zHealth, Inc., a cloud-based EHR and practice management software provider, confirmed a data breach after an unauthorized third party accessed its network in January 2026, affecting more than 118,000 individuals. Exposed data may include names, medical information, and health insurance details. Affected individuals should enroll in the free credit monitoring zHealth is offering and closely watch for signs of medical identity theft.
| Company | zHealth, Inc. |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Full Names, Medical Information, Health Insurance Information |
| People Affected | 118,563 individuals |
| Attack Method | Unauthorized Network Access |
| Regulators Notified | California Attorney General |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the zHealth Data Breach?
zHealth, Inc. has confirmed a data breach that may have let an unauthorized party access sensitive patient information. The company operates cloud-based practice management and electronic health records software used by healthcare providers. Because of this role, zHealth stores medical and insurance data belonging to patients across many practices.
According to the company’s breach notice, zHealth first became aware that data may have been copied around June 2026. This discovery led to a deeper investigation into the scope of the incident. That investigation ultimately traced unauthorized network access back to a narrow window in January 2026, meaning intruders may have been inside the system for months before detection.
Once the suspicious activity was confirmed, zHealth launched a formal forensic review to determine exactly what happened and what data was involved. This review took several months to complete, finishing in early September 2026. As a result, the full scope of the zHealth data breach was not confirmed until nearly nine months after the initial intrusion occurred.
Because the review process was extensive, notification to affected individuals came well after the original access. This gap is common in complex breach investigations involving large volumes of healthcare data. Still, it means potentially affected individuals had no way to protect themselves until the notice went out in September 2026.
Who was affected?
The zHealth data breach affected patients whose information was stored or processed through the company’s software platform. Because zHealth serves multiple healthcare practices, the affected population likely spans numerous providers and geographic areas. Patients may not even be aware their provider used zHealth’s systems.
According to notifications sent to state regulators, the breach affected 118,563 individuals. This number was confirmed through zHealth’s disclosure to the Oregon Attorney General. Meanwhile, the incident does not currently appear on the federal HHS Office for Civil Rights breach portal, though that could change as reporting continues.
It remains unclear exactly which practices or patient populations were most affected. However, given the nature of practice management software, both current and former patients of client providers could be included. Anyone who has received care from a provider using zHealth’s platform should consider themselves potentially affected.
What Information Was Potentially Exposed?
zHealth has stated that the specific data exposed varies by individual. This means not every affected person had the same categories of information compromised. Still, the company has identified several types of data that may have been accessed.
- Full names
- Medical information
- Health insurance information
Exposed medical information can be especially damaging because it cannot be changed like a password or credit card number. Once health details are exposed, they remain permanently associated with that individual. This creates lasting risk that extends far beyond the initial breach event.
In addition, exposed health insurance information can be used to commit medical identity theft. Criminals may use stolen insurance details to fraudulently obtain medical services or prescriptions. As a result, victims could face incorrect medical records, denied claims, or unexpected bills tied to care they never received.
What is the company doing?
In response to the breach, zHealth reviewed and strengthened its data privacy and security policies. This step is intended to reduce the chance of a similar incident happening again. The company also completed a full internal investigation before notifying affected individuals.
To help affected individuals, zHealth is offering single-bureau credit monitoring, along with credit report and credit score services, for 12 months at no cost. This offer gives affected patients a way to watch for suspicious financial activity tied to the breach. Additionally, zHealth filed a formal notification with the California Attorney General to comply with state breach notification requirements.
Beyond these immediate steps, zHealth appears to be continuing its compliance efforts as more state notifications are processed. Because breach reporting requirements vary by state, additional details may still emerge. Affected individuals should watch for official mailed notices explaining exactly what information was involved in their case.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Affected individuals should take advantage of the credit monitoring service zHealth is offering. This service can help detect unauthorized accounts or unusual credit activity early. Catching problems quickly often limits the damage caused by identity theft.
In addition to the offered service, it’s wise to request free copies of your credit reports from all three major bureaus. Reviewing these reports regularly helps you spot inconsistencies you might otherwise miss. If you notice unfamiliar accounts or inquiries, report them immediately to the credit bureau involved.
Watch for Medical Identity Theft
Because medical and insurance information was involved, patients should carefully review any insurance statements they receive. Look for services or claims you don’t recognize. This could indicate someone else is using your insurance details fraudulently.
If you spot a suspicious claim, contact your insurance provider right away. You should also request a copy of your medical records to check for inaccuracies. Correcting fraudulent entries early can prevent complications with future medical care or coverage.
Stay Alert for Phishing Attempts
Following a breach like this, scammers often try to exploit fear by sending fake emails or texts. These messages may pretend to be from zHealth, a healthcare provider, or a credit monitoring service. Because of this, affected individuals should be cautious with any unexpected communication referencing the breach.
Never click links or share personal details in response to unsolicited messages. Instead, go directly to the official zHealth website or contact your provider using a known phone number. This simple habit can prevent scammers from tricking you into giving up sensitive information.
Consider a Fraud Alert or Credit Freeze
If you’re concerned about identity theft risk, placing a fraud alert on your credit file is a strong protective step. A fraud alert requires lenders to verify your identity before opening new credit in your name. This makes it harder for criminals to misuse your information.
For even stronger protection, consider a credit freeze, which restricts access to your credit file entirely. While this adds an extra step when you apply for credit yourself, it significantly reduces fraud risk. Given the exposure of health insurance information, this precaution may be worth the added inconvenience.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
Official data breach notification from California Attorney General
