CSIDB logo
Incident

TriZetto Provider Solutions

Incident posture

Attack window
Oct 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-13 02:56

Linked entities

Victim
TriZetto Provider Solutions
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Oct 2025
Disclosed
Mar 2026
Resolved
Pending

Summary

TriZetto Provider Solutions discovered suspicious activity in a web portal used by its healthcare provider customers, leading to a breach that exposed personal and health insurance information of over 3.4 million individuals. The compromised data included names, addresses, dates of birth, Social Security numbers, health insurance member numbers (including Medicare identifiers), provider and insurer names, primary insured details and other demographic and health information, while payment card and bank account details were not taken. The firm reported that law enforcement and security partners investigated the incident and that it has since implemented additional security protocols; its platform holds SOC 2, EHNAC and HITRUST certifications. Affected individuals are being offered credit monitoring services. Parent company Cognizant has previously faced security incidents, including a ransomware attack by the Maze group and a lawsuit stemming from a cyber attack.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On October 2 2025, TriZetto Provider Solutions detected suspicious activity in a web portal used by some of its healthcare provider customers, prompting an immediate internal review. The company subsequently confirmed that unauthorized access had occurred and initiated a breach investigation in coordination with law enforcement and external security partners. The incident was later disclosed through a breach notification filed with the Office of the Maine Attorney General, which became public on March 9 2026. According to that notification, the breach affected over 3.4 million individuals whose personal and health insurance information was stored in the compromised system.

The data that may have been accessed includes names, addresses, dates of birth, Social Security numbers, health insurance member numbers (including Medicare identifiers), provider names, health insurer names, primary insured information, and other demographic, health, and health insurance details. TriZetto explicitly stated that no payment card numbers, bank account information, or other financial data were taken during the incident. The exposure of such personal identifiers raises risks of identity theft and fraudulent use of health insurance benefits, although the company did not report any observed misuse of the compromised data at the time of disclosure.

In response to the discovery, TriZetto undertook a thorough investigation with the assistance of law enforcement agencies and third‑party security firms. As part of its remediation, the firm implemented additional security protocols, though the specific measures were not detailed in the public notice. TriZetto also noted that its platform holds certifications for SOC 2, EHNAC, and HITRUST standards, which were referenced to indicate existing security frameworks. To mitigate potential harm to affected individuals, the company began offering credit monitoring services to all those whose information was involved in the breach.

TriZetto Provider Solutions is a subsidiary of Cognizant Technology Solutions, which has experienced prior security events, including a ransomware attack by the Maze group in April 2020 that resulted in estimated costs of $50‑70 million. In the preceding year, Cognizant faced litigation from Clorox related to a 2023 cyber attack, with the lawsuit alleging that a helpdesk employee reset a password without following prescribed security procedures, enabling threat actor access and contributing to a reported $49 million loss for Clorox. These historical incidents are presented as factual background concerning the parent company’s security history.

Sources

Sources available to members: 1 source.

CSIDB