Epic
ent_48b9a9b386b136f1e1bf9ac2
Disclosures
4
State AG · HHS OCR · 4 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
10,050
as filed · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Epic
- Normalized
- epic— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300NPX3D3TA7JN323
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- getepic.com
Disclosure history (4)newest first
- 🐻California State AGas reporting2023-03-08
On January 24, 2023, Beaver Medical Group (BMG) / Epic Management LLC (EPIC), part of Optum, detected unusual activity on an employee workstation. An unauthorized third party launched a targeted phishing attack, gaining temporary access to certain emails and records. The incident involved names, member IDs, health plan names, and premium payment amounts. No SSNs, clinical info, or financial account data were compromised. Security controls were enhanced.
- ⛰️New Hampshire State AGas victim2022-12-14
Epic Management LLC, a nursing home operator, notified the NH Attorney General of a data security incident discovered on September 2, 2021. An unauthorized actor accessed files in Epic's email tenant, potentially exposing PII, SSNs, health info, and financial data. Three NH residents were notified on December 14, 2022. Epic engaged forensic experts and offered credit monitoring.
- 🦞Maine State AGas victim2022-12-13
Epic Management LLC reported a data breach affecting 10,050 individuals. The incident, described as an external system breach (hacking), occurred between March 2, 2021, and October 9, 2021, but was not discovered until December 9, 2022. The compromised information included names and financial account or credit/debit card numbers along with their security codes or PINs. Epic Management offered affected individuals 12 months of credit monitoring services through IDX.
- TNHHS OCRas victim2022-11-14
Epic Management LLC reported to HHS on 2022-11-14 a Hacking/IT Incident affecting 10,050 individuals. Breached information located on Email. The covered entity ceased all operations and the investigation was closed.