OCHIN, Inc. A.I CyberSecurity Scoring
OCHIN, Inc.
Company Information
Website:http://www.ochin.org
Employees number:989
Number of followers:23,535
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:ochin.org
OCHIN, Inc. Risk Score (AI oriented)
Between 0 and 549
OCHIN, Inc.Hospitals and Health Care
Updated:
02/04/2026
02/04/2026
253/1000
Critical
C
OCHIN, Inc. Global Score (TPRM)
xxxx
OCHIN, Inc.Hospitals and Health Care
Score locked

OCHIN, Inc.Critical
Current Score
253C (CRITICAL)
01000
9 incidents
-90.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
276
MAY 2026
263
APRIL 2026
261
MARCH 2026
245
FEBRUARY 2026
293
Breach
09 Feb 2026 • OCHIN, Inc.
TriZetto Provider Solutions, OCHIN and Terry Reilly Health Services: Terry Reilly Health Services alerts patients to data security breach
TRHS Data Breach Exposes Patient Information via Third-Party Vendor
237
CRITICAL-56
TRIOCHTER1770659813
TRHS Data Breach Exposes Patient Information via Third-Party Vendor
Terry Reilly Health Services (TRHS) has begun notifying patients of a data security incident that may have compromised personal and health-related information. The breach, discovered through TriZetto Provider Solutions (TPS) a third-party vendor for OCHIN, TRHS’s electronic medical record provider prompted immediate action from cybersecurity experts and law enforcement.
TPS contained and neutralized the threat while implementing enhanced security measures to prevent future incidents. Exposed data may include names, addresses, dates of birth, Social Security numbers, health coverage member numbers, insurer details, provider names, and other demographic and health information. Financial data, such as payment cards and bank accounts, was not affected.
Affected individuals will receive notification letters by mail within the next week, along with instructions for enrolling in complimentary identity and credit monitoring services provided by Kroll. Patients will need a unique code from the letter to access the service. TRHS has not disclosed the number of impacted individuals or the exact timeline of the breach.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
344
Breach
23 Jan 2026 • OCHIN, Inc.
OCHIN Inc. and Baltimore City Health Department: Baltimore City Health Department investigating data breach involving third-party system
Baltimore City Health Department Third-Party Data Breach
288
CRITICAL-56
OCHBAL1769200436
Baltimore City Health Department Investigates Third-Party Data Breach
The Baltimore City Health Department (BCHD) is investigating a data breach involving its third-party electronic medical records system, which handles insurance and eligibility processing. The breach, linked to vendor OCHIN Inc., exposed files containing patients’ insurance eligibility verification data.
BCHD confirmed that its internal systems remain unaffected and that the incident was isolated to the third-party platform. OCHIN Inc. is collaborating with a fraud assistance provider to address the breach and will offer free credit monitoring services to impacted individuals. Notifications to affected patients are expected to begin around February 9, 2026.
A dedicated helpline (410-545-6674) has been established for inquiries. In a statement, Baltimore City Health Commissioner Dr. Michelle Taylor expressed regret over the breach, emphasizing the department’s commitment to patient privacy and vendor security compliance. BCHD is working with TriZetto and other experts to mitigate the breach’s impact and provide support to those affected.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
398
Breach
13 Jan 2026 • OCHIN, Inc.
OCHIN, Mosaic, Reid Health and Trinity Health: Health Gorilla Data Breach Investigation
Health Gorilla Data Breach Exposes Sensitive Patient Information
342
CRITICAL-56
TRIMOSOCHREI1774651014
Health Gorilla Data Breach Exposes Sensitive Patient Information
Health Gorilla, a Silicon Valley-based healthcare interoperability platform founded in 2014, is under investigation following a data breach that may have exposed sensitive patient information. The incident, disclosed on January 13, 2026, involved an unauthorized disclosure of health data through its health information exchange (HIE) network.
The breach potentially compromised a wide range of personally identifiable information (PII) and medical records, including:
- Names, dates of birth, and addresses
- Driver’s license and insurance card details
- Financial information
- Clinical data (diagnoses, conditions, lab results, medications, and care plans)
Health Gorilla reported that the data may have been accessed for treatment purposes, but investigators have not confirmed whether the requests or authorizations were legitimate. In response, the affected health organizations Mosaic, OCHIN, Reid Health, Trinity Health, and UMass Memorial Health were temporarily suspended from the HIE while the investigation continues.
Class action law firm Shamis & Gentile P.A. is examining potential legal claims for affected individuals, who may be eligible for compensation. The full scope and impact of the breach remain under review.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
505
Breach
15 Dec 2025 • OCHIN, Inc.
TriZetto, OCHIN and CommuniCare+OLE: CommuniCare+OLE Data Breach Investigation
CommuniCare+OLE Data Breach Affecting Sensitive Patient Information
392
CRITICAL-113
TRIOCHCOM1769016387
CommuniCare+OLE Reports Data Breach Affecting Sensitive Patient Information
CommuniCare+OLE, a healthcare provider, disclosed a data breach involving unauthorized access to sensitive personal and health information. On December 15, 2025, OCHIN CommuniCare+OLE’s electronic medical record system provider alerted the organization that an unauthorized individual had compromised a system managed by TriZetto, a third-party vendor.
The breach prompted an investigation to assess the scope and impact. While details of the security incident remain undisclosed, affected data may include names, Social Security numbers, dates of birth, contact information, and health or insurance-related records. The exact information exposed varies by individual.
CommuniCare+OLE has since begun notifying impacted individuals via mail, providing specifics on the compromised data. The breach notice filed with the California Attorney General’s office outlines the types of information potentially exposed. Further details can be found in the official notification documents.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Breach
15 Dec 2025 • OCHIN, Inc.
TriZetto, OCHIN and Petaluma Health Center: Petaluma Health Center Data Breach Investigation
Petaluma Health Center Data Breach Exposes Sensitive Patient Information
392
CRITICAL-113
TRIOCHPET1769201334
Petaluma Health Center Data Breach Exposes Sensitive Patient Information
Petaluma Health Center recently disclosed a data breach affecting sensitive personal and health-related information of its patients. On December 15, 2025, the center was alerted by its electronic medical record system, OCHIN, that an unauthorized individual had accessed a system belonging to TriZetto, a third-party vendor working with OCHIN.
TriZetto’s investigation confirmed that patient data linked to Petaluma Health Center may have been exposed during the breach. The compromised information varies by individual but includes names, Social Security numbers, dates of birth, contact details, and health or insurance-related data.
In response, Petaluma Health Center began notifying affected individuals via mail, detailing the specific types of information impacted. The center and TriZetto are also offering complimentary credit monitoring services to those affected. The breach notice was filed with the California Attorney General’s office.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
626
Breach
10 Dec 2025 • OCHIN, Inc.
TriZetto, OCHIN and Adapt Integrated Health Care: Adapt Integrated Health Care reports data breach at vendor, assures patient info safety
Adapt Integrated Health Care Third-Party Data Security Incident
505
CRITICAL-121
TRIOCHADA1768955835
Adapt Integrated Health Care Reports Third-Party Data Security Incident
Adapt Integrated Health Care disclosed a data security incident involving TriZetto, a third-party vendor for its electronic medical record system provider, OCHIN. The breach was discovered on December 10, 2025, when OCHIN notified Adapt that an unauthorized individual had accessed one of TriZetto’s systems.
TriZetto acted to halt the unauthorized activity and secure its systems. While Adapt’s internal systems were not directly breached, the incident may have exposed sensitive patient information. Not all patients were affected, and there is currently no evidence that the data has been misused.
Potentially exposed data includes:
- Names
- Social Security numbers
- Dates of birth
- Contact information
- Health-related and insurance details
Adapt is collaborating with OCHIN to strengthen security measures and review its own processes to prevent future incidents. TriZetto plans to begin sending individual notification letters to affected patients in February 2026, with support from its vendor, Kroll, which will provide identity theft protection services, call center assistance, and credit monitoring enrollment instructions.
For further details, patients may contact TriZetto’s dedicated call center at (844) 572-2724 or reach out to Heather Donohue, COO of TriZetto Provider Solutions, at (314) 802-6789.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
560
OCTOBER 2025
692
Breach
02 Oct 2025 • OCHIN, Inc.
OCHIN, TriZetto Provider Solutions and SFCHC: San Francisco Community Health Center Data Breach Investigation
SFCHC Data Breach Involving TriZetto Provider Solutions
552
CRITICAL-140
OCHTRISAN1768259195
SFCHC Reports Data Breach Affecting Patient Information via Third-Party Vendor
San Francisco Community Health Center (SFCHC) disclosed a data breach involving sensitive patient information, stemming from a security incident at one of its business associates. On December 12, 2025, SFCHC was alerted by OCHIN a vendor managing its electronic health record system that TriZetto Provider Solutions (TriZetto), a subcontractor handling healthcare eligibility and claims, had experienced unauthorized access to its systems.
TriZetto’s investigation confirmed that an unauthorized third party may have accessed patient data linked to SFCHC between November 2024 and October 2, 2025. The exposed information varies by individual but includes names, Social Security numbers, addresses, dates of birth, and health insurance details such as member numbers, insurer names, and provider information.
SFCHC has since reviewed the impacted data to identify affected individuals and began mailing breach notification letters. In compliance with California regulations, the notices outline the specific types of compromised information and offer complimentary credit monitoring services to those affected. The breach report filed with the California Attorney General’s office provides further details.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Breach
02 Oct 2025 • OCHIN, Inc.
Cognizant, OCHIN and TriZetto: TriZetto confirms 3.4M people’s health and personal data was stolen during breach
TriZetto Confirms 2024 Cyberattack Exposing 3.4 Million Patients’ Data
552
CRITICAL-140
OCHCOGTRI1772814516
TriZetto Confirms 2024 Cyberattack Exposing 3.4 Million Patients’ Data
Health technology firm TriZetto, a subsidiary of Cognizant, disclosed a 2024 cyberattack that compromised the personal and health information of over 3.4 million individuals. The breach, detected on October 2, 2025, remained undetected for nearly a year, with hackers gaining access as early as November 2024.
TriZetto, which processes insurance eligibility transactions for 200 million patients across 875,000 U.S. healthcare providers, confirmed in a filing with Maine’s attorney general that stolen data included names, dates of birth, addresses, Social Security numbers, provider details, and insurance information. The company stated that not all customers were affected.
Affected organizations include OCHIN, a nonprofit serving 300 rural and community care providers, as well as multiple California-based healthcare entities. Cognizant confirmed the threat was neutralized but did not explain the delayed detection.
This incident follows the 2024 ransomware attack on Change Healthcare, which disrupted U.S. medical services and exposed 192 million patient records. TriZetto’s breach underscores ongoing vulnerabilities in the healthcare sector’s cybersecurity defenses.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
692
AUGUST 2025
691
JULY 2025
690
NOVEMBER 2024
766
Breach
01 Nov 2024 • OCHIN, Inc.
TriZetto, OCHIN and Change Healthcare: TriZetto confirms data breach affecting 3.4 million patients tied to 2024 cyberattack
TriZetto Confirms 2024 Cyberattack Exposing 3.4 Million Patients’ Data
676
CRITICAL-90
TRICHAOCH1772815208
TriZetto Confirms 2024 Cyberattack Exposing 3.4 Million Patients’ Data
TriZetto, a major U.S. health technology provider under Cognizant, disclosed a 2024 cyberattack that compromised the personal and medical data of over 3.4 million individuals. The breach, detected on October 2, 2025, went unnoticed for nearly a year, with unauthorized access dating back to November 2024.
The stolen data included sensitive information such as names, dates of birth, home addresses, Social Security numbers, health status details, provider names, and insurance records. TriZetto, which processes insurance eligibility for roughly 200 million patients through 875,000 healthcare providers, confirmed that patient eligibility reports were extracted from its servers.
Multiple organizations, including OCHIN a nonprofit serving 300 U.S. providers and several California-based medical providers, verified that their patients’ data was exposed. However, TriZetto stated that not all clients were affected.
The incident follows a 2024 ransomware attack on Change Healthcare, which resulted in the theft of 192 million patient files and caused widespread disruptions in medical services nationwide. TriZetto has not provided details on why the breach remained undetected for nearly a year, and Cognizant has not responded to requests for comment.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for OCHIN, Inc. ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in May 2026 ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in April 2026 ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in March 2026 ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in February 2026 ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in January 2026 ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in December 2025 ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in November 2025 ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in October 2025 ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in September 2025 ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in August 2025 ??
What was OCHIN, Inc.'s A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on OCHIN, Inc.'s A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with OCHIN, Inc. ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view OCHIN, Inc.'s profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?