EpiSource
bd_1b92ab769d91dc2a · schema v1 · pii pii-v1
Full breach record for EpiSource →Episource, LLC reported unauthorized access to its computer systems between January 27, 2025, and February 6, 2025. The incident involved the exfiltration of protected health information (PHI), including medical records, diagnoses, and treatment data, as well as personal identifiable information (PII) such as names, addresses, and government IDs. Episource detected unusual activity on February 6, 2025, and contained the incident by shutting down systems. Law enforcement was notified. Affected individuals are offered two years of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_9fdbc50e284e387eCalifornia State AGfiled 2025-09-22(11d gap)Verified by operator
- bd_f7b2fef6a5a68d49California State AGfiled 2025-10-01(20d gap)Verified by operator
- bd_9fbf33f1d80fd6cdCalifornia State AGfiled 2025-10-15(34d gap)Verified by operator
- bd_00920f0067d5e69dCalifornia State AGfiled 2025-07-31(42d gap)Verified
Show 6 more filings ↓Show fewer ↑up to 97d gap
- bd_95baeb3422bb54e2Montana State AGfiled 2025-07-31(42d gap)Verified
- bd_8bfabd788a54c7ddMontana State AGfiled 2025-11-12(62d gap)Verified by operator
- bd_b89e0c880448cf1bCalifornia State AGfiled 2025-07-11(62d gap)Verified
- bd_a777c7526ecf94bdOregon State AGfiled 2025-12-11(91d gap)Verified by operator
- bd_61b844bea6eb84e8Oregon State AGfiled 2025-06-06(97d gap)Candidate
- bd_63544f6aac5ae4a4Washington State AGfiled 2025-06-06(97d gap)Verified
Showing first 10 of 13 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-608454
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 11, 2025
- Raw hash
- 8fd7b8f71738885048f384126d563870b5ba2eff2d648127906cfdfb7e7c7e1d
Reporting entity
- Name
- Sharp Community Medical Group (SCMG)norm: sharp community medical group scmg
Victim entity
- Name
- EpiSourcenorm: episource
Incident
- Discovered
- Feb 6, 2025
- Materiality determined
- —
- Notification sent
- Jun 6, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
Compliance
- Time to disclose
- 31 weeks(217 days from discovery to filing)
- Compliance flags
- CA 60-day late · 120d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 6, 2025→ Notified: Jun 6, 2025120d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.