HackingSupply Chain (3P Vendor)Business Associate (HIPAA)Customer Data InvolvedDelayed DiscoveryPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Planned Parenthood Northern California
bd_c72bc64c2dca9d4e · schema v1 · pii pii-v1
Full breach record for Planned Parenthood Northern California →Planned Parenthood Northern California notified patients of a data breach involving a third-party subcontractor, Trizetto Provider Solutions. Unauthorized access to patient insurance eligibility and related information occurred between November 2024 and October 2, 2025. The organization was notified by its business associate, OCHIN, on December 10, 2025. Affected data included names, dates of birth, Social Security numbers, and health insurance information. Credit monitoring services are being offered to affected individuals.
California clockDiscovered Dec 10, 2025 → Notified Dec 24, 202514d ✓ CA 60-day OK20 days discovery → filing
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-616419
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 30, 2025
- Raw hash
- e21f69251a9a9bc2aacc128867799c0d38250295736c1a53e4517d598434f148
Reporting entity
- Name
- Planned Parenthood Northern Californianorm: planned parenthood northern california
- Domain
- ppnorcal.org
Victim entity
- Name
- Planned Parenthood Northern Californianorm: planned parenthood northern california
- Domain
- ppnorcal.org
Incident
- Discovered
- Dec 10, 2025
- Materiality determined
- —
- Notification sent
- Dec 24, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1195 Supply Chain Compromise
- Threat actor
- External
- Third party
- via Trizetto Provider Solutions
- Initial access
- supply_chain
Compliance
- Time to disclose
- 20 days(20 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 14d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 10, 2025→ Notified: Dec 24, 202514d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.