Episource, LLC, a medical coding and healthcare IT vendor, experienced an unauthorized access incident resulting in data exfiltration. The breach occurred on January 27, 2025, with discovery on February 6, 2025. Notification letters to individuals began on April 23, 2025.
The breach exposed data for an estimated 6,725,572 individuals. Exposed data types included names, contact information, dates of birth, health insurance information, medical record numbers, diagnoses, medications/prescriptions, test results, images, and treatment information. Social Security numbers were exposed in some instances. The full scope of affected data for each individual varied.
Details regarding this incident, including potential further impacts, may continue to emerge as investigations proceed. Official reports to regulators like the California Attorney General were made on June 6, 2025, and entries from the California Attorney General's breach portal indicate later reported dates on November 12, 2025, and February 9, 2026.