Two dates define this breach, and they sit five months apart. Someone was inside zHealth’s systems on January 20 and 21. Nobody at the California healthcare software company realized anything was wrong until mid-June, and pinning down the scope took until early September.
Patient names, medical information, and health insurance information were caught up in the incident. Notices went out starting September 11, and the company reported the breach to the Texas attorney general on September 15. A victim count has not been published.
Software vendors sit downstream of hundreds of clinics, so one intrusion can touch records that no individual practice knows it shares. That five-month gap is the detail compliance teams should study: a compromised vendor platform buys an attacker months of quiet residency rather than a smash-and-grab.
Attorneys working with ClassAction.org are investigating a possible class action on behalf of people who received notice. Practices that run vendor-hosted scheduling, billing, or clinical tools should confirm who holds the data, what access each vendor has, and whether contract language requires breach notification timelines that match the organization’s own obligations.