2026 Trinity Health — HIE unauthorized disclosure (51+ Mass residents)
Data compromised
Clinical care details, demographics, insurance, driver licenses, medical records, emails
Technical writeup
Trinity Health, one of the largest not-for-profit Catholic health systems in the US, reported a data breach involving unauthorized disclosure of patient health information through an electronic Health Information Exchange (HIE). An HIE member called Health Gorilla requested patient data stating it was for treatment; the HIE could not confirm Health Gorilla's statements or whether receiving companies had proper authorizations. Unauthorized disclosure occurred December 16, 2022; Trinity was notified January 13, 2026. At least 51 Massachusetts residents affected. Exposed: clinical care details, demographic info, insurance info, driver licenses, medical records, emails, provider names. Offering 12 months (MA) or 24 months (VT) credit monitoring via Cyberscout.
Root cause
HIE unauthorized disclosure; Health Gorilla request; authorization verification failure