DisclosureLens
Social EngineeringHealthcareHealthcarePhishingTargetedCustomer Data InvolvedIdentity (basic)Health (basic)LowContained

Beaver Medical Group (BMG) / Epic Management LLC (EPIC)

bd_d6f4dce472358f95 · schema v1 · pii pii-v1

Severity

Low

Discovered

Jan 24, 2023

Filed

Mar 8, 2023

To disclose

6 weeks

Affected

Not disclosed

Confidence

66%
Full breach record for Beaver Medical Group (BMG) / Epic Management LLC (EPIC)

On January 24, 2023, Beaver Medical Group (BMG) / Epic Management LLC (EPIC), part of Optum, detected unusual activity on an employee workstation. An unauthorized third party launched a targeted phishing attack, gaining temporary access to certain emails and records. The incident involved names, member IDs, health plan names, and premium payment amounts. No SSNs, clinical info, or financial account data were compromised. Security controls were enhanced.

Incident timeline

discovery → filing · 6 weeks / 43 days

Jan 24, 2023

Begins

Jan 24, 2023

Discovered

Mar 8, 2023

Filed

vs. sector median

6 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.