← Blog

TriWest Breach: 12K TRICARE West Beneficiaries Warned

Share on X

July 13, 2026: TriWest Healthcare Alliance, the managed care contractor for TRICARE West Region, began notifying 11,844 beneficiaries that protected health information was downloaded in an unauthorized access incident discovered April 16, 2026, according to Military Times and the HHS OCR breach portal, which lists 11,848 individuals affected under Defense Health Agency (TriWest).

What happened

TriWest told Military Times that on April 16, 2026, an unauthorized person gained limited access to TriWest systems and downloaded information. The company hired a third-party forensic firm, worked with the government on notification timelines, and said it had taken immediate steps to stop further unauthorized activity.

Notification letters provided to Military Times were dated around July 2, 2026—roughly two and a half months after discovery. TriWest attributed the gap to coordination with the Defense Health Agency and applicable HIPAA notification rules. For families juggling PCS moves and deployment schedules, a late-summer letter about an April event is easy to miss in a pile of DEERS or pharmacy mail.

What data was exposed

Per TriWest's notification language summarized by Military Times, the unauthorized download included health-related and personal information:

  • Names
  • Department of Defense Benefits Numbers
  • ZIP codes

In fewer than five instances, the company said the data also included Social Security numbers, addresses, and dates of birth. TriWest is notifying each beneficiary about the specific fields involved in their case—your letter may not list every category above.

Who is at risk

TriWest covers about four million beneficiaries in TRICARE West, serving active-duty service members, retirees, National Guard and Reserve members, family members, survivors, and certain former spouses. Eligibility flows through DEERS; the breach is at the contractor, not a single base clinic, so affected individuals may live across the West Region footprint without ever having visited a TriWest-branded facility.

Even when SSNs were not broadly exposed, a DoD Benefits Number paired with name and ZIP is enough to fuel TRICARE impersonation calls, fake pharmacy benefit texts, and phishing that cites real-sounding beneficiary context.

What TriWest is offering

TriWest stated it is unaware of misuse but is offering 24 months of free credit monitoring through Experian for beneficiaries who want it. Enrollment requires the activation code and deadline in your notification letter. The company also stood up a breach response line at 1-833-918-1296 for suspicious activity questions.

After the incident, TriWest reported tightening password-reset controls, strengthening access monitoring, and adding employee training on cyber attacks.

Action items if you received a notice

  1. Enroll in Experian monitoring before the deadline in your letter if you want the complimentary service.
  2. Do not share activation codes or letter details with callers who claim to be TriWest or TRICARE support unless you initiated contact via official channels.
  3. Review TRICARE Explanation of Benefits and pharmacy statements for services you did not receive.
  4. File an FTC report at IdentityTheft.gov if you believe you are a victim of medical identity theft.
  5. Call 1-833-918-1296 (TriWest Breach Response Line) for questions tied to your notification.

Canonical record

TriWest TRICARE West 2026 breach on BreachHistory.

Sources: Military Times, HHS OCR breach portal, TriWest Healthcare Alliance.