Menu
Browse

Cyber Incident Victim: ZenPatient

Date:

Dec 2025

Location:

United States of America

Summary

ZenPatient, a telehealth and messaging software provider, disclosed that an unauthorized party gained access to its network and exfiltrated files containing names, addresses, birth dates, and medical information. After the breach was detected, the company engaged third‑party cybersecurity experts to investigate and confirmed the intrusion, then sent notification letters to affected individuals. To mitigate potential harm, the company offered complimentary credit monitoring services and implemented additional security controls to reduce the likelihood of similar incidents.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On February 27, 2026, ZenPatient’s security team identified suspicious activity within its computer network and promptly engaged third‑party cybersecurity professionals to investigate. The investigation confirmed that an unauthorized third party had gained access to the network between December 5, 2025, and February 12, 2026. During that window, certain files were exfiltrated from the system. The breach notice did not specify the exact method used to gain entry.

Cyber Incident Image

Review of the exfiltrated files revealed that they contained names, addresses, birth dates, and medical information of individuals. Notification letters were mailed to the affected individuals on July 17, 2026. ZenPatient stated that it was unaware of any misuse of the patient data resulting from the incident. As a precaution, the company made complimentary credit monitoring services available to those individuals for a period of 12 months.

In addition to offering credit monitoring, ZenPatient reported that it had implemented additional cybersecurity measures aimed at reducing the risk of similar incidents in the future. The incident was disclosed alongside notices from other healthcare organizations, including Anatomic and Clinical Laboratory Associates, Saint Pete MRI, Carlyle Senior Care, SportsMed Physical Therapy, and Lifeways Inc. The company’s response focused on notification, mitigation services, and strengthening its network defenses.

Sources
Sources available to members
1 source