What Happened?
On October 2, 2025, TriZetto Provider Solutions became aware of a security incident involving unauthorized access to a web portal used by some of its healthcare provider customers. Upon detection, TriZetto promptly secured the web portal and engaged the cybersecurity firm Mandiant to investigate and remediate the incident. The investigation revealed that an unauthorized third party had been accessing historical eligibility transaction reports as early as November 2024, almost a year before detection. The accessed reports contained protected health information of patients from various healthcare providers.
Between October and November 2025, TriZetto conducted a detailed review of the compromised data to determine what information was involved and which individuals were affected. On December 11, 2025, TriZetto publicly disclosed the breach and began notifying affected healthcare clients, who in turn are expected to notify individuals within the HIPAA-mandated 60-day window.