HackingStolen CredentialsCapture Stored DataData ExfiltratedCustomer Data InvolvedDownstream VictimsIDENTITY_BASICHEALTH_BASICIDENTITY_GOVERNMENTPHIMediumContained
EpiSource
bd_86be71a38f1e4e1d · schema v1 · pii pii-v1
Full breach record for EpiSource →Episource, LLC, a medical coding and risk adjustment services provider, notified the New Hampshire Attorney General of a data security event. Unauthorized access occurred between Jan 27 and Feb 6, 2025, involving PHI, SSNs, and contact info for patients of Episource's healthcare clients. Episource detected the incident on Feb 6, 2025, engaged forensic investigators, and notified law enforcement. Notices were mailed to 4 NH residents on July 11, 2025.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_62e71d1149df6ffbCalifornia State AGfiled 2025-09-11(59d gap)Candidate
- bd_a2b82676192bff45New Hampshire State AGfiled 2025-09-15(63d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/episource-20250714.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 14, 2025
- Raw hash
- 95dbddc304cdaaea201b2ad0c33c0e9755eda28fd29d8763767ab3660552d826
Reporting entity
- Name
- EpiSourcenorm: episource
Victim entity
- Name
- EpiSourcenorm: episource
Incident
- Discovered
- Feb 6, 2025
- Materiality determined
- —
- Notification sent
- Jul 11, 2025
- Affected individuals
- 4
- Data types
- IDENTITY_BASICHEALTH_BASICIDENTITY_GOVERNMENTPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Office of the New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 23 weeks(158 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.