HackingSupply Chain (3P Vendor)Customer Data InvolvedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumContained
OLE Health
bd_8ced1e7888cb8531 · schema v1 · pii pii-v1
Full breach record for OLE Health →OLE Health (DBA CommuniCare + OLE) notified patients of a data security incident involving a third-party vendor, TriZetto, which works with their electronic medical record system (OCHIN). An unauthorized individual gained access to TriZetto's systems. Affected data may include names, social security numbers, dates of birth, contact information, and health/insurance information. The clinic was notified by OCHIN on December 15, 2025. No specific count of affected individuals was disclosed in the notice.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-617210
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 16, 2026
- Raw hash
- 66c599fb7212b9784b1661342e2a7bb1b76d2c82a0b65c616a22816bc005f1c3
Reporting entity
- Name
- OLE Healthnorm: ole health
Victim entity
- Name
- OLE Healthnorm: ole health
Incident
- Discovered
- Dec 15, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Third party
- via TriZetto
- Initial access
- supply_chain
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.