Valley Family Health Care (VFHC), a provider serving communities in Idaho and Oregon, disclosed to the US Department of Health and Human Services that 4,300 patients were affected by the broader TriZetto Provider Solutions (TPS) breach, which began in November 2024. Reporting on the TriZetto incident indicated that healthcare organizations were continuing to notify patients after protected health information was stolen through the vendor, extending the fallout from the third-party compromise into 2026.
VFHC then faced a separate and potentially far larger incident after the threat actor Insomnia listed the organization on its dark web leak site and claimed to have exfiltrated more than one million records. Data later published by the group reportedly included internal documents, patient charts, insurance information, and other highly sensitive PHI; much of the material was described as unencrypted and not password protected, although some files in a "Secure Email" directory were protected. At the time of reporting, VFHC had not publicly disclosed any breach beyond the TPS-related exposure, and the full scope and initial access method for the alleged Insomnia theft had not been confirmed.

See the actors and campaigns active against you right now.
8 events from the most recent confirmed update back to the earliest known activity.
The Oncology Institute disclosed that patient information was affected in a cybersecurity incident involving a third-party software provider. The company said it was notified on 2026-05-20 that unauthorized access at the vendor affected its patient data, and indicated other healthcare providers may also be impacted.
DataBreaches published findings on an apparent second VFHC breach, noting it could not confirm the full scale of the alleged theft or how Insomnia gained access. VFHC had not responded to inquiries by publication time and had not publicly disclosed any breach beyond the TriZetto incident.
After listing VFHC, Insomnia later released a tranche of alleged stolen data. Reported contents included internal documents, patient charts, insurance information, and other protected health information, much of it apparently unencrypted.
A Fox News report said the cyberattack affecting TriZetto Provider Solutions exposed 3.4 million patient records, indicating the incident was far broader than the previously documented impact on Valley Family Health Care alone. The report represents a new public accounting of the overall scale of the TriZetto-related breach.
On March 7, 2026, the threat actor Insomnia added Valley Family Health Care to its dark web leak site and claimed to have exfiltrated more than one million records containing sensitive patient information. The claim represented a separate incident from the TriZetto breach.
On 2026-02-06, the Office of the Vermont Attorney General published a consumer breach notice concerning the TriZetto Provider Solutions incident. The notice marked a separate official notification step following Valley Family Health Care's earlier HHS disclosure of patient impact.
On January 12, 2026, Valley Family Health Care disclosed to the U.S. Department of Health and Human Services that 4,300 patients were affected by the TriZetto Provider Solutions breach. This was the only VFHC breach publicly disclosed at that time.
Valley Family Health Care said the TriZetto Provider Solutions incident affecting its patients began in November 2024. The breach ultimately impacted 4,300 VFHC patients.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
5 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcedatabreaches.net
Open sourcefoxnews.com
Open sourceago.vermont.gov
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.