DisclosureLens
HackingHealthcareTechnologyHealthcareStolen CredentialsCapture Stored DataData ExfiltratedTargetedIdentity (basic)Government IDHealth (basic)PHIMediumContained

EpiSource

bd_95baeb3422bb54e2 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 6, 2025

Filed

Jul 31, 2025

To disclose

25 weeks

Affected

432state residents only

Linked

24 filings

Confidence

65%
Full breach record for EpiSource4 incidents on file

Episource, LLC notified Montana residents of a data breach occurring between Jan 27 and Feb 6, 2025. Unauthorized access led to the copying of PHI, health insurance data, and PII (SSN, DOB). Episource engaged forensic help, notified law enforcement, and offered 2 years of credit monitoring.

Incident timeline

undetected · 10 days
discovery → filing · 25 weeks / 175 days

Jan 27, 2025

Begins

Feb 6, 2025

Discovered

Jul 31, 2025

Filed

vs. sector median

+14 wks slower

This filing is one of 24 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (10) · sorted by filing gap

Show 6 more filingsup to 195d gap

Showing first 10 of 23 linked disclosures.

Filing propagation · 11 filings · 5 states

View merged incident ↗

Pattern: first filing Jul 31 (MT), last Feb 11 (TX) — a 195-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Cascade drawn from the first 10 linked disclosures of 23 — the full spread may be wider.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.