Health software vendor zHealth tells patients their data was taken

The California health software vendor took five months to discover an intrusion that lasted two days in January.

MedRisk Staff
By
1 Min Read

Two dates define this breach, and they sit five months apart. Someone was inside zHealth’s systems on January 20 and 21. Nobody at the California healthcare software company realized anything was wrong until mid-June, and pinning down the scope took until early September.

Patient names, medical information, and health insurance information were caught up in the incident. Notices went out starting September 11, and the company reported the breach to the Texas attorney general on September 15. A victim count has not been published.

Software vendors sit downstream of hundreds of clinics, so one intrusion can touch records that no individual practice knows it shares. That five-month gap is the detail compliance teams should study: a compromised vendor platform buys an attacker months of quiet residency rather than a smash-and-grab.

Attorneys working with ClassAction.org are investigating a possible class action on behalf of people who received notice. Practices that run vendor-hosted scheduling, billing, or clinical tools should confirm who holds the data, what access each vendor has, and whether contract language requires breach notification timelines that match the organization’s own obligations.

Share This Article