Episource, LLC reported unauthorized access to its systems between January 27 and February 6, 2025, discovered on February 6. A criminal actor viewed and copied data including PHI (health diagnoses, treatments, medical record numbers), health insurance data, and PII (names, addresses, SSNs, DOBs). The incident affected patients of Episource's customers, including Brown & Toland Physicians. Episource engaged forensic investigators, notified law enforcement, and shut down systems. Two years of credit monitoring were offered.