OPTION CARE HEALTH, INC.
ent_019e07a2505da5a4db326b5a3c3677c4
Disclosures
6
HHS OCR · State AG · SEC 8-K · 4 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
2,897
nationwide · HHS OCR IL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- OPTION CARE HEALTH, INC.
- Normalized
- option care health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DI3Q5ACSYJRI17
- SEC EDGAR CIK
- 0001014739
- Domain
- optioncare.com
Disclosure history (6)newest first
- ILHHS OCRas victim2026-04-06
Option Care Health, Inc. (IL) reported to HHS OCR on 2026-04-06 a Hacking/IT Incident affecting 1,891 individuals. Breached information was located on Email. No business associate was identified as present. No further detail is available from the HHS web description.
- 🐻California State AGas victim2026-01-01
Option Care Health, Inc. discovered that an employee's email account was accessed without authorization between February 6–9, 2026. The incident was identified on February 26, 2026. Potentially accessed information included names, dates of birth, medical record numbers, and treatment information. A forensic security firm was engaged to assist. The notice was filed with the California AG.
- ILHHS OCRas victim2024-11-15
Option Care Health reported to HHS on 2024-11-15 a Hacking/IT Incident affecting 2897 individuals. Breached information located on Email. An employee was the subject of an email phishing scheme that compromised PHI including SSNs, birthdates, addresses, and diagnoses.
- 🦬Montana State AGas victim2024-11-15
Option Care Health reported a data breach to the Montana Attorney General. The breach was reported on 2024-11-15. The breach occurred from 07/31/2024 to 08/01/2024. 17 Montana residents were affected.
- 🐻California State AGas victim2024-11-15
Option Care Health notified patients that an unknown party briefly accessed an employee's email inbox on July 31, 2024. The company became aware of the issue on August 1, 2024, and terminated access. Forensic analysis determined that Protected Health Information (PHI) and basic identity information may have been impacted. The company reset passwords, restricted access, and engaged Kroll for identity monitoring services.
- FEDERALSEC 8-Kas reporting2024-03-14
Option Care Health, Inc. filed an 8-K disclosing that Change Healthcare, a subsidiary of UnitedHealth Group, experienced a cybersecurity incident on February 21, 2024. Option Care Health disconnected from Change Healthcare's systems on that date and has not identified any compromise of its own systems. The incident caused operational disruptions, preventing the processing of over half of the Company's claims, impacting cash flow and patient care operations.