ZenPatient
Incident posture
Linked entities
- Victim
- ZenPatient
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
ZenPatient reported a cybersecurity incident involving unauthorized access to its network, during which certain files containing names, addresses, birth dates, and medical information were exfiltrated. The incident was investigated with third‑party cybersecurity professionals, who confirmed the unauthorized access. Notification letters were sent to affected individuals, and the company stated it is unaware of any misuse of the data but offered complimentary credit monitoring as a precaution. Additional security measures have been implemented to reduce future risk.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On February 27, 2026, ZenPatient identified suspicious activity within its computer network and promptly engaged third‑party cybersecurity professionals to investigate. The investigation confirmed that an unauthorized third party had gained access to the network between December 5, 2025, and February 12, 2026. During this period, certain files were exfiltrated from the ZenPatient environment. The unauthorized access was initially detected as anomalous activity that prompted the involvement of external experts.
Review of the compromised files revealed that they contained names, addresses, birth dates, and medical information of individuals. Notification letters detailing the breach were mailed to the affected individuals on July 17, 2026. ZenPatient stated that it had no evidence of misuse of the patient data resulting from the incident. As a precautionary measure, the company offered complimentary credit monitoring services to those affected for a period of twelve months.
In addition to providing credit monitoring, ZenPatient reported that it had implemented additional cybersecurity measures aimed at reducing the risk of similar incidents in the future. The company did not disclose the specific nature of these measures in the public notice. The incident was disclosed alongside other breaches reported by various healthcare providers in the same timeframe.
Sources
Sources available to members: 1 source.