Wire flash
TechTriWest Healthcare Alliance: Nearly 12,000 Tricare Beneficiaries Warned of Data Breach
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
TriWest Healthcare Alliance, the managed care contractor for the Tricare West Region, notified 11,844 beneficiaries of a data breach discovered on April 16, 2026. An unauthorized person gained limited access to TriWest information and downloaded it, potentially exposing protected health information including names, Department of Defense Benefits Numbers, and ZIP codes. In fewer than five instances, Social Security numbers, addresses, and dates of birth were also compromised. TriWest stated they are unaware of any misuse of the information and is offering 24 months of free credit monitoring through Experian. The company has taken steps to prevent future incidents, including increasing security controls for password resets, strengthening system access monitoring, and providing additional employee education on cyber attacks. Beneficiaries are advised to enroll in credit monitoring by the deadline in their notification letter and to report suspicious activity to the TriWest Healthcare Alliance Breach Response Line.
Source report
TriWest Healthcare Alliance officials have notified 11,844 beneficiaries of a data breach that may have compromised their protected health information.
Incident Details
In a letter dated July 2 and provided to Military Times, TriWest officials stated that a security incident was discovered on April 16, in which an unauthorized person gained limited access to TriWest information and downloaded it.
"We are unaware of any misuse of your information," officials stated in the letter, though they noted that TriWest is offering free credit-monitoring services for those who feel it is needed.
Information Compromised
The unauthorized individual obtained health-related and other personal information, including:
- Names
- Department of Defense Benefits Numbers
- Beneficiaries' ZIP codes
In fewer than five instances, the compromised data also included Social Security numbers, addresses, and dates of birth.
About TriWest and Tricare
TriWest is the managed care contractor for the Tricare West Region, covering approximately four million beneficiaries. Active duty, retired, National Guard and Reserve members, along with their family members, survivors, and certain former spouses, receive health care under the Department of Defense's Tricare program. Eligibility is determined by the Defense Enrollment Eligibility Reporting System (DEERS).
TriWest is notifying each beneficiary about the specific information involved in their case.
Notification Timeline
The timing of the notifications has raised questions, as at least one letter was dated July 2—approximately two and a half months after the incident occurred.
In an email response to Military Times, TriWest officials explained: "With regard to timing, as soon as the incident was discovered, TriWest took immediate action to prevent any further unauthorized activity and worked diligently with the government to notify affected individuals, consistent with applicable law and notification timelines."
The company hired a third-party forensic expert to review what information was accessed during the incident.
Steps for Beneficiaries
- Credit monitoring: Beneficiaries who wish to use the free credit-monitoring service, offered through Experian for 24 months, should enroll by the deadline provided in their notification letter, using the activation code and instructions included.
- Report suspicious activity: Contact the TriWest Healthcare Alliance Breach Response Line at 1-833-918-1296.
- Identity theft: Beneficiaries who believe they are victims of identity theft should file a report with the Federal Trade Commission at identitytheft.gov.
Preventive Measures
TriWest officials stated that the company has taken steps to prevent future incidents, including:
- Increasing security controls related to password resets
- Strengthening system access monitoring tools
- Providing additional employee education on identifying and mitigating different types of cyber attacks
About the Author
Karen Jowers has covered military families, quality of life, and consumer issues for Military Times for more than 30 years. She is co-author of a chapter on media coverage of military families in the book "A Battle Plan for Supporting Military Families." She previously worked for newspapers in Guam, Norfolk, Jacksonville, Fla., and Athens, Ga.
Source
Military TimesWestern
Part of this Story
TriWest Data Breach Exposes 12,000 Military Tricare Beneficiaries' Information