Virta Health Corp. notified the California AG of a security incident where unauthorized activity was identified on March 24, 2026, in a data repository separate from the production platform. The incident involved potential access to files between March 19 and March 22, 2026. Exposed data included names, Social Security numbers, dates of birth, and medical information (diagnoses, treatments, record numbers). Virta engaged external cybersecurity experts, notified law enforcement, and is offering 12 months of complimentary credit monitoring and fraud assistance to affected individuals. No indication of misuse was found.