Clustered 14 filings across 11 jurisdictions · filing window Dec 16, 2025 → Mar 5, 2026. View entity profile → Other incidents for this victim →
incident inc_f12d6ef3cf624f9b · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
PHI · PII
CA IN ME MO MT NH OR SC
HHS OCR · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
14 filings across 11 jurisdictions · Dec 16, 2025 – Mar 5, 2026 · 3 milestones
Nov 1, 2024
When the intrusion reportedly occurred, per the linked filings
Oct 2, 2025
Reported by CALIFORNIA AG, WASHINGTON AG, NEW HAMPSHIRE AG filings
Nov 28, 2025
Reported by TEXAS AG, MAINE AG filings
TriZetto Provider Solutions reported to HHS on 2026-02-06 a Hacking/IT Incident affecting 3433965 individuals. Breached information located on Network Server. Business Associate present.
Affected (this filing): 3,433,965
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
TriZetto Provider Solutions (TPS) disclosed a security incident affecting its healthcare provider customers, including OCHIN. The breach occurred on November 1, 2024, but was discovered on October 2, 2025, when suspicious activity was detected. TPS contained the incident by disabling affected users and IPs. An investigation by Mandiant confirmed the vulnerability was remediated. TPS is offering identity monitoring services to affected individuals and assisting providers with regulatory notifications to OCR and state Attorneys General. The incident involved unauthorized access to protected health information.
Open Door Community Health Centers notified patients of a data security incident involving their vendor, TriZetto Provider Solutions. An unauthorized third party accessed TriZetto's network on or about November 2024; TriZetto discovered the incident on October 2, 2025, and contained it on the same day. Affected data includes names, addresses, dates of birth, SSNs, and health insurance information. TriZetto engaged cybersecurity experts, notified law enforcement, and is offering 12 months of credit monitoring.
Asian Americans for Community Involvement (AACI) notified patients that their protected health information may have been accessed by an unauthorized actor via a third-party vendor, Trizetto Provider Solutions (TPS). The breach occurred between November 2024 and October 2, 2025, when TPS became aware of suspicious activity on its web portal. Affected data includes names, addresses, dates of birth, Social Security numbers, and health insurance information. TPS engaged Mandiant for investigation, contained the threat, and is offering 12 months of credit monitoring through Kroll.
TriZetto Provider Solutions reported a data breach to the Montana Attorney General. The breach was reported on 2026-02-06. The breach occurred from 11/01/2024 to 11/30/2024. 8,072 Montana residents were affected.
Affected (this filing): 8,072
TriZetto Provider Solutions reported a data breach to the Indiana Attorney General. The breach occurred on 2025-10-02 and was reported on 2026-02-06. 7,155 Indiana residents were affected. 3,433,965 individuals affected in total.
Affected (this filing): 3,433,965
TriZetto Provider Solutions notified consumers in multiple states, including Vermont, of a data breach involving unauthorized access to personal information. Affected data included names, addresses, and government IDs. The company offered identity monitoring services and established a call center for inquiries. No evidence of identity theft was found at the time of notification.
TriZetto Provider Solutions, a health sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2025-10-02 and filed notice on 2026-02-06. 44,985 Washington residents were affected. 127 days elapsed between awareness and notification. 317 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 44,985
TriZetto Provider Solutions reported a data breach to the Indiana Attorney General. The breach occurred on 2025-10-02 and was reported on 2026-02-06. 7,155 Indiana residents were affected. 3,433,965 individuals affected in total.
Affected (this filing): 3,433,965
TriZetto Provider Solutions based in Earth City, Missouri, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-11-28 and reported on 2026-02-09. 171,158 Texas residents were affected. 3,433,965 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
Affected (this filing): 171,158
TriZetto Provider Solutions reported a data breach to the Oregon Attorney General. The breach was reported on 2026-02-11. The breach occurred during 11/19/2024. The breach was discovered on 1/1/000111/28/2025. 3,433,965 individuals were affected. Notice was sent on 1/1/0001.
Affected (this filing): 3,433,965
TriZetto Provider Solutions (TPS) notified the New Hampshire Attorney General of a security incident involving unauthorized access to a web portal used by healthcare providers. TPS became aware of suspicious activity on October 2, 2025, and determined that an unauthorized actor accessed historical eligibility transaction reports containing PHI and PII (names, SSNs, DOB) starting November 2024. TPS engaged Mandiant, contained the threat, and notified approximately 1,795 New Hampshire residents. Remediation included portal security review and offering 12 months of credit monitoring.
Affected (this filing): 1,795
TriZetto Provider Solutions issued a consumer breach notification to South Carolina residents regarding unauthorized access to personal information. The company offered identity monitoring services and established a call center for affected individuals. No evidence of identity theft or fraud was found at the time of notification.
TriZetto Provider Solutions, a healthcare technology company, reported an external system breach (hacking) that occurred on November 19, 2024 and was discovered on November 28, 2025 — approximately one year later. A total of 3,433,965 individuals were affected nationwide, including 1,128 Maine residents. Affected individuals were notified on February 6, 2026. Kroll provided 12 months of single-bureau credit monitoring and identity protection services.
Affected (this filing): 1,128