The breach occurred over a two-day span between January 20 and January 21, 2026, though the company did not discover the unauthorized network access until mid-June. Following a forensic review that concluded on September 3, zHealth began notifying victims on September 11. The compromised data includes names, medical histories, and health insurance details, which experts warn carry long-term risks for fraud and misuse.
zHealth has initiated a response protocol, providing affected parties with 12 months of credit monitoring services while asserting that it has updated its internal security policies. Meanwhile, Edelson Lechtzin LLP is offering free consultations to those impacted, advising victims to secure their notification letters and monitor financial statements for unauthorized activity. The firm is evaluating whether a class action lawsuit is appropriate given the scope of the sensitive information exposed.




Comments (0)
No comments yet. Be the first!