TriZetto Provider Solutions (TPS), the revenue-cycle and medical-billing subsidiary of IT services giant Cognizant, has reported a data breach to the HHS Office for Civil Rights affecting 3,433,965 individuals. The filing, submitted in February 2026, makes it the single largest healthcare breach posted to the OCR portal in the first half of 2026 according to Paubox's tally of federal reporting. The figure is unusually consistent across sources: the exact count 3,433,965 appears in the OCR-derived reporting (Paubox), in the consolidated litigation docket (OpenClassActions), and in secondary coverage, with other outlets rounding to "approximately 3.4 million." What makes this incident notable is not the headline number but the dwell time behind it. The unauthorized party had access to eligibility-verification records beginning in November 2024 and was not detected until October 2, 2025, roughly eleven months later.
What Happened
Per TPS's own disclosures, as relayed through class-action trackers and the OCR filing summary, the company detected suspicious activity on a web portal used by some of its healthcare provider customers on October 2, 2025. TPS says it launched an investigation, engaged outside cybersecurity specialists, and notified law enforcement. That investigation determined an unauthorized actor had been intermittently accessing records tied to insurance eligibility verification transactions starting in November 2024.
The reporting timeline is where accounts diverge slightly. ClassActionU states individual notification began December 9, 2025, and one secondary summary agrees notifications "started in December 2025." OpenClassActions records the HHS OCR report as filed February 6, 2026, and Paubox's review of the OCR portal places the TriZetto filing in February 2026. Read together, that means roughly two months elapsed between the start of individual notification and the federal filing, and roughly four months between detection and the federal filing. Some secondary write-ups compress this into a claim that the company "sat on" the breach for nearly a year; that framing conflates dwell time with disclosure delay, and the underlying dates do not support treating them as the same thing.
One further caution on sourcing. A pair of aggregator posts (Mosquera) contain internally garbled causality, at one point describing "suspicious activity detected in October 2025 led to unauthorized access." That is backwards relative to the primary-derived timeline and should be disregarded. No threat actor, ransomware brand, or extortion demand is named in any of the available sources, and none of them report a ransom claim or a leak-site listing.
What Was Taken
The exposed data set is the kind that supports long-tail identity fraud rather than one-off card abuse. Across the sources, the reported elements are:
- Names and addresses
- Dates of birth
- Social Security numbers
- Health insurance member numbers
- Health insurer names and provider names
- Primary insured information
OpenClassActions notes explicitly that no payment card or bank account data was involved. TPS is offering complimentary credit monitoring; the litigation tracker identifies the provider as Kroll.
The population is worth understanding structurally. Most of the 3.4 million people affected never had a direct relationship with TriZetto or Cognizant. Their data reached the portal because their provider used TPS for eligibility checks and claims processing. That is a defining trait of clearinghouse and business-associate breaches: the affected individuals cannot audit, choose, or opt out of the vendor that lost their records, and many will not recognize the notifying entity's name when the letter arrives.
Why It Matters
TriZetto is not an isolated event but the largest data point in a visible 2026 pattern of attackers targeting the billing and revenue-cycle layer beneath US healthcare rather than hospitals directly.
Two other incidents in the same window make the pattern explicit. TechCrunch reported on July 20, 2026 that UK-based healthcare billing software maker Craneware disclosed to the London Stock Exchange that attackers had exfiltrated a "significant volume" of employee, customer, and partner data; Craneware's 2021 acquisition of pharmacy software firm Sentry brought with it access to roughly 147 million patient records accumulated over two decades. Separately, Security Affairs reported that CareCloud, which stores records for more than 45,000 US providers, is notifying nearly 350,000 people after an attacker accessed one of its AWS environments between March 10 and March 16, 2026 and claimed to have exfiltrated database contents. CareCloud, like TriZetto, took months to fill in details, with the specifics emerging only through state attorney general filings.
The macro numbers reinforce it. Paubox, citing HealthTechSecurity's review of the OCR portal, counted 189 large healthcare breaches affecting more than 19 million individuals in H1 2026, with 173 of those attributed to hacking and IT incidents. Revenue-cycle vendors and benefits administrators sit near the top of the resulting leaderboard, with TriZetto (3,433,965), QualDerm Partners (3,117,874), Nacogdoches Memorial Hospital (2,507,073), and Navia Benefit Solutions (2,151,330) leading. There is an interesting counterpoint from the HIPAA Journal's coverage of the ITRC H1 2026 report: no healthcare breach cracked the overall top-ten data compromise list this half, and only seven healthcare breaches required more than one million notices, against 471 million total victim notices across all sectors, dominated by Instructure Canvas at an estimated 275 million. Healthcare is not producing the biggest numbers right now. It is producing the most durable damage per record.
The other lesson defenders should extract is the detection failure. Eleven months of intermittent access to a transaction-processing portal, terminated only after suspicious activity surfaced, is not an exploit sophistication story. It is a monitoring and access-review story. Paubox notes TriZetto is not alone in this either: ApolloMD detected suspicious activity in May 2025 and did not report to OCR until February 2026.
The Attack Technique
Initial access vector is not disclosed in any available source, and no source attributes the intrusion to a named group. What can be stated from the disclosures is limited but useful:
- The compromised asset was a provider-facing web portal, an internet-exposed application intended for TPS customer organizations, not an internal system.
- The access was described as intermittent over roughly eleven months, which is more consistent with reuse of valid credentials or a persistent access path than with a single smash-and-grab.
- The data reached was eligibility-verification transaction records, meaning the attacker was operating against the application's normal data plane rather than pivoting to unrelated infrastructure.
- Detection came from observed suspicious activity, not from an extortion notice, a third-party notification, or a leak-site posting.
Absent a technical disclosure from Cognizant, treat any specific vector claim you encounter as unverified. The available sources do not support one.
What Organizations Should Do
Inventory your clearinghouse and RCM exposure. If you are a provider, list every business associate touching eligibility checks, claims submission, and billing, and determine what fields each one holds. TriZetto's affected population exists almost entirely because of downstream provider relationships. Your patients are in someone else's breach report.
Instrument partner-facing portals for volumetric and behavioral anomalies. Eleven months of intermittent record access should be detectable as a deviation in query volume, off-hours activity, or per-account record retrieval rates. Alert on access patterns, not just authentication failures.
Enforce phishing-resistant MFA on all external portal accounts, including partner and service accounts. Long-lived intermittent access strongly suggests credentials that remained valid. Rotate and re-attest partner credentials on a fixed schedule and kill dormant accounts automatically.
Put contractual detection and notification SLAs in your BAAs. Require vendor notification within a defined window of detection, require dwell-time disclosure, and require the vendor to state whether exfiltration was confirmed or merely claimed. The CareCloud notice language ("claimed to have exfiltrated") shows how much ambiguity survives into formal filings.
Cap data retention in transaction systems. Eligibility verification is a transient business process. If completed transaction records containing SSNs and member numbers persist indefinitely in a portal-accessible store, the breach population becomes every patient ever processed rather than every patient processed during the intrusion window.
Prepare for the notification and litigation tail now. TriZetto's incident has been consolidated as In re: Cognizant Technology Solutions Corporation and TriZetto Provider Solutions, LLC, Data Security Breach Litigation, MDL No. 3185, in the Eastern District of Missouri, centralized by JPML transfer order on June 5, 2026, with roughly 28 actions consolidated. These are unproven allegations at the pleading stage with no certified class and no settlement, but the pattern is now predictable enough that legal, communications, and security should have a joint runbook before an incident, not after.
Sources: Data Breach At Cognizant Trizetto Impacts Over 3 4 Million Patients... | CareCloud Breach Exposes Medical and Financial Data of ... | Hackers stole 'significant' amount of data from tech firm relied on... | Report Shows Surge in Malicious Insider Incidents; Mega Data Breaches | TriZetto Provider Solutions Data Breach Lawsuit - Class Action U | Cognizant TriZetto Data Breach Lawsuit: 3.4M Affected | Cloaked Is Your Health Data At Risk After The Cognizant Trizetto –... | More than 19M affected by healthcare data breaches in 2026 so far