Supply chain β›“ Supply Chain

TriZetto (Cognizant) Healthcare Technology Breach (3M+ Individuals)

πŸ“… 2024-07-01 🏒 TriZetto (Cognizant subsidiary) β€” healthcare benefits/RCM software
Primary Source β†—

Incident Details

TriZetto, a healthcare technology subsidiary of Cognizant Technology Solutions, disclosed in late 2024 that a data breach had affected over 3 million individuals. TriZetto provides healthcare benefits administration, claims processing, and revenue cycle management software used by health insurance payers and providers across the US. The breach exposed sensitive patient and member data including names, Social Security numbers, dates of birth, medical records, health insurance information, and financial account details. Multiple health insurance payers and providers notified their members about exposure via TriZetto systems. The breach reinforced systemic concerns about the concentration of healthcare data in large health IT vendors and the cascade effect when such vendors are compromised.

Technical Details

Initial Attack Vector
Attackers breached TriZetto's healthcare data platform systems, exfiltrating data for health insurance customers that had been processed through TriZetto's revenue cycle management and benefits administration software
Vendor / Product
TriZetto (Cognizant subsidiary) β€” healthcare benefits/RCM software
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-07-01 Breach occurred
  2. 2024-11-15 Publicly disclosed
  3. 2024-12-01 Customers notified