TriZetto Provider Solutions
bd_d8d072b04feca193 · schema v1 · pii pii-v1
Full breach record for TriZetto Provider Solutions →4 incidents on fileTriZetto Provider Solutions (TPS) notified the New Hampshire Attorney General of a security incident involving unauthorized access to a web portal used by healthcare providers. TPS became aware of suspicious activity on October 2, 2025, and determined that an unauthorized actor accessed historical eligibility transaction reports containing PHI and PII (names, SSNs, DOB) starting November 2024. TPS engaged Mandiant, contained the threat, and notified approximately 1,795 New Hampshire residents. Remediation included portal security review and offering 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 1, 2024
Begins
Oct 2, 2025
Discovered
Feb 11, 2026
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- California State AGbd_6134d3c7272644722026-02-11Verified by operator
- Massachusetts State AGbd_c3aa17f3ff0b12182026-02-11Verified
- Texas State AGbd_3dcd151ab202765f2026-02-09 · +2dVerified
- HHS OCRbd_19390dc3934af63c2026-02-06 · +5dVerified
Show 6 more filings ↓Show fewer ↑up to 22d gap
- Montana State AGbd_32b4937e7011ae892026-02-06 · +5dVerified
- Nebraska State AGbd_3982aaa97bcc57b02026-02-06 · +5dVerified by operator
- Indiana State AGbd_42e0b818cf987cd02026-02-06 · +5dVerified
- Vermont State AGbd_7d1e2d4a707b85262026-02-06 · +5dVerified
- South Carolina State AGbd_eb48dcb214315d162026-02-20 · +9dVerified by operator
- Maine State AGbd_9e9cfe5bca10e7182026-03-05 · +22dVerified
Showing first 10 of 12 linked disclosures.
Filing propagation · 11 filings · 11 states
View merged incident ↗Pattern: first filing Feb 6 (MO), last Mar 5 (ME) — a 27-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 12 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.