TriZetto Breach Exposes 3.4M Health Records

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- TriZetto confirmed that hackers stole personal and health data of more than 3.4 million people, filing the disclosure with Maine's attorney general on Friday
- The stolen records include patients' names, dates of birth, home addresses, Social Security numbers, and healthcare/insurance details, lifted from insurance eligibility transaction reports
- TriZetto identified the breach on October 2, 2025, then discovered hackers had access as far back as November 2024 — an 11-month detection gap
- Cognizant spokesperson William Abelson said the company "eliminated the threat" but declined to explain why the intrusion took nearly a year to detect
- OCHIN, a nonprofit serving roughly 300 rural and community care providers, and healthcare providers in California confirmed their patients' data was among the compromised records
- The breach follows the 2024 Change Healthcare ransomware attack, which compromised over 192 million patient files and disrupted medical access across the U.S.
Why it matters: TriZetto serves roughly 200 million people across 875,000 healthcare providers, so a breach at a single clearinghouse can cascade to thousands of practices. The 11-month window — which Cognizant won't explain — means 3.4 million patients' Social Security numbers and medical details sat exposed and unaddressed for nearly a year, a timeline that typically drives class-action litigation and regulatory scrutiny.
Ask SkimNews




