HackingData ExfiltratedCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
EpiSource
bd_9fdbc50e284e387e · schema v1 · pii pii-v1
Full breach record for EpiSource →Episource, LLC disclosed a data breach affecting health insurance and medical data. Unauthorized access occurred between January 27 and February 6, 2025, and was discovered on February 6, 2025. The attacker viewed and copied data including contact info, health plans, diagnoses, and treatments. Systems were taken offline and law enforcement notified. Credit monitoring offered.
California clockDiscovered Feb 6, 2025 → Notified Sep 22, 2025228d ✗ CA 60-day late33 weeks discovery → filing
This filing is one of 14 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- bd_f7b2fef6a5a68d49California State AGfiled 2025-10-01(9d gap)Verified by operator
- bd_1b92ab769d91dc2aCalifornia State AGfiled 2025-09-11(11d gap)Verified by operator
- bd_9fbf33f1d80fd6cdCalifornia State AGfiled 2025-10-15(23d gap)Verified by operator
- bd_8bfabd788a54c7ddMontana State AGfiled 2025-11-12(51d gap)Verified by operator
Show 6 more filings ↓Show fewer ↑up to 108d gap
- bd_00920f0067d5e69dCalifornia State AGfiled 2025-07-31(53d gap)Verified
- bd_95baeb3422bb54e2Montana State AGfiled 2025-07-31(53d gap)Verified
- bd_b89e0c880448cf1bCalifornia State AGfiled 2025-07-11(73d gap)Verified
- bd_a777c7526ecf94bdOregon State AGfiled 2025-12-11(80d gap)Verified by operator
- bd_61b844bea6eb84e8Oregon State AGfiled 2025-06-06(108d gap)Candidate
- bd_63544f6aac5ae4a4Washington State AGfiled 2025-06-06(108d gap)Verified
Showing first 10 of 13 linked disclosures.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-610396
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 22, 2025
- Raw hash
- eca038e640343d14440447bb89f7178dc89ff47d766ede256f10bd841c5082bd
Reporting entity
- Name
- EpiSourcenorm: episource
Victim entity
- Name
- EpiSourcenorm: episource
Incident
- Discovered
- Feb 6, 2025
- Materiality determined
- —
- Notification sent
- Sep 22, 2025
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Called law enforcement
Compliance
- Time to disclose
- 33 weeks(228 days from discovery to filing)
- Compliance flags
- CA 60-day late · 228d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 6, 2025→ Notified: Sep 22, 2025228d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.