
ZenPatient, Inc., a Santa Monica, California-based digital health and telehealth software company, has reportedly suffered a significant data breach that may have compromised sensitive patient information. The Attorneys General of Texas and California have reported on the incident.
The company develops branded, direct-to-consumer healthcare platforms for providers, pharmacies, and related services. It also partners with pharmacies to facilitate medication delivery for both human and veterinary patients. Given the nature of its work, ZenPatient manages large volumes of protected health information (PHI) and personally identifiable information (PII) on behalf of its clients and their patients. Contact our data breach attorneys to learn more.
According to public reports, unauthorized access to ZenPatient systems occurred between early December 2025 and mid-February 2026. The incident was reportedly detected in late February 2026, with formal notifications and public disclosure following several months later.
As is common in healthcare technology breaches, the full scope, including the exact categories of data accessed and the precise number of individuals affected, may not be fully known until ZenPatient issues additional notifications or regulatory filings become available.
In incidents like this, exposed information often includes:
Healthcare data breaches hit especially hard because patients rarely have any direct relationship with the vendor that holds their information. Yet their most private details—medical histories, prescriptions, and insurance data—can still be exposed.
Stolen health data is particularly valuable to cybercriminals. It can fuel identity theft, insurance fraud, medical identity theft, phishing attacks, and long-term exploitation that may not surface for months or even years. Victims often face ongoing stress, financial losses, and the burden of monitoring their credit and accounts for years afterward.
If you received a notification letter from ZenPatient or one of its partner providers about this incident, take it seriously. You may have important legal rights and options for recourse.
The Lyon Firm has a strong track record representing individuals and classes affected by healthcare data breaches across the country. Our attorneys are well-versed in HIPAA, data privacy laws, and the obligations companies have to safeguard sensitive health information.
We hold organizations accountable when they fail to implement reasonable security measures to protect the data entrusted to them. Clients benefit from decades of combined experience in data privacy and class action litigation and a proven history of securing meaningful settlements for breach victims.
If your personal or protected health information may have been compromised in the ZenPatient data breach, contact The Lyon Firm today for a free consultation. Our attorneys will help you understand your rights, assess your situation, and determine whether you may be entitled to compensation.
References to ZenPatient, Inc. are based on publicly available reports at the time of writing and may be updated as additional information becomes available. Nothing in this article should be construed as a final determination of wrongdoing by any company named.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: