Episource breach exposed health records of more than 5.4 million people
- Organization
- Episource
- Exploit
- Hacking
- Industry
- Healthcare
Episource, a California company that provides medical coding and risk adjustment services to health plans and providers, disclosed in June 2025 that attackers had copied data from its systems earlier in the year. The company said it detected unusual activity on February 6, 2025 and powered down its computer systems, then determined that an intruder had been able to view and copy files between January 27 and February 6.
The breach was reported to the U.S. Department of Health and Human Services Office for Civil Rights as affecting 5,418,866 individuals, placing it among the largest healthcare breaches disclosed in 2025. Cybersecurity Dive noted that at the time it ranked second among healthcare breaches reported to federal regulators that year, behind Yale New Haven Health System.
Episource said the exposed information varied by person and could include names, addresses, telephone numbers, email addresses, dates of birth, Social Security numbers, health plan and Medicare or Medicaid identification numbers, medical record numbers, and clinical details such as diagnoses, prescriptions, test results, imaging and treatment records.
The company notified law enforcement, coordinated with the health plans and providers whose members were affected, and began sending letters on a rolling basis from April 23, 2025. It set up a dedicated call line, offered complimentary credit monitoring and identity theft protection, and told recipients to review benefit statements for services they did not receive. Episource said it was not aware of any misuse of the data. The reported total later rose, with HHS records subsequently updated to 6,725,572 individuals.
Updates
-
The total Episource reported to the HHS Office for Civil Rights was revised upward to 6,725,572 people, from the 5.4 million confirmed in June 2025.