HackingSupply Chain (3P Vendor)Customer Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Axis Community Health
bd_ef58f141a6520d0d · schema v1 · pii pii-v1
Full breach record for Axis Community Health →Axis Community Health notified patients that their protected health information may have been compromised due to a data breach at Trizetto Provider Solutions (TPS), a third-party revenue management vendor. The breach occurred between November 1, 2024, and October 2, 2025. Axis discovered the impact on December 15, 2025. Affected data includes names, addresses, dates of birth, Social Security numbers, and health insurance information. No payment card or bank account data was involved. TPS engaged cybersecurity experts and notified law enforcement.
California clockDiscovered Dec 15, 2025 → Notified Dec 30, 202515d ✓ CA 60-day OK5 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_6d1334c29fc9c50fHHS OCRfiled 2026-01-16Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-617146
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 16, 2026
- Raw hash
- e7c43df8cf411f8878319de6388782149f504a7f1cdc337528d584055f2e813f
Reporting entity
- Name
- Axis Community Healthnorm: axis community health
Victim entity
- Name
- Axis Community Healthnorm: axis community health
Incident
- Discovered
- Dec 15, 2025
- Materiality determined
- —
- Notification sent
- Dec 30, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Third-Party / Supply Chain
- Threat actor
- External
- Third party
- via Trizetto Provider Solutions
Compliance
- Time to disclose
- 5 weeks(32 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 15d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 15, 2025→ Notified: Dec 30, 202515d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.