HackingSupply Chain (3P Vendor)Customer Data InvolvedPHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASICMediumContained
Petaluma Health Center
bd_9de0745dc22742d0 · schema v1 · pii pii-v1
Full breach record for Petaluma Health Center →Petaluma Health Center notified patients of a data breach involving a third-party vendor, TriZetto, which works with their electronic medical record system (OCHIN). An unauthorized individual gained access to TriZetto's systems. Affected data may include names, social security numbers, dates of birth, contact information, and health/insurance information. The clinic was notified by OCHIN on December 15, 2025. TriZetto engaged Kroll for notification and identity theft protection services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-617350
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 20, 2026
- Raw hash
- bf3c85808a570521d357e38789da75567ab3049728d72bef2e3b29db63071006
Reporting entity
- Name
- Petaluma Health Centernorm: petaluma health center
Victim entity
- Name
- Petaluma Health Centernorm: petaluma health center
Incident
- Discovered
- Dec 15, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_GOVERNMENTIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via TriZetto
- Initial access
- supply_chain
Compliance
- Time to disclose
- 5 weeks(36 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.