zHealth Inc. Data Breach: What Your Notification Letter Means
zHealth, Inc. reported a data breach in 2026 that exposed sensitive personal and medical information. If you received a notification letter, your Full Name, Date of Birth, Social Security Number, and health data may have been compromised. This exposure can lead to long-term risks like identity theft and medical fraud.
- State
- Oregon
- Breach date
- January 20, 2026
- Reported
- September 11, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Prescription Information
- Provider and Treatment Dates
zHealth, Inc., a company providing digital practice management and electronic health record (EHR) software, reported a data breach to the Oregon Attorney General in September 2026. This incident, which occurred on January 20, 2026, involves the compromise of sensitive personal and medical information stored within their systems.
According to the breach notification, the exposed information includes your Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Prescription Information, and Provider and Treatment Dates. The nature of this data means it is highly sensitive and carries significant risk.
Unlike a credit card number that can be easily changed, much of this exposed data, particularly your Social Security Number and medical history, is permanent. This type of information can be used for various forms of identity theft, including financial fraud, tax fraud, or targeted medical fraud where unauthorized parties might seek healthcare services using your identity.
If you received a data breach notification from zHealth, Inc., it's important to monitor your financial accounts and credit reports for any suspicious activity. Regularly review your Explanation of Benefits (EOB) statements from your health insurer for unauthorized medical procedures. You may also consider placing a fraud alert or credit freeze on your credit files to help protect against identity theft.
Companies like zHealth, Inc. are required by law to protect your sensitive data through robust security measures. The occurrence of a breach raises questions about whether these safeguards were sufficient. Receiving a notification letter establishes your standing to seek legal recourse. Our firm is currently investigating potential claims against zHealth, Inc. for affected individuals and offers a free case review to help you understand your options without any upfront cost.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Oregon Attorney General filing
Related data breach cases
- Kaniksu Community Health
- Craneware, Inc.
- See's Candies - Corporate Office
- Greenberg Traurig, LLP (“GT”)
- Northwest Paper Box Manufacturers
- Quatrro Business Support Services, Inc.
- ASOS US Sales LLC
- BestCare treatment Services, Inc.
- Catalyst Brands LLC
- Bimbo Bakeries USA
- American Addiction Centers
- Boston Health Care for the Homeless Program
- RB American Group LLC
- Integrated Specialty Coverages, LLC (“ISC”)