zHealth, Inc., a San Francisco-based provider of cloud practice-management and electronic health records software, has disclosed a cybersecurity incident affecting 118,563 individuals, according to the breach notice it provided to the California Attorney General and the count the Oregon Attorney General has been given. The timeline is the operationally significant part: zHealth became aware that information may have been copied on or around 15 June 2026, its investigation confirmed that an unauthorised third party had accessed its network between 20 and 21 January 2026, and its review of the impacted data was not completed until 3 September 2026 β a five-month gap between the intrusion and the end of the review, with the intrusion itself predating the company's awareness by roughly five months. The affected information varies by individual and may include names, medical information and health insurance information, and affected individuals have been offered twelve months of single-bureau credit monitoring. The incident is not yet listed on the HHS Office for Civil Rights breach portal. The disclosure arrived in a batch that illustrates how routine the vendor-side breach has become in US healthcare: Bridgeway Benefit Technologies, a Baltimore third-party health-plan administrator, notified OCR of a breach affecting 9,268 individuals arising from an employee email account accessed between 5 March and 19 May 2026 that exposed Social Security numbers, with the company confirming the breach was limited to its own email system and no client systems were compromised; Longview ER Operations, trading as Hospitality Health ER in Texas, identified suspicious network activity on 22 July, confirmed that an unauthorised third party accessed its network and copied files, and has reported to OCR using an estimate of at least 501 individuals pending completion of its file review, with the Tyler and Galveston facilities unaffected; and HealthStream also reported. Read together, the three disclosure shapes β a long-dwell network intrusion, a months-long mailbox compromise, and a file review still open β cover the three ways vendor-side healthcare breaches are discovered late.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-09-17 |
| Source | HIPAA Journal |
| Reliability | Tier 2 |