Markets & Business
TriZetto confirms data breach affecting more than 3.4 million people
TriZetto confirmed that more than 3.4 million people’s personal and health information was stolen in a 2024 cyberattack that went undetected for nearly a year.
TriZetto, a health technology company owned by the multinational conglomerate Cognizant, has confirmed a major security incident involving the theft of personal and health data. The company confirmed that the personal and health information of more than 3.4 million people was stolen in a 2024 cyberattack. TriZetto failed to detect the breach for almost a year. Although the company officially identified the breach on October 2, 2025, its subsequent investigation revealed that hackers had access to its servers as far back as November 2024.
The scale of the company’s operations highlights the potential reach of the incident. TriZetto serves around 200 million people and 875,000 healthcare providers across the United States, who use the platform to assess patients’ insurance for medical treatments. In a filing submitted to Maine’s attorney general on Friday, TriZetto disclosed that the hackers accessed insurance eligibility transaction reports on its servers. These reports are data used to verify patient coverage for medical treatments. However, TriZetto clarified that not every customer was affected by the breach.
Following the disclosure, several organizations have confirmed that their patients’ information was compromised in the cyberattack. Among the affected entities is OCHIN, a nonprofit consultancy firm that provides healthcare technology services to some 300 rural and community care providers across the United States. In response to the incident, Cognizant spokesperson William Abelson stated that the company has “eliminated the threat” to its environment, though the company did not clarify why it took almost a year to detect the access.
This incident represents the latest in a series of large-scale cyberattacks targeting health technology infrastructure in the United States. It closely follows a 2024 ransomware attack on Change Healthcare, another health tech giant that processes some 15 billion healthcare transactions. In that previous attack, hackers stole more than 192 million patient files, causing widespread outages and disrupting access to medical treatments and medications across the country.
Why it matters
TriZetto is a critical infrastructure provider for around 200 million people, and this incident highlights the persistent vulnerability of large-scale health tech platforms to long-term, undetected cyberattacks.