DisclosureLens
HackingHealthcareTechnologyHealthcareVulnerability ExploitStolen CredentialsData ExfiltratedCustomer Data InvolvedIdentity (basic)Health (basic)PHILowContained

EpiSource

bd_278e1dec2e1b4e36 · schema v1 · pii pii-v1

Severity

Low

Discovered

Feb 20, 2023

Filed

Jun 9, 2023

To disclose

16 weeks

Affected

2state residents only

Linked

4 filings

Confidence

66%
Full breach record for EpiSource4 incidents on file

Episource, a medical coding vendor, notified Montana residents of a data breach involving unauthorized access to its AWS environment between Feb 19-21, 2023. Suspicious activity was detected on Feb 20, 2023. Compromised data included names, DOBs, addresses, MRNs, and clinical data. No SSNs or financial data were involved. Episource engaged forensic investigators, hardened AWS security, and offered one year of LifeLock identity theft protection.

Incident timeline

undetected · 1 days
discovery → filing · 16 weeks / 109 days

Feb 19, 2023

Begins

Feb 20, 2023

Discovered

Jun 9, 2023

Filed

vs. sector median

+5 wks slower

This filing is one of 4 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (3) · sorted by filing gap

Filing propagation · 4 filings · 4 states

View merged incident ↗
HHS OCRJun 2 · first
California State AGJun 2 · first
Montana State AG+7d · this page

Pattern: first filing Jun 2 (MN), last Jun 9 (MT) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.