One Community Health
ent_44f38f1c1864f3109168c9e6
Disclosures
8
State AG · HHS OCR · Leak Site · 6 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
39,865
as filed · State AG OR
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- One Community Health
- Normalized
- one community health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- 🐻California State AGas victim2026-01-08
One Community Health notified patients of a security incident involving its third-party clearinghouse, TriZetto Provider Solutions. An unauthorized individual accessed historical eligibility transaction reports containing PHI (including SSNs and health insurance info) between November 2024 and October 2, 2025. TriZetto discovered the activity on October 2, 2025, engaged Mandiant, and contained the threat. No payment card data was involved. Credit monitoring is being offered.
- FEDERALHHS OCRas victim2026-01-02
The covered entity (CE), One Community Health, reported that a subcontractor of its business associate (BA) experienced a hacking incident that compromised the protected health information (PHI) of 4,309 individuals. The PHI involved included demographic and clinical information. The CE notified HHS, affected individuals, the media, and published substitute notice on its website. The subcontractor notified law enforcement. OCR provided technical assistance regarding the HIPAA Breach Notification Rule.
- 🐻California State AGas victim2021-11-22
One Community Health experienced a ransomware attack between April 19-20, 2021. The incident resulted in the exfiltration of patient data, including Social Security numbers, names, dates of birth, addresses, and health information. The organization isolated affected systems, engaged cybersecurity experts, and offered one year of credit monitoring to affected individuals. No identity fraud was reported.
- 🌲Washington State AGas victim2021-11-22
One Community Health, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2021-04-19 and filed notice on 2021-11-22. 7,945 Washington residents were affected. 217 days elapsed between awareness and notification. 0 days to identify the breach. 1 days to contain the breach.
- 🦫Oregon State AGas victim2021-11-22
One Community Health reported a data breach to the Oregon Attorney General. The breach was reported on 2021-11-22. The breach occurred during 4/19/2021 - 4/20/2021. The breach was discovered on 10/6/2021. 39,865 individuals were affected. Notice was sent on 11/22/2021.
- OREGONHHS OCRas victim2021-11-22
One Community Health (Oregon) reported to HHS OCR on 2021-11-22 a Hacking/IT Incident affecting 39,865 individuals. A cybersecurity attack compromised PHI stored on a Network Server, including names, dates of birth, driver's license numbers, Social Security numbers, diagnoses, and other treatment information. The CE notified HHS, affected individuals, and the media, and implemented additional administrative and technical safeguards in response.
- 🦬Montana State AGas victim2021-11-22
One Community Health reported a data breach to the Montana Attorney General. The breach was reported on 2021-11-22. The breach occurred from 4/19/2021 to 4/20/2021. 19 Montana residents were affected.
- GLOBALLeak Siteas victim2021-09-13