
zHealth EHR, a cloud-based practice management and electronic health records platform designed for wellness providers, disclosed a data breach involving unauthorized access to its network environment.
The company began notifying affected individuals on Sept. 3, 2026. The company posted a notice of the data event on its website on Sept. 10, 2026.
An unauthorized third party copied certain information from the zHealth network environment between Jan. 20 and Jan. 21, 2026. The breach went undetected until June 15, 2026.
On Jan. 26, 2026, Kazu, a threat actor, posted on the dark web, claiming to have obtained 15 GB of data from zHealth EHR. The compromised dataset reportedly contained over 1.2 million records, including patient medical information, clinical notes, appointment and intake details, and billing and payment data. The threat actor stated an intention to publish the stolen data within 22 to 23 days.
A comprehensive review of the potentially impacted data was conducted to determine what sensitive or personal information may have been affected and to identify the individuals involved.
The types of information potentially exposed include names, medical information and health insurance information.
zHealth is offering affected individuals credit monitoring and identity protection services at no cost. These services are intended to help those affected monitor for any unusual activity tied to their personal information.
The company also encouraged affected individuals to remain vigilant against incidents of identity theft and fraud.
Individuals who did not receive a notification letter but want to know if they were affected can call zHealth's dedicated assistance line at 1-866-899-5709. The line is available Monday through Friday from 8 a.m. to 8 p.m. Eastern time, excluding major U.S. holidays.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)