Data Breach & Privacy
Blog > Data Breach & Privacy
ServiceTitan Data Breach: What Affected Individuals Need to Know
ServiceTitan, a Glendale, California software company serving contractors and trades businesses, reported a hacking incident involving protected health information to federal regulators in July 2026, with 4,851 individuals listed as affected. Here is what has been disclosed so far, what has not, and what affected individuals can consider doing.

What Happened in the ServiceTitan Data Breach
A hacking incident reported to federal regulators in July 2026
According to the U.S. Department of Health and Human Services Office for Civil Rights breach portal, ServiceTitan, Inc. submitted a breach report on July 27, 2026. The portal categorizes the incident as a hacking/IT incident, lists the location of the breached information as a network server, and records 4,851 individuals as affected.
Federal law requires HIPAA-covered entities to report breaches of unsecured protected health information affecting 500 or more individuals, and the portal indicates the ServiceTitan report is among those currently under investigation. Beyond the federal listing, ServiceTitan has not published a public statement describing the incident, and a notification letter has not been located on the public breach lists maintained by the California, Vermont, or Massachusetts attorneys general as of this writing. When the incident occurred, when it was discovered, and how it happened have not been publicly detailed.
What Information May Have Been Involved
Protected health information that has not been publicly itemized
Because the incident was reported to the Office for Civil Rights as a HIPAA breach, it is understood to involve protected health information. However, the specific categories of data, such as names, dates of birth, Social Security numbers, health plan or claims information, or medical details, have not been publicly itemized as of the portal listing.
Health plan records commonly combine identifying information with insurance and claims details, so affected individuals may wish to treat the situation with appropriate caution until more is known. Individual notification letters would typically describe the information involved for each person, and where health-related data may have been exposed, there can be an increased risk of medical identity theft, fraud, or targeted phishing, even where no misuse has been reported.
Who May Be Affected by the ServiceTitan Breach
Likely members of a company-sponsored health plan, not software customers
ServiceTitan, Inc. is a publicly traded cloud software company headquartered in Glendale, California, whose platform is used by home-services contractors and other trades businesses. Notably, the federal breach portal lists the reporting entity type as a health plan rather than a healthcare provider or business associate. That classification suggests the affected information relates to a health plan sponsored by the company, such as an employee benefit plan, rather than to data from ServiceTitan’s software customers, though the company has not publicly confirmed who the affected individuals are.
The HHS portal lists 4,851 affected individuals. Individuals whose information was involved would generally receive a written notification describing the specific data at issue and any resources being offered. If you are a current or former ServiceTitan employee, a dependent covered under a ServiceTitan-sponsored plan, or otherwise received a letter from ServiceTitan referencing a data security incident, that notice may indicate your information was among the data reported to have been affected.
How ServiceTitan Has Responded
What is known and what to watch for
Beyond the federal breach report, ServiceTitan has not published a detailed public statement describing its response, and no notice about the incident was located on the company’s public website as of this writing. Organizations responding to incidents of this kind commonly engage cybersecurity specialists, notify law enforcement, and review their security controls, but the company has not publicly confirmed which steps it has taken.
If ServiceTitan is offering complimentary credit monitoring or identity protection services, those details would typically appear in individual notification letters. Affected individuals may want to review any letter they receive carefully and follow its instructions for enrolling in any services offered before the stated deadline.
Steps You Can Take to Protect Yourself
Practical precautions while details remain limited
While the details of the ServiceTitan incident are still emerging, affected individuals may wish to consider a few precautionary steps:
- Watch for a notification letter. It may describe the specific information involved and any services being offered.
- Review your Explanation of Benefits statements. Watch for medical claims or services you did not receive, which can be a sign of medical identity theft.
- Check your credit reports. You are entitled to free annual credit reports at annualcreditreport.com, and you can watch for accounts or inquiries you do not recognize.
- Consider a fraud alert or credit freeze. These are available at no cost through Equifax, Experian, and TransUnion and can add a layer of protection.
- Stay alert to phishing. Be cautious of unexpected emails, calls, or texts referencing ServiceTitan, your health plan, or the incident, and verify any outreach independently before responding.
This information is a general overview and is not legal advice; your situation may differ, and consulting a legal professional can help you understand rights that may apply to you.
Talk to Wilshire Law Firm
Were you affected by the ServiceTitan data breach?
If your health information or personal data may have been involved in the ServiceTitan data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.
Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.
FAQs
ServiceTitan, Inc. submitted a breach report to the U.S. Department of Health and Human Services on July 27, 2026. The dates on which the unauthorized activity occurred or was discovered have not been publicly detailed.
The HHS Office for Civil Rights portal categorizes the incident as a hacking/IT incident involving a network server. ServiceTitan has not publicly described the specific method of access.
Because the incident was reported as a HIPAA breach, it is understood to involve protected health information, but the specific categories have not been publicly itemized. Individual notification letters would typically describe the information involved for each person.
The HHS Office for Civil Rights breach portal lists 4,851 individuals as affected by the ServiceTitan, Inc. incident.
The federal portal lists ServiceTitan as a health plan for purposes of this report, which suggests the affected information relates to a company-sponsored health plan, such as an employee benefit plan, rather than to its software customers. ServiceTitan has not publicly confirmed who the affected individuals are.
The company has not publicly announced whether complimentary credit monitoring or identity protection services are being offered. Any such services would typically be described in the individual notification letter, so it is worth reviewing any notice you receive.
Individuals who believe they were affected may have legal options, and data breaches involving protected health information can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts. A free case review with a legal professional can help you understand your potential rights.

