TriZetto Data Breach: 3.4 Million People, Eleven Months Undetected
You were almost certainly never a TriZetto customer. TriZetto Provider Solutions is a Cognizant company that handles billing and insurance-eligibility checks for doctors' offices and health insurers — so your records passed through it because your provider used it. An intruder sat in that system from November 2024 until October 2025. Twelve lawsuits are now one federal case. There is no settlement and no claim form.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What the Lawsuits Say Happened
TriZetto Provider Solutions runs revenue-cycle work for physician practices: submitting claims, checking whether a patient's insurance covers a visit. That means it holds identity and health-insurance records for patients of many unrelated practices. According to the complaints, an unauthorised party was reading records tied to insurance-eligibility transactions from at least November 2024. TriZetto identified suspicious activity on its web portal on October 2, 2025 and confirmed unauthorised access on November 28, 2025 — roughly eleven months after it began. The plaintiffs plead negligence, negligence per se, breach of contract, invasion of privacy, breach of fiduciary duty, unjust enrichment and violations of state consumer-protection law, and they attack the notification delay as much as the breach itself.
Case Details
On June 5, 2026 the Judicial Panel on Multidistrict Litigation transferred twelve civil actions into In re: Cognizant Technology Solutions Corporation and TriZetto Provider Solutions, LLC, Data Security Breach Litigation, MDL No. 3185, No. 4:26-md-03185 in the U.S. District Court for the Eastern District of Missouri, before Judge John A. Ross. Missouri was chosen because TriZetto is headquartered there. Two of the underlying cases were filed in New Jersey: Madoff v. Cognizant Technology Solutions Corp., No. 2:26-cv-02634, and Billingslea v. Cognizant Technology Solutions Corp., No. 2:26-cv-03394.
Status: One Consolidated Case, No Settlement
Who Is in the Proposed Classes
The complaints seek nationwide and statewide classes of people whose information was exposed — more than 3.4 million individuals by the figure in the transfer order. You do not join an MDL by signing up anywhere; if a class is certified or a settlement is reached, a court-appointed administrator contacts class members directly.
The practical test is your mail. Because TriZetto is a vendor, the notice may carry your doctor's practice name, TriZetto's, or Cognizant's. Keep the letter and the envelope: it states which fields were in your record and it is your proof of membership. If you never received one but were treated by a practice that bills through TriZetto, that is not proof either way — vendor breaches are notified through the provider, and those mailings ran at different times.
What a Case Like This Pays
TriZetto Breach Timeline
- 1
November 2024 — The Access Begins
Per the complaints, an unauthorised party starts reading records tied to insurance-eligibility transactions. Nobody notices.
- 2
October 2, 2025 — Suspicious Activity Spotted
TriZetto identifies unusual activity on its web portal — about eleven months after the access began.
- 3
November 28, 2025 — Unauthorised Access Confirmed
The investigation confirms that an outside party had access. Determining whose records were involved takes longer still.
- 4
Early 2026 — First Class Actions
Suits are filed in federal courts in New Jersey and Missouri, including Madoff (2:26-cv-02634) and Billingslea (2:26-cv-03394) in New Jersey. They plead the delay as its own harm.
- 5
June 5, 2026 — Twelve Cases Become One
The JPML transfers twelve actions to the Eastern District of Missouri as MDL No. 3185, before Judge John A. Ross.
- 6
Now — Pretrial, No Settlement
The consolidated case is in pretrial proceedings. No fund, no administrator, no claim form and no deadline exist.
Three Things to Watch For
A 3.4-million-person class with no claim form is exactly the gap imposters fill:
“File your TriZetto claim” pages
There is no claims portal, because there is no settlement. A site collecting your Social Security number to “secure your share” is harvesting data, not filing anything.
Calls naming your doctor's office
The vendor relationship makes it easy to sound informed — a caller can name a practice without knowing anything about you. No court-appointed administrator phones to ask for your full Social Security number or for a fee.
“Sign here to join the MDL”
You do not opt in to a class action; Rule 23 classes include you unless you opt out. A retainer is a real choice with real consequences — read what you are signing rather than treating it as registration.
TriZetto Breach — Questions People Actually Ask
Who is TriZetto, and why do they have my medical information?
TriZetto Provider Solutions is a Cognizant company that handles revenue-cycle work for healthcare providers — submitting insurance claims and verifying coverage. Your doctor's office used it, so your identity and insurance details passed through its systems. You had no direct relationship with the company.
How many people were affected?
More than 3.4 million individuals, per the figure in the JPML transfer order of June 5, 2026. For scale, the Aesto Health vendor breach reported this year covers 9,540,683 people.
What data was exposed?
Per the complaints: names, addresses, dates of birth, Social Security numbers, billing information, health histories, provider information and other health insurance information. Your own notice states which of those applied to you.
Is there a TriZetto settlement or a claim form?
No. MDL 3185 is in pretrial proceedings. There is no settlement, no fund, no administrator, no claim form and no deadline. If that changes, class members are notified directly by a court-appointed administrator.
What does MDL 3185 actually mean for me?
An MDL gathers similar federal cases before one judge for pretrial work — discovery, motions, sometimes bellwether trials. It is not a class certification and not a settlement. Practically, it means the case is being taken seriously enough to consolidate, and that nothing is payable for some time.
Do I have to do anything to be included?
No. Under Rule 23 you are included in a certified class unless you opt out by the deadline in the official notice. There is nothing to sign up for now.
Why did it take so long to tell anyone?
That question is central to the lawsuits. Access began around November 2024, suspicious activity was spotted October 2, 2025 and unauthorised access was confirmed November 28, 2025. Plaintiffs argue the delay left people unable to protect themselves; the defendants have not conceded that.
What is worth doing right now?
Freeze your credit at all three bureaus — free and reversible. Read your health insurer's explanation-of-benefits statements for care you never received, which is how medical identity theft surfaces. Keep any notice letter you received.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
Aesto Health Breach (9.5M)
Another healthcare vendor breach — the full provider list
DentaQuest Breach (23M+)
Consolidated cases, no settlement yet — current status
Data Breach Payout Estimator
What a breach pays by data type, plus 30+ tracked cases
Return to Kroll, P.O. Box 980108
How to tell a breach notice from a settlement check