All Breaches
April 16, 2026 Verified Sensitive Record Healthcare

TriWest Healthcare Alliance 2026 Data Breach

The TriWest Healthcare Alliance 2026 data breach involved unauthorized activity discovered on the organization's network April 16, 2026, and a person accessing and downloading some TriWest information. TriWest stopped further access, obtained outside expert assistance, and reported the event to appropriate authorities. The recipient letter also notes that TriWest administers TRICARE in the West Region.

According to the recipient letter, possible fields were names, Department of defense benefits numbers, Zip codes, and types of authorization requests such as physical therapy. A Texas regulatory filing reports 2,408 people; that figure is a verifiable lower bound, not a nationwide total. LeakData imported no person-level data. At the time of the letter, the organization said it was unaware of misuse of the information.

How Was the TriWest Healthcare Alliance Breach Confirmed?

The primary source is California Attorney General public record SB24-625860 and the TriWest recipient letter published with it. The letter confirms the April 16 discovery, network data download, affected fields, 24 months of Experian support, October 31, 2026 enrollment deadline, and assistance line at 1-833-918-1296.

The Texas Attorney General notification portal provides the population of 2,408 in that state. ClaimDepot combines the regulatory links and notice text and reports the same incident, fields, and July 2 letter date. The sources show that this occurred in TriWest's own network; it is not duplicated as a separate breach at another healthcare provider.

What Happened on April 16, 2026?

TriWest found unauthorized activity on its network April 16. The organization's account says that an unauthorized person accessed and downloaded some TriWest information. TriWest acted immediately to prevent further access, retained an expert to assist with its response, and reported the matter to the appropriate authorities.

The public letter does not disclose the initial-entry method, account or vulnerability used, exact access start and end times, or actor identity. It also does not confirm a ransom demand, malware family, or public release of information. LeakData records only the network access and download finding that the organization confirmed.

What Defense and Healthcare Information Was Involved?

Possible data elements were a person's name, Department of Defense Benefits Number, ZIP code, and type of authorization request. The organization gives physical therapy as an example of a request type. Together, these fields can reveal information about a person's military-health beneficiary status and request context.

The notice does not say that every field was present for every person. It does not list Social Security numbers, dates of birth, full addresses, financial accounts, payment cards, passwords, detailed diagnoses, or treatment notes among the affected fields. LeakData does not expand the categories or add data types absent from the source.

What Risks Come From This Information?

A DoD beneficiary number and a real authorization-request type can make fake verification, appointment, billing, or care-approval messages using the TRICARE or TriWest name more convincing. A ZIP code and name may help narrow a target's identity, but their presence does not by itself mean that a financial account was accessible.

Even if a caller demonstrates knowledge of a real service type, a request for a password, full SSN, payment card, or one-time code should be treated as suspicious. Verify a healthcare-authorization message through independently opened official TriWest and TRICARE channels, rather than using the inbound link or telephone number.

How Many People Were Affected and How Did TriWest Respond?

The Texas record reports 2,408 state residents; no exact, deduplicated nationwide total has been published. Accordingly, pwnCount and totalRecords are null, affectedCountStatus is “lower_bound,” and affectedCountLowerBound is 2408. The lower bound is not zero, but it is also not misrepresented as an exact national total.

TriWest said it increased security controls for network-access resets, expanded system monitoring, and provided employees more training on preventing cyberattacks. Affected people received 24 months of Experian IdentityWorks monitoring, identity restoration, and qualifying identity-theft insurance. The letters are dated July 2, 2026.

What Should Affected People Do?

Recipients can enroll before the end of October 31, 2026, using the activation code in their own letter. Review healthcare authorization requests, statements, and unfamiliar provider communications. Verify a suspicious change directly through TriWest or the relevant official healthcare program rather than replying to the incoming contact.

For unexpected communications using the TRICARE, TriWest, or Experian name, independently open the official site instead of following an inbound link. The assistance line at 1-833-918-1296 is available weekdays from 8 a.m. to 8 p.m. Central Time. Do not disclose a password, full identifier, or one-time code to a caller who merely knows real details.

0
Affected Accounts
5
Data Types
Low
Severity
Yes
Verification

Exposed Data Types

5
Personal information
First and last names
Department of defense benefits numbers
Zip codes
Healthcare authorization request types

Additional Information

Added DateJuly 27, 2026
Breach DateApril 16, 2026
Domaintriwest.com
SourceState regulatory notice confirming unauthorized TriWest network access and downloading of beneficiary-related information
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information