zHealth, Inc. Reports Breach of Patient Health Data to California AG
zHealth, Inc., a provider of software for healthcare practices, reported an unspecified data breach to the California Attorney General's office on September 11, 2026. The incident, which occurred on January 20, 2026, involved the exposure of sensitive patient health information. Affected individuals should monitor their accounts and reports for potential misuse of their data.
- State
- California
- Breach date
- January 20, 2026
- Reported
- September 11, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Billing and Payment History
- Provider and Treatment Dates
zHealth, Inc. offers software solutions crucial for chiropractic, physical therapy, and other allied health practices. These platforms manage electronic health records, scheduling, and billing, centralizing a vast amount of sensitive information for practices across the country. On September 11, 2026, zHealth, Inc. filed a report with the California Attorney General's office concerning a security incident that occurred on January 20, 2026.
The company stated that this breach involved an unauthorized intrusion into its network infrastructure. While the exact nature of the attack was not specified, such incidents often target centralized databases containing confidential administrative systems and digital patient files within healthcare technology providers.
The exposed data categories are extensive and highly sensitive. They include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Billing and Payment History, and Provider and Treatment Dates. This combination of personal and health data carries substantial risk for affected individuals.
Exposure of this detailed information can lead to various forms of identity compromise, including fraudulent access to healthcare services, financial fraud, and other unauthorized activities. Individuals should be aware that their comprehensive personal and health records are now potentially in the hands of unauthorized parties.
For those who receive a notification regarding this incident, it is important to take protective steps. Regularly review any explanation of benefits (EOB) statements from insurers for services you did not receive. Additionally, monitor your credit reports for any suspicious accounts or activities. Placing a fraud alert on your credit file with the major credit bureaus can also provide an additional layer of security.
This documentation reflects information provided in public filings by zHealth, Inc. with regulatory bodies, detailing the reported security incident and the scope of data exposure.