Asian Americans for Community Involvement Data Breach

Asian Americans for Community Involvement (AACI) has notified patients that their personal and health information was exposed in a data breach that did not happen on AACI’s own systems, but at a company several steps down its vendor chain. AACI uses a company called OCHIN, Inc. to run its electronic medical records software. OCHIN, in turn, contracts with TriZetto Provider Solutions (TPS) to handle revenue management services for many healthcare providers, including AACI. TPS operates a web portal where providers can look up historical eligibility and insurance records, and it was that portal that was compromised. TPS says an unauthorized actor had access to certain historical eligibility transaction reports from November 2024 until October 2, 2025, when the intrusion was discovered and shut down. This falls under hacking or system intrusion, and TPS reports there is no evidence the unauthorized actor downloaded any of the information they could access.

Leave a Comment