2026 Pivot Health — unauthorized AWS access (Feb–Mar; 1,172+ Texas residents noted)
Data compromised
Names, DOB, member/coverage IDs, billing/payment data, some financial account info
Technical writeup
Pivot Health, a short-term and supplemental health insurer, detected and blocked unauthorized access to its Amazon Web Services environment on March 13, 2026. Investigators confirmed an unauthorized third party accessed the AWS environment at various points between February 26 and March 13, 2026, viewing or copying files with member data. Exposed categories included names, birth dates, member and coverage identifiers, insurance billing/payment information, and financial account data for certain individuals. The Texas Attorney General was notified that 1,172 Texas residents were affected while a nationwide HHS total was not yet posted in May 2026 summaries.
Root cause
Unauthorized access to AWS cloud environment