The Health Trust discovered unauthorized network access in May 2025, with a second intrusion in June 2025, that exposed personal information tied to files handled by its finance vendor FASS. Notification letters went out in August 2026 confirming names and other personal details were accessed. Affected individuals should enroll in the free IDX credit monitoring before the November 24, 2026 deadline.
| Company | The Health Trust |
|---|---|
| Industry | Non-profit |
| Data Types Exposed | Full Name, Personal Identifiers, Financial or Accounting Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unauthorized Network Access |
| Regulators Notified | Delaware Attorney General, California Attorney General, Iowa Attorney General |
What Happened in the The Health Trust Data Breach?
The Health Trust has begun notifying individuals about a data security incident that exposed personal information stored in its network. The organization is a non-profit that helps government and non-government groups deliver services to people in need. According to its notification letter, the exposed files were housed with Financial Administrative Support Services, known as FASS, which handles finance and accounting work for The Health Trust and other partner organizations.
The Health Trust first noticed suspicious activity on its computer network in May 2025. As a result, the organization moved to secure its systems and restore normal operations. However, additional suspicious activity turned up in June 2025. At that point, The Health Trust took its systems offline entirely to protect them while it investigated further.
The investigation later revealed that an unauthorized actor had gained access to certain systems before March 26, 2025. That same actor returned between June 8 and June 11, 2025, and this time copied certain files. Because the intrusion happened in two separate waves, the organization needed extra time to determine exactly what data was taken and who was affected.
Following containment, The Health Trust launched a detailed review of the compromised files. This process involved identifying every affected individual and matching their records to the specific data types involved. The review has since concluded, and The Health Trust confirmed that certain individuals’ information was part of the exposed data set.
The organization also reported the incident to law enforcement. In addition, it began notifying relevant regulators as required by law. This formal notification process is what led to the breach letters now reaching affected people.
Who was affected?
The Health Trust breach may affect individuals whose information was included in files handled by FASS on behalf of The Health Trust or its partner organizations. Because The Health Trust supports both governmental and non-governmental service providers, the affected population could include people who received assistance through various community programs. The notification letter specifically states that there is no evidence The Health Trust’s own internal client files were involved, which suggests the exposure is tied more narrowly to financial and accounting records processed by FASS.
The exact number of people affected has not been publicly disclosed. This means it isn’t yet clear whether the breach touches a small group or a much larger population. What is clear is that The Health Trust considered the exposure significant enough to trigger notification obligations with multiple state regulators.
Because this organization works across many partner programs, the geographic reach could extend beyond a single state. In addition, since some of the served organizations may work with vulnerable populations, there is a possibility that minors or dependent individuals could be among those affected. The Health Trust has not specified further demographic details in its notice.
What Information Was Potentially Exposed?
The notification letter confirms that names were included in the exposed data. Beyond names, the letter references additional categories of personal information, though the exact list varies by individual based on what was found in their specific file.
Based on the structure of the notice, the following categories of information were identified during the investigation as potentially exposed:
- Full name
- Additional personal identifiers specific to each individual’s file
- Financial or accounting-related information processed through FASS
Because FASS provides finance and accounting services, it’s reasonable for affected individuals to assume that some financial details may be part of the exposed records. The Health Trust has stated that it has no current evidence of actual or attempted identity theft connected to this event. Still, the presence of financial-related files raises the stakes for those impacted.
When personal details are stolen, criminals can use them to open new credit accounts or file fraudulent tax returns. They may also attempt to access existing financial accounts or trick victims through targeted phishing messages. This risk often persists for months or years after a breach, since stolen data can be resold or reused long after the original incident.
In addition, combined data points make identity theft more convincing to unwitting victims. For example, a scammer with a name and financial detail can build a more believable phishing email or phone call. Consequently, affected individuals should treat any unexpected contact about their accounts with caution, even if it appears legitimate.
What is the company doing?
Once The Health Trust identified the intrusion, it acted to secure its network right away. The organization brought systems offline during the second wave of activity in June 2025 to prevent further access. This decisive step allowed investigators to examine the scope of the incident without additional interference.
The Health Trust also reported the matter to law enforcement. Furthermore, it has filed formal breach notifications with several state regulators. Filings were submitted to the Delaware Attorney General, the California Attorney General, and the Iowa Attorney General.
As an added protective measure, The Health Trust is offering complimentary credit monitoring through IDX to affected individuals. Enrollment requires a unique code provided in each notification letter. The deadline to enroll is November 24, 2026, so affected individuals should not delay signing up.
Looking ahead, The Health Trust says it is reviewing its internal policies, procedures, and security tools. This step is meant to reduce the chance of a similar event happening again. The organization has stated that protecting the privacy and security of the information in its care remains a top priority going forward.
What Should Affected Individuals Do?
Enroll in the Offered Credit Monitoring
Affected individuals should take advantage of the complimentary credit monitoring offered through IDX. This service can help detect suspicious activity early, before it turns into a larger problem. Enrollment must happen before the November 24, 2026 deadline listed in the notification letter.
To sign up, individuals can scan the QR code included in their letter or visit the enrollment website directly. Because the monitoring only works once activated, it’s important to complete the enrollment steps rather than assuming automatic protection. Anyone needing help can call the dedicated assistance line for guidance through the process.
Watch for Signs of Identity Theft
Even though The Health Trust says it has no evidence of fraud so far, affected individuals should still monitor their accounts closely. This means checking bank and credit card statements regularly for unfamiliar charges. It also means reviewing account login activity for anything unusual.
In addition, individuals can request a free credit report from each of the three major bureaus every year through annualcreditreport.com. Reviewing these reports can reveal new accounts opened without permission. If something looks wrong, it should be reported and disputed as soon as possible.
Consider a Fraud Alert or Credit Freeze
Because financial information may have been involved, placing a fraud alert on credit files is a smart precaution. A fraud alert requires businesses to verify identity before extending new credit in someone’s name. This makes it harder for criminals to open accounts using stolen information.
Individuals who suspect they’ve already experienced identity theft can request an extended fraud alert lasting seven years. Alternatively, a credit freeze restricts access to a credit file entirely, offering even stronger protection. Both options are free to set up with each credit bureau.
Stay Alert for Phishing Attempts
Scammers often use breach notifications as bait to trick people into revealing more information. As a result, affected individuals should be cautious about unexpected calls, texts, or emails referencing this incident. Legitimate correspondence from The Health Trust will not ask for sensitive details like passwords over email.
Before clicking any links, it helps to verify the sender’s identity independently. For example, individuals can call the official assistance number listed in their letter rather than replying directly to a suspicious message. This simple habit can prevent a second, more damaging breach of personal information.
Speak With a Data Breach Attorney
Individuals concerned about their exposure may want to consult a data breach attorney for a free case evaluation. An attorney can explain what legal options may be available given the specific circumstances of this incident. This is especially useful for anyone who later experiences fraud tied to their exposed data.
Because deadlines and legal rights can vary, getting advice early is generally a good idea. A consultation typically costs nothing and can clarify whether pursuing a claim makes sense. This step can provide peace of mind while the investigation and monitoring period continue.
More Information
Official data breach notification report (PDF) from Delaware Attorney General
Official data breach notification from California Attorney General
Official data breach notification from Iowa Attorney General
