CSIDB logo
Incident

ZenPatient

Incident posture

Attack window
Dec 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-25 01:03

Linked entities

Victim
ZenPatient
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Dec 2025
Discovered
Feb 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

ZenPatient reported a cybersecurity incident involving unauthorized access to its network, during which certain files containing names, addresses, birth dates, and medical information were exfiltrated. The incident was investigated with third‑party cybersecurity professionals, who confirmed the unauthorized access. Notification letters were sent to affected individuals, and the company stated it is unaware of any misuse of the data but offered complimentary credit monitoring as a precaution. Additional security measures have been implemented to reduce future risk.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 27, 2026, ZenPatient identified suspicious activity within its computer network and promptly engaged third‑party cybersecurity professionals to investigate. The investigation confirmed that an unauthorized third party had gained access to the network between December 5, 2025, and February 12, 2026. During this period, certain files were exfiltrated from the ZenPatient environment. The unauthorized access was initially detected as anomalous activity that prompted the involvement of external experts.

Review of the compromised files revealed that they contained names, addresses, birth dates, and medical information of individuals. Notification letters detailing the breach were mailed to the affected individuals on July 17, 2026. ZenPatient stated that it had no evidence of misuse of the patient data resulting from the incident. As a precautionary measure, the company offered complimentary credit monitoring services to those affected for a period of twelve months.

In addition to providing credit monitoring, ZenPatient reported that it had implemented additional cybersecurity measures aimed at reducing the risk of similar incidents in the future. The company did not disclose the specific nature of these measures in the public notice. The incident was disclosed alongside other breaches reported by various healthcare providers in the same timeframe.

Sources

Sources available to members: 1 source.

CSIDB