← eClinicalWorks

2025 TriZetto Provider Solutions (eClinicalWorks billing ecosystem) — portal intrusion Nov 2024–Oct 2025

2025 3.4M records affected Share on X

Data compromised

Names, addresses, DOB, SSNs, health-plan member IDs, provider and insurer metadata per HIPAA Journal / BankInfoSecurity summaries

Technical writeup

TriZetto Provider Solutions—a Cognizant-owned revenue-cycle and eligibility vendor frequently encountered by eClinicalWorks customers for claims and clearinghouse-style workflows—disclosed suspicious activity on October 2, 2025, involving a customer-facing web portal with forensics tracing unauthorized access to November 2024. Regulatory and trade reporting cited more than 3.4 million individuals across downstream healthcare clients, with PHI categories including insurance identifiers, demographic fields, and SSN-class data in many notices. eClinicalWorks users are part of the broader provider base notified through business-associate chains rather than a separate ECW application compromise.

Root cause

Long-running unauthorized access to internet-exposed provider web portal (Mandiant-engaged investigation per press)

References