zHealth, Inc. Reports Data Breach to California Attorney General
zHealth, Inc., a healthcare technology software provider, officially reported a data breach incident to the California Attorney General's office. The breach, which occurred in January 2026, involved sensitive personal and medical information. This filing provides public record of the compromised data for affected individuals.
- State
- California
- Breach date
- January 20, 2026
- Reported
- September 11, 2026
What may have been exposed
- Full Name
- Date of Birth
- Social Security Number
- Medical Record Number
- Health Insurance ID Number
- Diagnosis and Treatment Information
- Billing and Payment History
- Provider and Treatment Dates
zHealth, Inc., a company specializing in software solutions for chiropractic and allied health practices, filed a data breach notification with the California Attorney General's office. The reported incident took place on January 20, 2026, with the official notification filed on September 11, 2026. This public record confirms that an unauthorized access event affected the company's network infrastructure.
The data types reported as exposed include Full Name, Date of Birth, Social Security Number, Medical Record Number, Health Insurance ID Number, Diagnosis and Treatment Information, Billing and Payment History, and Provider and Treatment Dates. The comprehensive nature of this information means individuals should be aware of potential risks.
Individuals who received a notification from zHealth, Inc. should consider monitoring their financial and medical accounts for any unusual activity. It is advisable to review explanation of benefits (EOB) statements from health insurers and medical bills to identify any unauthorized services or charges. Placing a fraud alert or security freeze on credit reports can also help protect against identity theft.
This information is based on the official data breach filing made by zHealth, Inc. to California regulators. The details provided here are intended to help individuals understand the nature of the reported breach as documented in public records. The investigation status of this incident is currently listed as monitoring.
Source: Attorney General filing