Were you recently affected by a data breach?

TriZetto Provider Solutions Data Breach

TriZetto Provider Solutions, a healthcare billing services company, has notified individuals that a cybersecurity incident exposed personal and health information tied to insurance eligibility verification records. Exposed data may include Social Security numbers and health insurance details. Affected individuals are being offered complimentary credit monitoring services.

TriZetto Provider Solutions
Date of Breach: Unauthorized access began November 2024; detected October 2, 2025; notification began December 9, 2025
CAU logo

Who was affected:

Clients of TriZetto Provider Solutions

Impacted Data:

Names, addresses, dates of birth, Social Security numbers, health insurance member numbers, provider names, health insurer names, primary insured information

TriZetto Provider Solutions, which provides billing-related services to healthcare providers across the country, has notified individuals that a cybersecurity incident may have exposed personal and health information tied to insurance eligibility verification records processed on their behalf.

Companies that process healthcare billing and insurance data on behalf of providers are entrusted with some of the most sensitive information that exists, and have a responsibility to protect that data and to notify affected individuals promptly when a security failure occurs.

TriZetto Provider Solutions’s Data Breach Investigation

TriZetto Provider Solutions (“TPS”), a Cognizant-owned company that provides billing-related services to healthcare providers such as hospitals, health systems, and physician practices, detected suspicious activity within a web portal used by some of its healthcare provider customers on October 2, 2025. TPS says it quickly launched an investigation, engaged outside cybersecurity specialists, and notified law enforcement upon discovering the incident.

That investigation determined that an unauthorized party had been accessing records related to insurance eligibility verification transactions beginning in November 2024, nearly a full year before the intrusion was detected. These transactions are processed by healthcare providers to confirm a patient’s insurance coverage before delivering treatment, meaning the exposed records could include sensitive health and insurance information tied to real patient encounters. TPS conducted a review of the affected data to determine what information was involved and which individuals needed to be notified, and began notifying affected healthcare provider customers on December 9, 2025.

TPS’s notice to Montana residents identifies at least 8,072 individuals in that state as affected, submitted through the Montana Department of Justice’s consumer notification process. TPS has stated that it is not currently aware of any confirmed identity theft or fraud resulting from the incident.

Healthcare billing and clearinghouse vendors occupy a uniquely sensitive position in the healthcare data ecosystem. Because they process transactions for many providers, insurers, and patients at once, a single company like TPS can end up holding records that touch millions of individual patient encounters, even though most of those patients have never directly interacted with the vendor itself. This concentration of data makes billing and eligibility-verification vendors an attractive target for cybercriminals, since successfully breaching one vendor’s systems can expose records tied to dozens or hundreds of separate healthcare providers in a single intrusion, rather than requiring an attacker to compromise each provider individually.

The eleven-month gap between when TPS says unauthorized access began, in November 2024, and when the activity was actually detected, in October 2025, is not unusual for this type of incident. Insurance eligibility verification systems generate enormous volumes of routine transaction traffic, which can make it difficult to distinguish unauthorized access from ordinary business activity until a security review or an external report calls attention to it. That extended dwell time, however, also means that any data accessed during the intrusion window may have been exposed for many months before affected individuals were notified.

The combination of data types TPS has flagged as potentially exposed, including Social Security numbers, dates of birth, and health insurance member numbers alongside demographic and health information, is particularly valuable to fraudsters because it can support both conventional identity theft and medical identity theft. A criminal in possession of a health insurance member number and matching personal details can potentially use that information to obtain medical services, prescriptions, or durable medical equipment in a victim’s name, or to submit fraudulent insurance claims. Because this type of fraud does not always show up on a standard credit report, it can go undetected for longer than a typical stolen credit card number, making the credit monitoring and fraud consultation services vendors like TPS offer an important, though not complete, safeguard for affected individuals.

Because TriZetto services providers across many different states, its notification obligations are governed by a patchwork of state data breach notification laws, each with its own timeline and required disclosures. The company’s approach of notifying its healthcare provider customers first, in December 2025, and following up with direct notices to affected individuals over the following months, is consistent with how many multi-state vendor breaches unfold, since providers often must be looped in before a vendor can accurately determine which of their specific patients were affected.

When Did This Breach Occur?

TriZetto Provider Solutions says an unauthorized party began accessing insurance eligibility verification records in November 2024. TPS detected suspicious activity within a customer web portal on October 2, 2025, and immediately began an investigation with outside cybersecurity specialists.

After completing its review, TPS began notifying affected healthcare provider customers on December 9, 2025. Individual notices, including the notice sent to Montana residents, followed in 2026 as TPS worked through the patchwork of state-specific notification requirements.

What Information Was Breached?

TriZetto has disclosed that the exposed information may include names, addresses, dates of birth, Social Security numbers, health insurance member numbers (which for some individuals may be a Medicare beneficiary identifier), provider names, health insurer names, primary insured information, and other demographic, health, and health insurance information.

TPS has stated that the incident did not affect any payment card, bank account, or other financial account information.

What You Can Do

TriZetto Provider Solutions is offering affected individuals complimentary Single Bureau Credit Monitoring, a Single Bureau Credit Report, and Single Bureau Credit Score services through Kroll, along with fraud consultation support. If you received a notice from TPS, consider taking the following steps:

  • Enroll in the complimentary Kroll credit monitoring services referenced in your notice letter.
  • Review your Explanation of Benefits statements from your health insurer for services you did not receive, which can indicate medical identity theft.
  • Regularly review your bank and credit card statements for unauthorized transactions.
  • Consider placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion.
  • Watch for phishing emails, calls, or texts referencing this breach or your healthcare provider.

File a Data Breach Lawsuit Against TriZetto Provider Solutions

If you received a notice from TriZetto Provider Solutions about this data breach, you may have legal options. An attorney can help you understand whether you are eligible to pursue compensation for the exposure of your personal and health information.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed; reported to the Texas Attorney General on August 22, 2025
Date of Breach: Not publicly disclosed; reported to the Texas Attorney General on August 22, 2025
Date of Breach: Not publicly disclosed; reported to the Texas Attorney General on August 19, 2025
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.