Were you recently affected by a data breach?

The Health Trust Data Breach

The Health Trust has notified individuals that files provided to its subsidiary FASS were involved in a cybersecurity incident detected in 2025, affecting certain personal information.

The Health Trust
Date of Breach: Unauthorized access prior to March 26, 2025 and June 8-11, 2025; notice submitted to CA AG August 24, 2026
CAU logo

Who was affected:

Clients of The Health Trust

Impacted Data:

Names; additional data types not fully specified in the public notice

The Health Trust has notified individuals that files provided to Financial Administrative Support Services (FASS), a related organization that handles finance and accounting services for The Health Trust and other nonprofits, were involved in a cybersecurity incident. Nonprofit organizations and their service providers that maintain sensitive personal records have a responsibility to protect that information from unauthorized access.

The Health Trust’s Data Breach Investigation

The Health Trust, a San Jose, California-based nonprofit that assists governmental and non-governmental organizations with providing services to individuals, says it identified suspicious activity on its computer network on May 26, 2025. In response, the organization took steps to secure its network and restore its systems. However, on June 11, 2025, further suspicious activity was identified. Upon discovering this second wave of activity, The Health Trust took its systems offline to secure them and investigate the scope of what had occurred.

According to The Health Trust’s notice, the resulting investigation determined that an unknown actor gained access to certain Health Trust systems prior to March 26, 2025, and then again between June 8, 2025, and June 11, 2025, and accessed and/or copied off certain information during that time. Notably, the organization states that the information involved in this event was contained in files provided to FASS, which provides finance and accounting services to The Health Trust and other organizations, and that there is no evidence that The Health Trust’s own internal client files were involved.

The Health Trust says it then conducted a thorough and comprehensive review of the impacted information to determine what data was involved and to whom it related. As part of its response, the organization reported the event to law enforcement and began notifying relevant regulators, including submitting a sample notification letter to the California Attorney General’s office dated August 24, 2026. The Health Trust states it is also reviewing its internal policies, procedures, and security tools in an effort to reduce the risk of a similar incident occurring in the future.

Incidents that occur through a third-party vendor or service provider, rather than directly through an organization’s own internal systems, are an increasingly common way sensitive information ends up exposed. Nonprofits and the organizations that provide back-office functions like accounting and finance for them, such as FASS in this case, often maintain files containing names and other personal details on the individuals those nonprofits serve. When such a vendor experiences unauthorized access, the individuals affected are often people who never directly interacted with the vendor itself, and may not realize a third-party relationship even existed until they receive a notification letter.

Data exposed in incidents like this one can enable a range of fraud, including identity theft, unauthorized account openings, and targeted phishing attempts that reference real personal details to appear more convincing. Consumers who receive breach notification letters should be especially cautious of follow-up communications claiming to be from the notifying organization or its credit monitoring vendor. The Health Trust’s own notice specifically states it has no evidence of any actual or attempted fraud or identity theft connected to this event to date, which is a common disclosure in early breach notifications and does not rule out that fraud attempts could still occur later using the exposed information.

The gap between when suspicious activity is first detected and when a fully verified list of affected individuals can be determined is common in incidents involving a forensic investigation of this scale. Here, The Health Trust identified suspicious activity in May and June of 2025 but did not complete the comprehensive review needed to identify specifically whose information was affected, and to notify those individuals, until well over a year later. This kind of timeline is not unusual for incidents requiring a detailed manual document review across potentially large volumes of files, particularly when, as here, the affected files were maintained by a separate service provider rather than the notifying organization’s own systems.

When Did This Breach Occur?

The Health Trust’s investigation determined that unauthorized access to certain systems occurred prior to March 26, 2025, and again between June 8, 2025, and June 11, 2025. The Health Trust states it first identified suspicious network activity on May 26, 2025, and identified further suspicious activity on June 11, 2025, at which point it took its systems offline. The organization’s sample notification letter to the California Attorney General is dated August 24, 2026.

What Information Was Breached?

The Health Trust’s notice confirms that the information identified in its review included affected individuals’ names, but the sample notice submitted to regulators does not specify the complete list of additional personal information categories involved. The Health Trust has not otherwise publicly disclosed the full extent of the information affected. Individuals who receive a direct notification letter from The Health Trust should review it carefully, as it may identify the specific categories of information involved in their individual case.

What You Can Do

The Health Trust is offering affected individuals complimentary credit monitoring services through IDX. Affected individuals should:

  • Enroll in the complimentary IDX credit monitoring services referenced in The Health Trust’s notification letter before the enrollment deadline.
  • Regularly review account statements and credit reports for unfamiliar or unauthorized activity.
  • Request free annual credit reports from Equifax, Experian, and TransUnion at annualcreditreport.com.
  • Consider placing a fraud alert or security freeze with the three major credit bureaus.
  • Report any suspected identity theft or fraud to local law enforcement and the Federal Trade Commission.

File a Data Breach Lawsuit Against The Health Trust

If you received a notice from The Health Trust about this data security incident, or if you believe your personal information may have been exposed through FASS, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Unauthorized access prior to March 26, 2025 and June 8-11, 2025; notice submitted to CA AG August 24, 2026
Date of Breach: May 20, 2025 (former employee access); notice submitted to CA AG August 21, 2026
Date of Breach: Reported to HHS OCR on July 31, 2026 (exact incident date not publicly disclosed)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.