EpiSource
ent_d74ff2644806ee32a3a627f3
Disclosures
25+
State AG · 7 jurisdictions
Incidents
5
filings grouped by incident
Max affected reported
6,584,876
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- EpiSource
- Normalized
- episource— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (newest 25)newest first
- ⭐Texas State AGas victim2026-02-11
Episource, LLC based in Gardena, California, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-11-05 and reported on 2026-02-11. 351,562 Texas residents were affected. 6,725,572 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Health Insurance Information;Date of Birth. Consumers were notified via U.S. Mail.
- ⛰️New Hampshire State AGas victim2026-02-10
Episource, LLC filed a supplemental notice with the New Hampshire Attorney General regarding a prior data security event. The filing states that Episource has completed all notification efforts, mailing final notice letters on February 9, 2026, on behalf of its healthcare provider customers. The filing provides no specific details on the nature of the breach, data types affected, or the number of individuals impacted, stating there are 'no updates' to previous submissions regarding entities or resident counts. The incident status is effectively resolved as notification efforts are complete.
- 🐻California State AGas victim2026-02-09
Episource, LLC reported a data breach where a criminal accessed and copied data between January 27 and February 6, 2025. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, and health data (PHI). This is a supplemental notice sent to individuals for whom addresses were previously unavailable. Episource engaged forensic investigators, notified law enforcement, and shut down systems. Two years of credit monitoring are offered.
- 🐻California State AGas reporting2026-01-26
Episource, LLC reported unauthorized access to its systems between January 27 and February 6, 2025, discovered on February 6. A criminal actor viewed and copied data including PHI (health diagnoses, treatments, medical record numbers), health insurance data, and PII (names, addresses, SSNs, DOBs). The incident affected patients of Episource's customers, including Brown & Toland Physicians. Episource engaged forensic investigators, notified law enforcement, and shut down systems. Two years of credit monitoring were offered.
- 🦫Oregon State AGas victim2025-12-11
Episource, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2025-12-11. The breach occurred during 1/27/2025. The breach was discovered on 2/6/2025. 6,584,876 individuals were affected. Notice was sent on 11/12/2025.
- 🐻California State AGas victim2025-11-12
Episource, LLC disclosed a data breach where a criminal accessed and copied data between January 27, 2025, and February 6, 2025. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments), and in limited instances, Social Security numbers. Episource engaged forensic investigators, notified law enforcement, and shut down systems. They are offering two years of credit monitoring.
- 🦬Montana State AGas victim2025-11-12
Episource, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2025-11-12. The breach occurred from 01/27/2025 to 02/06/2025. 1 Montana residents were affected.
- 🐻California State AGas victim2025-10-15
Episource, LLC reported a data breach where a criminal accessed and copied data from its computer systems between January 27, 2025, and February 6, 2025. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments, medical record numbers), date of birth, and in limited instances, Social Security numbers. Episource engaged a forensic team, notified law enforcement, and shut down systems. It is offering two years of credit monitoring.
- 🐻California State AGas victim2025-10-01
Episource, LLC reported unauthorized access to its computer systems between January 27 and February 6, 2025. An external actor accessed and copied data including contact information, health insurance data, health data (diagnoses, treatments), and other personal data such as Social Security numbers. The incident was discovered on February 6, 2025. Episource engaged forensic investigators, notified law enforcement, and shut down systems. No misuse of data was observed. Credit monitoring was offered.
- 🐻California State AGas victim2025-09-22
Episource, LLC disclosed a data breach affecting health insurance and medical data. Unauthorized access occurred between January 27 and February 6, 2025, and was discovered on February 6, 2025. The attacker viewed and copied data including contact info, health plans, diagnoses, and treatments. Systems were taken offline and law enforcement notified. Credit monitoring offered.
- ⛰️New Hampshire State AGas victim2025-09-15
Episource, LLC submitted a supplemental notice to the New Hampshire Attorney General regarding a data security event. Unauthorized access occurred between January 27 and February 6, 2025, involving PHI and PII of healthcare plan members. The incident affected at least 5 individuals in NH (Blue Shield of California, MCS Healthcare Holdings, United Healthcare). Episource engaged law enforcement, contained systems, and offered credit monitoring.
- 🐻California State AGas victim2025-09-11
Episource, LLC reported unauthorized access to its computer systems between January 27, 2025, and February 6, 2025. The incident involved the exfiltration of protected health information (PHI), including medical records, diagnoses, and treatment data, as well as personal identifiable information (PII) such as names, addresses, and government IDs. Episource detected unusual activity on February 6, 2025, and contained the incident by shutting down systems. Law enforcement was notified. Affected individuals are offered two years of credit monitoring.
- 🐻California State AGas victim2025-09-11
Episource, LLC reported a data breach where a criminal accessed and copied data from its computer systems between January 27, 2025, and February 6, 2025. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments), and other personal data such as date of birth. Episource engaged a special investigation team, notified law enforcement, and shut down impacted systems. It is offering two years of credit monitoring and identity theft protection to affected individuals.
- 🐻California State AGas victim2025-08-22
Episource, LLC reported a data breach affecting patient and member data. Unauthorized access occurred between January 27, 2025, and February 6, 2025, when a criminal viewed and copied data including health insurance details, medical records, and personal information such as names, addresses, and Social Security numbers. The incident was discovered on February 6, 2025. Episource engaged forensic investigators, notified law enforcement, and shut down systems to contain the breach. Affected individuals are offered two years of credit monitoring.
- 🐻California State AGas victim2025-07-31
Episource, LLC disclosed a data breach affecting patient and member data. Unauthorized access occurred between January 27, 2025, and February 6, 2025, when a criminal actor viewed and copied data including health insurance details, medical records, and Social Security numbers. The incident was discovered on February 6, 2025. Episource shut down systems, engaged forensic investigators, and notified law enforcement. Affected individuals are offered two years of credit monitoring.
- 🦬Montana State AGas victim2025-07-31
Episource, LLC reported a data breach to the Montana Attorney General. The breach was reported on 2025-07-31. The breach occurred from 01/27/2025 to 02/06/2025. 432 Montana residents were affected.
- ⛰️New Hampshire State AGas victim2025-07-14
Episource, LLC, a medical coding and risk adjustment services provider, notified the New Hampshire Attorney General of a data security event. Unauthorized access occurred between Jan 27 and Feb 6, 2025, involving PHI, SSNs, and contact info for patients of Episource's healthcare clients. Episource detected the incident on Feb 6, 2025, engaged forensic investigators, and notified law enforcement. Notices were mailed to 4 NH residents on July 11, 2025.
- 🍁Vermont State AGas victim2025-07-11
Episource, LLC notified consumers of a data breach occurring between Jan 27 and Feb 6, 2025. Criminals accessed and copied data including contact info, health insurance data, health data, and SSNs/DOB. Episource engaged law enforcement, turned off systems, and offers 2 years of credit monitoring. No misuse of data known to date.
- 🐻California State AGas victim2025-07-11
Episource, LLC reported a data breach where an unauthorized third party accessed and copied data from its computer systems between January 27, 2025, and February 6, 2025. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments, etc.), and in limited instances, Social Security numbers. Episource engaged forensic investigators, notified law enforcement, and shut down systems. It is offering two years of credit monitoring.
- 🦫Oregon State AGas victim2025-06-06
Episource, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2025-06-06. The breach occurred during 1/27/2025 - 2/6/2025. The breach was discovered on 5/30/2025. 5,418,866 individuals were affected. Notice was sent on 6/6/2025.
- 🌲Washington State AGas victim2025-06-06
Episource, LLC, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2025-02-06 and filed notice on 2025-06-06. 102,913 Washington residents were affected. 120 days elapsed between awareness and notification. 10 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGas victim2025-06-06
Episource, LLC reported a data breach affecting its computer systems. Unauthorized access occurred between January 27, 2025, and February 6, 2025, when a criminal viewed and copied data. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments), and other personal data such as driver's license numbers. Episource shut down systems, engaged investigators, and notified law enforcement. Two years of credit monitoring are offered.
- 🐻California State AGas victim2025-06-06
Episource, LLC disclosed a data breach affecting its computer systems. Unauthorized access occurred between January 27, 2025, and February 6, 2025, when a criminal viewed and copied data. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments), and other personal data such as driver's license numbers. Episource engaged forensic investigators, notified law enforcement, and shut down systems. They are offering two years of credit monitoring.
- 🐻California State AGas victim2025-06-06
Episource, LLC reported a data breach where an unauthorized third party accessed and copied data from January 27 to February 6, 2025. The incident was discovered on February 6, 2025. Affected data includes contact information, health insurance data, health data (diagnoses, treatments), and potentially Social Security numbers. Episource engaged forensic investigators, notified law enforcement, and shut down systems. They are offering two years of credit monitoring.
- 🦬Montana State AGas victim2023-06-09
Episource reported a data breach to the Montana Attorney General. The breach was reported on 2023-06-09. The breach occurred from 2/19/2023 to 2/21/2023. 2 Montana residents were affected.