TriZetto Provider Solutions
bd_d731ae63f6528c4a · schema v1 · pii pii-v1
Full breach record for TriZetto Provider Solutions →TriZetto Provider Solutions (TPS) disclosed a security incident affecting its healthcare provider customers, including OCHIN. The breach occurred on November 1, 2024, but was discovered on October 2, 2025, when suspicious activity was detected. TPS contained the incident by disabling affected users and IPs. An investigation by Mandiant confirmed the vulnerability was remediated. TPS is offering identity monitoring services to affected individuals and assisting providers with regulatory notifications to OCR and state Attorneys General. The incident involved unauthorized access to protected health information.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_19390dc3934af63cHHS OCRfiled 2026-02-06(52d gap)Verified
- bd_32b4937e7011ae89Montana State AGfiled 2026-02-06(52d gap)Verified
- bd_42e0b818cf987cd0Indiana State AGfiled 2026-02-06(52d gap)Verified
- bd_7d1e2d4a707b8526Vermont State AGfiled 2026-02-06(52d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 79d gap
- bd_9500e811026457a4Washington State AGfiled 2026-02-06(52d gap)Verified
- bd_3dcd151ab202765fTexas State AGfiled 2026-02-09(55d gap)Verified
- bd_5af0053e3e0d5c36Oregon State AGfiled 2026-02-11(57d gap)Verified
- bd_d8d072b04feca193New Hampshire State AGfiled 2026-02-11(57d gap)Verified
- bd_eb48dcb214315d16South Carolina State AGfiled 2026-02-20(66d gap)Verified by operator
- bd_9e9cfe5bca10e718Maine State AGfiled 2026-03-05(79d gap)Verified
Showing first 10 of 13 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-615860
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 16, 2025
- Raw hash
- 73971ac595b9398cb46f0ad293009a25a18ae93a759de729374128bb79b8ea13
Reporting entity
- Name
- Friends of Family Health Centernorm: friends of family health center
Victim entity
- Name
- TriZetto Provider Solutionsnorm: trizetto provider
- Domain
- trizettoprovider.com
Incident
- Discovered
- Oct 2, 2025
- Materiality determined
- —
- Notification sent
- Jan 5, 2026
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Offering to notify the U.S. Department of Health and Human Services Office for Civil Rights (OCR)Offering to notify certain state Attorneys General and privacy regulatorsOffering to notify prominent media outlets on behalf of affected providers
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 11 weeks(75 days from discovery to filing)
- Compliance flags
- CA 60-day late · 95dCA AG copy ≤15d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Oct 2, 2025→ Notified: Jan 5, 202695d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Jan 5, 2026→ AG copy submitted: Dec 16, 2025— 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.