The TriZetto Provider Solutions data breach, a subsidiary of Cognizant, compromised the personal and health information of approximately 3.43 million individuals. While suspicious activity was first flagged on October 2, 2025, a forensic investigation revealed that unauthorized access to its web portal actually began on November 19, 2024, remaining undetected for nearly a year.
Key Breach Details
- Data Compromised: Hackers accessed historical insurance eligibility verification reports. The exposed data includes full names, home addresses, dates of birth, Social Security numbers, Medicare Beneficiary numbers, and health insurance member IDs.
- Detection Delay: The breach lasted from late 2024 until its discovery in late 2025.
- Affected Clients: While TriZetto serves nearly 900,000 providers, confirmed impacted entities include Cascadia Health, Gardner Health Services, and the San Francisco Community Health Center.
Response and Legal Actions
- Protective Services: TriZetto is offering affected individuals complimentary credit monitoring and identity restoration services.
- Lawsuits: As of March 2026, Cognizant and TriZetto face nearly two dozen class-action lawsuits. Plaintiffs allege the companies were negligent in safeguarding data and failed to provide timely notification.
- Official Reporting: The incident was officially reported to the U.S. Department of Health and Human Services (HHS) on February 6, 2026.