Harmony Health Medical Clinic and Family Resource Center, a family practice medical clinic in northern California, was impacted by a data breach that originated with its third-party vendor, TriZetto Provider Solutions. This incident involved unauthorized access to patient records between November 2024 and October 2, 2025. TriZetto began notifying affected individuals around December 2025 and issued HIPAA notifications to covered entities on January 15, 2026.
The breach exposed a variety of sensitive data, including addresses, dates of birth, Social Security numbers, health insurance member numbers, Medicare beneficiary numbers, health insurer names, and other demographic health and protected health information (PHI). The incident affected over 700,000 individuals associated with TriZetto-contracted providers, with broader reports indicating PHI exposure for up to 3.4 million individuals across all affected entities. Investigations into the breach are ongoing, and a class-action lawsuit is possible.
It is important to note that details regarding data breaches can emerge over time, and notifications to affected individuals may be delayed.