Skip to main content
FQHC Talent
Back to the news

BACH's January notice confirms a TriZetto vendor incident

Bay AreaMore from California

Issue

Bay Area Community Health's January 5 substitute notice says the incident occurred at third-party company TriZetto, which works with its electronic-record provider OCHIN. BACH said OCHIN notified it on December 15, 2025 that an unauthorized individual had gained access to one TriZetto system.

Based on information BACH received from the two vendors, involved data may have included a name, Social Security number, date of birth, contact information, and certain health-related or insurance information. The notice expressly says not every patient's information was affected and that there was no evidence of misuse at that time.

It does not publish an affected-person count, say that BACH's own systems were accessed, establish later misuse, or support a class-action or sector-wide workforce claim. Privacy, security, and procurement leaders should use the incident as a tabletop prompt: identify every business-associate and subcontractor handoff, assign notification and evidence-preservation responsibilities, verify current vendor facts through counsel-approved channels, and test how patient questions reach the privacy office.

Workforce and communications leaders should give staff a short routing script for suspicious bills, insurer statements, or requests for personal information without naming affected people. Candidates may discuss vendor-governance controls as a de-identified scenario, not speculate about BACH.

Never place a notice, patient identifier, insurance statement, breach-response artifact, credential, vulnerability, or investigation detail in FQHC Talent.

Key points

  • The notice says information may have been involved; it does not say every patient was affected or establish misuse.
  • Privacy and security: map the BAA/subcontractor chain and test notice, evidence, and question-routing ownership.
  • Workforce and communications: use a short official routing script; do not circulate names or incident artifacts.
  • FQHC Talent is not an incident-response system; keep notices, identifiers, credentials, and vulnerabilities out.

Sources for your board packet

This story's source plus 4 related stories and their sources, ready to print for your team or board.

Free. Unlocking the packet subscribes you to Intel Brief. You'll be subscribed right away, with no confirmation email. Unsubscribe with one click in any issue. If you unsubscribed before, we won't re-add you. We never sell your email. You can open each source above without an email.

#BACH#TriZetto#data-breach#PHI#OCHIN#BAA-audit#vendor-risk#privacy-boundary#de-identified-tabletop

Part of

Cite this analysis

FQHC Talent. (2026, January 5). BACH's January notice confirms a TriZetto vendor incident. Source: Bay Area Community Health / California DOJ. Retrieved October 6, 2026, from https://www.fqhctalent.com/intel/bach-trizetto-data-breach-may-6-2026

More in Risk & Compliance

Cookie notice

We use Google Analytics, Vercel Web Analytics, and Vercel Speed Insights to improve the site. Select Decline to turn them off in this browser. We honor GPC and Do Not Track. Read our Privacy Policy.