EpiSource
bd_ba99421fd948eec9 · schema v1 · pii pii-v1
Full breach record for EpiSource →4 incidents on fileEpiSource, a medical coding vendor, experienced unauthorized access to its AWS environment between February 19-21, 2023. The incident was discovered on February 20, 2023. Affected data may include names, dates of birth, addresses, phone numbers, medical record numbers, health plan IDs, provider information, and clinical data such as diagnoses and medications. Social Security numbers and financial account information were not involved. EpiSource contained the incident, engaged a security firm, and enhanced security controls. Identity theft protection was offered to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Feb 19, 2023
Begins
Feb 20, 2023
Discovered
Jun 2, 2023
Filed
vs. sector median
+4 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- HHS OCRbd_2b5d69aa74007bf32023-06-02Verified
- Montana State AGbd_278e1dec2e1b4e362023-06-09 · +7dVerified
- Oregon State AGbd_e609d81cc43fbf8f2023-06-09 · +7dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Pattern: first filing Jun 2 (MN), last Jun 9 (OR) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.