TPSC Data Breach Affects PII & PHI

Published
September 16, 2025
Updated
September 16, 2025
TPSC Data Breach Affects PII & PHI
Trusteed Plans Service Corporation
Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info

Affected by the

Trusteed Plans Service Corporation

data breach?

Join the Lawsuit

It's free to join. 

Banner advertisement for ExpressVPN to take control of your online security

Claim Depot may receieve a commission from links on this page

Trusteed Plans Service Corporation (TPSC), a third-party administrator specializing in employee benefit plan administration, experienced a major data breach. On Dec. 26, 2024, the company identified suspicious activity within its internal network. An investigation determined that a cybercriminal gained access and obtained sensitive data from the TPSC computer environment.

A review was completed on Aug. 7, 2025 and revealed that both personally identifiable information (PII) and protected health information (PHI) may have been compromised. Exposed data may include names, addresses, dates of birth, Social Security numbers, health insurance information and medical information. The total number of individuals has not been released, but is believed to be in the thousands.

The breach was officially disclosed to the California Attorney General’s office on Sept. 15, 2025. Trusteed Plans Service Corporation began notifying impacted individuals by mail on the same day.

Trusteed Plans Service Corporation's response

In response to the breach, TPSC disconnected network access, changed administrative credentials and restored operations in a safe and secure mode. The company is also providing impacted individuals 12 months of free cyber monitoring services through HaystackID, a company specializing in fraud assistance and remediation. Similar services are being offered to minors and estates of deceased individuals whose information was compromised in the cybersecurity incident.

If you receive a data breach notice from Trusted Plans Service Corporation, your employer or your insurer, you may want to:

  • Sign up for the free cyber monitoring services, provided by the company.
  • Monitor your credit reports and financial accounts for any unusual activity.
  • Be alert for phishing emails or phone calls that may use your exposed information.
  • Consider placing a fraud alert or credit freeze with major credit bureaus.

For more information about the company, visit the official TPSC Benefits website.

Protect Your Data

A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.

This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image