are in place and reviewing its own processes.

Incident timeline

undetected · 440 days
discovery → filing · 5 weeks / 36 days

Oct 1, 2024

Begins

Dec 15, 2025

Discovered

Jan 20, 2026

Filed

vs. sector median

4 wks faster

Part of TriZetto Provider Solutions supply-chain incident (2025) — a supply-chain cascade affecting multiple organizations.View cascade →
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.