The Health Trust has notified individuals that files provided to Financial Administrative Support Services (FASS), a related organization that handles finance and accounting services for The Health Trust and other nonprofits, were involved in a cybersecurity incident. Nonprofit organizations and their service providers that maintain sensitive personal records have a responsibility to protect that information from unauthorized access.
The Health Trust’s Data Breach Investigation
The Health Trust, a San Jose, California-based nonprofit that assists governmental and non-governmental organizations with providing services to individuals, says it identified suspicious activity on its computer network on May 26, 2025. In response, the organization took steps to secure its network and restore its systems. However, on June 11, 2025, further suspicious activity was identified. Upon discovering this second wave of activity, The Health Trust took its systems offline to secure them and investigate the scope of what had occurred.
According to The Health Trust’s notice, the resulting investigation determined that an unknown actor gained access to certain Health Trust systems prior to March 26, 2025, and then again between June 8, 2025, and June 11, 2025, and accessed and/or copied off certain information during that time. Notably, the organization states that the information involved in this event was contained in files provided to FASS, which provides finance and accounting services to The Health Trust and other organizations, and that there is no evidence that The Health Trust’s own internal client files were involved.
The Health Trust says it then conducted a thorough and comprehensive review of the impacted information to determine what data was involved and to whom it related. As part of its response, the organization reported the event to law enforcement and began notifying relevant regulators, including submitting a sample notification letter to the California Attorney General’s office dated August 24, 2026. The Health Trust states it is also reviewing its internal policies, procedures, and security tools in an effort to reduce the risk of a similar incident occurring in the future.
Incidents that occur through a third-party vendor or service provider, rather than directly through an organization’s own internal systems, are an increasingly common way sensitive information ends up exposed. Nonprofits and the organizations that provide back-office functions like accounting and finance for them, such as FASS in this case, often maintain files containing names and other personal details on the individuals those nonprofits serve. When such a vendor experiences unauthorized access, the individuals affected are often people who never directly interacted with the vendor itself, and may not realize a third-party relationship even existed until they receive a notification letter.
Data exposed in incidents like this one can enable a range of fraud, including identity theft, unauthorized account openings, and targeted phishing attempts that reference real personal details to appear more convincing. Consumers who receive breach notification letters should be especially cautious of follow-up communications claiming to be from the notifying organization or its credit monitoring vendor. The Health Trust’s own notice specifically states it has no evidence of any actual or attempted fraud or identity theft connected to this event to date, which is a common disclosure in early breach notifications and does not rule out that fraud attempts could still occur later using the exposed information.
The gap between when suspicious activity is first detected and when a fully verified list of affected individuals can be determined is common in incidents involving a forensic investigation of this scale. Here, The Health Trust identified suspicious activity in May and June of 2025 but did not complete the comprehensive review needed to identify specifically whose information was affected, and to notify those individuals, until well over a year later. This kind of timeline is not unusual for incidents requiring a detailed manual document review across potentially large volumes of files, particularly when, as here, the affected files were maintained by a separate service provider rather than the notifying organization’s own systems.
When Did This Breach Occur?
The Health Trust’s investigation determined that unauthorized access to certain systems occurred prior to March 26, 2025, and again between June 8, 2025, and June 11, 2025. The Health Trust states it first identified suspicious network activity on May 26, 2025, and identified further suspicious activity on June 11, 2025, at which point it took its systems offline. The organization’s sample notification letter to the California Attorney General is dated August 24, 2026.
What Information Was Breached?
The Health Trust’s notice confirms that the information identified in its review included affected individuals’ names, but the sample notice submitted to regulators does not specify the complete list of additional personal information categories involved. The Health Trust has not otherwise publicly disclosed the full extent of the information affected. Individuals who receive a direct notification letter from The Health Trust should review it carefully, as it may identify the specific categories of information involved in their individual case.
What You Can Do
The Health Trust is offering affected individuals complimentary credit monitoring services through IDX. Affected individuals should:
- Enroll in the complimentary IDX credit monitoring services referenced in The Health Trust’s notification letter before the enrollment deadline.
- Regularly review account statements and credit reports for unfamiliar or unauthorized activity.
- Request free annual credit reports from Equifax, Experian, and TransUnion at annualcreditreport.com.
- Consider placing a fraud alert or security freeze with the three major credit bureaus.
- Report any suspected identity theft or fraud to local law enforcement and the Federal Trade Commission.
File a Data Breach Lawsuit Against The Health Trust
If you received a notice from The Health Trust about this data security incident, or if you believe your personal information may have been exposed through FASS, you may have legal options available to you.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.