TriZetto Provider Solutions
bd_c899572e8d27d67f · schema v1 · pii pii-v1
Full breach record for TriZetto Provider Solutions →Asian Americans for Community Involvement (AACI) notified patients that their protected health information may have been accessed by an unauthorized actor via a third-party vendor, Trizetto Provider Solutions (TPS). The breach occurred between November 2024 and October 2, 2025, when TPS became aware of suspicious activity on its web portal. Affected data includes names, addresses, dates of birth, Social Security numbers, and health insurance information. TPS engaged Mandiant for investigation, contained the threat, and is offering 12 months of credit monitoring through Kroll.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_19390dc3934af63cHHS OCRfiled 2026-02-06(21d gap)Verified
- bd_32b4937e7011ae89Montana State AGfiled 2026-02-06(21d gap)Verified
- bd_42e0b818cf987cd0Indiana State AGfiled 2026-02-06(21d gap)Verified
- bd_7d1e2d4a707b8526Vermont State AGfiled 2026-02-06(21d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 48d gap
- bd_9500e811026457a4Washington State AGfiled 2026-02-06(21d gap)Verified
- bd_3dcd151ab202765fTexas State AGfiled 2026-02-09(24d gap)Verified
- bd_5af0053e3e0d5c36Oregon State AGfiled 2026-02-11(26d gap)Verified
- bd_d8d072b04feca193New Hampshire State AGfiled 2026-02-11(26d gap)Verified
- bd_eb48dcb214315d16South Carolina State AGfiled 2026-02-20(35d gap)Verified by operator
- bd_9e9cfe5bca10e718Maine State AGfiled 2026-03-05(48d gap)Verified
Showing first 10 of 13 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-617142
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 16, 2026
- Raw hash
- adb76a8ca5f8a61a373ad6a10b1d70ee5d77fbaa421b3fb109ef759b016ae9ee
Reporting entity
- Name
- Asian Americans for Community Involvementnorm: asian americans for community involvement
- Domain
- aaci.org
Victim entity
- Name
- TriZetto Provider Solutionsnorm: trizetto provider
- Domain
- trizettoprovider.com
Incident
- Discovered
- Oct 2, 2025
- Materiality determined
- —
- Notification sent
- Dec 24, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via Trizetto Provider Solutions
Compliance
- Time to disclose
- 15 weeks(106 days from discovery to filing)
- Compliance flags
- CA 60-day late · 83d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 2, 2025→ Notified: Dec 24, 202583d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.