The Health Trust Data Breach: Personal and Health Information Exposed

Published
August 25, 2026
Updated
August 25, 2026
The Health Trust Data Breach: Personal and Health Information Exposed
The Health Trust
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

The Health Trust, a nonprofit foundation based in San Jose, California, disclosed a data breach involving sensitive personal and health information.

The information involved in the breach was contained in files that had been provided to Financial Administrative Support Services (FASS), a firm that provides finance and accounting services to The Health Trust and other organizations. The notification stated that there is no evidence that The Health Trust's internal client files were involved in the event.

The Health Trust first identified suspicious activity on its computer network on May 26, 2025. In response, the organization took steps to secure its network and restore its systems. Then, on June 11, 2025, further suspicious activity was detected.

The Health Trust brought its systems fully offline at that point to ensure their security and to investigate the nature and scope of the incident.

The investigation found that an unauthorized actor had gained access to certain Health Trust systems during two separate time periods. The first period of unauthorized access occurred at some point before March 26, 2025. The second occurred between June 8, 2025, and June 11, 2025.

During those windows, the actor accessed and/or copied certain information from the organization's systems.

Notably, on June 5, 2025, a ransomware group known as Qilin posted a claim on the Tor network, stating it had obtained 408 gigabytes of data from The Health Trust.

After securing its network, The Health Trust initiated a thorough review of the impacted data to determine what types of information were affected and which individuals' data was involved.

The types of personally identifiable information exposed included names, Social Security numbers, financial account information and government-issued identification. The breach also exposed protected health information, including health insurance information and medical information.

The breach was disclosed to the California Attorney General on Aug. 21, 2026. A notice about the data event was also posted on the FASS website.

The Health Trust began sending notification letters to affected individuals on Aug. 24, 2026.

The Health Trust's response to the breach

The Health Trust is offering affected individuals complimentary credit monitoring and identity protection services through IDX. Depending on the individual, the monitoring period covers either 12 or 24 months.

Affected individuals can enroll through the IDX enrollment page using the enrollment code provided in their notification letter. The deadline to enroll is Nov. 24, 2026.

Those with questions or who need assistance can call a dedicated help line at 1-866-200-0959. IDX representatives are available Monday through Friday from 6 a.m. to 6 p.m. Pacific Time.

Individuals may also write to The Health Trust at 3180 Newberry Drive, Suite 200, San Jose, CA 95118.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
The Health Trust
Consumers Notification date
Date of Breach
prior to 2025-03-26 and between 2025-06-08 and 2025-06-11
Breach Discovered Date
May 26, 2025
Total People Affected
Information Types Exposed
  • Social Security number
  • financial account information
  • government-issued identification
  • health insurance information
  • medical information
  • name
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image