Were you recently affected by a data breach?

zHealth EHR Data Breach

zHealth EHR, a cloud-based practice management and electronic health records platform for wellness providers, has disclosed a data breach involving unauthorized access to its network. Attorneys are investigating whether affected individuals can pursue legal action.

zHealth EHR
Date of Breach: January 20-21, 2026
CAU logo

Who was affected:

Clients of zHealth EHR

Impacted Data:

Names, medical information, and health insurance information

zHealth EHR is a cloud-based practice management and electronic health records platform designed primarily for chiropractors and other wellness providers, serving thousands of small to mid-size practices across the United States. Because it stores clinical documentation, appointment records, and billing information on behalf of the practices that use it, a security incident involving zHealth EHR has the potential to affect not just the company’s direct customers, but the patients whose records live inside the system.

zHealth EHR’s Data Breach Investigation

According to zHealth EHR, an unauthorized third party copied certain information from the company’s network environment between January 20 and January 21, 2026. The breach reportedly went undetected until June 15, 2026, several months after the initial intrusion occurred. The company began notifying affected individuals on September 3, 2026, and posted a formal notice of the data event on its website on September 10, 2026.

Public reporting indicates that on January 26, 2026, a threat actor known as Kazu posted on the dark web claiming to have obtained approximately 15 GB of data from zHealth EHR, with the compromised dataset reportedly containing over 1.2 million records. Those records were said to include patient medical information, clinical notes, appointment and intake details, and billing and payment data. The threat actor reportedly stated an intention to publish the stolen data within roughly three weeks of the initial claim. zHealth EHR has not publicly confirmed the full scope of that claim, and following its own comprehensive review, has stated only that the types of information potentially exposed include names, medical information, and health insurance information.

Electronic health record platforms are a particularly attractive target for cybercriminals because a single breach can expose sensitive clinical data belonging to patients across many unrelated practices at once, rather than the records of a single provider’s own patient base. The combination of medical information and health insurance details is valuable on the black market, since it can be used to file fraudulent insurance claims or obtain medical services and prescriptions in another person’s name, harms that can be harder for a victim to detect than simple financial fraud.

The roughly five-month gap between the reported intrusion in January 2026 and its discovery in June 2026 illustrates a common challenge with cloud-hosted software platforms: because the platform sits between the wellness practice and the patient, neither party may notice unauthorized activity until a third party, such as a threat actor’s own dark web posting, brings it to light. Attorneys working with Class Action U are continuing to review zHealth EHR’s notice and gather information from affected individuals as more details become available.

When Did This Breach Occur?

zHealth EHR has stated that an unauthorized third party copied information from its network environment between January 20 and January 21, 2026. The breach was not discovered until June 15, 2026, and the company began notifying affected individuals on September 3, 2026, with a formal notice posted on its website on September 10, 2026.

What Information Was Breached?

zHealth EHR has stated that the types of information potentially exposed include names, medical information, and health insurance information. A threat actor’s dark web posting separately claimed the stolen dataset included clinical notes, appointment and intake details, and billing and payment data, though zHealth EHR has not specifically confirmed each of those categories in its own public notice.

What You Can Do

If you received a notice from zHealth EHR about this data breach, or believe your information may have been affected because your wellness provider uses the zHealth EHR platform, there are steps you can take to help protect yourself, including:

  • Reviewing your health insurance Explanation of Benefits statements for any services you did not receive
  • Monitoring your accounts for signs of medical identity theft
  • Enrolling in the credit monitoring and identity protection services zHealth EHR is offering to affected individuals
  • Calling zHealth EHR’s dedicated assistance line at 1-866-899-5709 if you have questions about whether you were affected

File a Data Breach Lawsuit Against zHealth EHR

Attorneys working with Class Action U are investigating whether patients and practices affected by the zHealth EHR data breach may be entitled to compensation. Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: January 20-21, 2026
DSE
Date of Breach: March 14, 2025 - April 16, 2025
Date of Breach: September 2026 (reported)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.