EpiSource
bd_ba99421fd948eec9 · schema v1 · pii pii-v1
Full breach record for EpiSource →EpiSource, a medical coding vendor, experienced unauthorized access to its AWS environment between February 19-21, 2023. The incident was discovered on February 20, 2023. Affected data may include names, dates of birth, addresses, phone numbers, medical record numbers, health plan IDs, provider information, and clinical data such as diagnoses and medications. Social Security numbers and financial account information were not involved. EpiSource contained the incident, engaged a security firm, and enhanced security controls. Identity theft protection was offered to affected individuals.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_278e1dec2e1b4e36Montana State AGfiled 2023-06-09(7d gap)Verified
- bd_e609d81cc43fbf8fOregon State AGfiled 2023-06-09(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-567518
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 2, 2023
- Raw hash
- d707bebe080619c70647dcbfd4a162bcee61e20c8c683dcb9ec39cfa5728b820
Reporting entity
- Name
- EpiSourcenorm: episource
Victim entity
- Name
- EpiSourcenorm: episource
Incident
- Discovered
- Feb 20, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 15 weeks(102 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.