BACH's January notice confirms a TriZetto vendor incident
Issue
Bay Area Community Health's January 5 substitute notice says the incident occurred at third-party company TriZetto, which works with its electronic-record provider OCHIN. BACH said OCHIN notified it on December 15, 2025 that an unauthorized individual had gained access to one TriZetto system.
Based on information BACH received from the two vendors, involved data may have included a name, Social Security number, date of birth, contact information, and certain health-related or insurance information. The notice expressly says not every patient's information was affected and that there was no evidence of misuse at that time.
It does not publish an affected-person count, say that BACH's own systems were accessed, establish later misuse, or support a class-action or sector-wide workforce claim. Privacy, security, and procurement leaders should use the incident as a tabletop prompt: identify every business-associate and subcontractor handoff, assign notification and evidence-preservation responsibilities, verify current vendor facts through counsel-approved channels, and test how patient questions reach the privacy office.
Workforce and communications leaders should give staff a short routing script for suspicious bills, insurer statements, or requests for personal information without naming affected people. Candidates may discuss vendor-governance controls as a de-identified scenario, not speculate about BACH.
Never place a notice, patient identifier, insurance statement, breach-response artifact, credential, vulnerability, or investigation detail in FQHC Talent.
Key points
- The notice says information may have been involved; it does not say every patient was affected or establish misuse.
- Privacy and security: map the BAA/subcontractor chain and test notice, evidence, and question-routing ownership.
- Workforce and communications: use a short official routing script; do not circulate names or incident artifacts.
- FQHC Talent is not an incident-response system; keep notices, identifiers, credentials, and vulnerabilities out.
Sources for this story
Bay Area Community Health / California DOJSources for your board packet
This story's source plus 4 related stories and their sources, ready to print for your team or board.
Free. Unlocking the packet subscribes you to Intel Brief. You'll be subscribed right away, with no confirmation email. Unsubscribe with one click in any issue. If you unsubscribed before, we won't re-add you. We never sell your email. You can open each source above without an email.
Affected FQHCs
Part of
- Enforcement: privacy, fraud and audits
Data breaches
FQHC Talent. (2026, January 5). BACH's January notice confirms a TriZetto vendor incident. Source: Bay Area Community Health / California DOJ. Retrieved October 6, 2026, from https://www.fqhctalent.com/intel/bach-trizetto-data-breach-may-6-2026
More in Risk & Compliance
Sep 29
HHS civil rights office says when states can use substance use records
Sep 25
CMS and 37 states pledge to judge Medicaid by health outcomes
Sep 24
Geiger Gibson review finds health centers expect a heavy work-rule frailty burden
Sep 24
CMS seeks input on Part D pharmacy contract terms, including 340B claims