Santa Rosa Community Health, a federally qualified health network, was impacted by a vendor data breach that occurred between November 2024 and October 2025. The breach stemmed from TriZetto Provider Solutions, a third-party vendor, which acted as a subcontractor to OCHIN. Notifications to individuals began around December 2025, although no direct notification from Santa Rosa Community Health Centers has been located. Attorneys are investigating a potential class action lawsuit related to this incident.
The breach potentially exposed a range of sensitive data including Address, Date of Birth, Social Security Number, Health Insurance Member Number, Medicare Beneficiary Number, Health Insurer Name, Demographic Health Information, and Health Insurance Information. While the specific number of affected individuals for Santa Rosa Community Health is unconfirmed, the broader TriZetto incident affected over 700,000 patient records across multiple providers, with up to 3.4 million individuals exposed in total nationwide. The primary affected states include California, Maryland, Tennessee, and Oregon.
Details can emerge later regarding the full scope and impact of this breach. Official notices to affected individuals may also be delayed.