[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1x7xfqwgw0hp2":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":12,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":21,"affectedCount":21,"affectedCountStatus":22,"affectedCountLowerBound":13,"affectedCountUnit":23,"hasEnglishDescription":4,"contentLocale":24,"availableLocales":25,"translations":27,"severity":30,"dataClasses":31,"description":50,"seoTitle":51,"seoDescription":52,"logoUrl":53,"isVerified":4,"isSensitive":4,"isSpamList":54,"isMalware":54,"company":55},"6a4f7c1fca239566a8ce5f47","Episource 2025","Episource 2025 Data Breach","episource-2025","episource.com","2025-01-27T00:00:00.000Z","2026-07-09T10:46:54.410Z",null,"2026-07-19T00:11:02.117Z","Official company notice and federal health breach report","https:\u002F\u002Fresponse.idx.us\u002Fepisource\u002F",[16,18,19,20],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf","https:\u002F\u002Fwww.unicare.com\u002Fcontent\u002Fdam\u002Fdigital\u002Fdocs\u002Fglobal\u002FAnthem-SubstituteNoticeEpisourceFinal6-25.pdf","https:\u002F\u002Fwww.hipaajournal.com\u002Fepisource-data-breach\u002F",6725572,"known","unknown","en",[24,26],"tr",{"en":28,"tr":29},{"slug":9},{"slug":9},"Critical",[32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49],"Names","Physical addresses","Phone numbers","Email addresses","Health insurance information","Member IDs","Group IDs","Medicaid\u002FMedicare numbers","Medical record numbers","Provider names","Diagnoses","Prescription information","Test results","Medical images","Medical treatment information","Social security numbers","Dates of birth","Other ID numbers","\u003Cp>The Episource 2025 data breach is a large-scale health data incident that occurred due to unauthorized access to Episource systems, which provide medical coding, risk adjustment, and health data services, resulting in the viewing and copying of personal and health-related information. According to the company's notification, unusual activity was noticed on February 6, 2025, the systems were shut down for protection, and the investigation determined that an unauthorized third party was able to view and copy certain data between January 27, 2025, and February 6, 2025.\u003C\u002Fp>\n\u003Cp>The current row in the federal health violation report shows the number of affected individuals as 6,725,572. Therefore, the record has been prepared using the updated regulatory number, not the lower estimate mentioned in the initial disclosures. The company statement clearly notes that the data is not the same for everyone and that the affected areas vary on an individual basis. It is also stated that financial and bank information, as well as payment card information, were largely unaffected in this incident; these areas have not been added to this record as a data class.\u003C\u002Fp>\n\u003Ch2>Leaking Data Types and Risks\u003C\u002Fh2>\n\u003Cp>In verified notifications, the information at risk begins with contact fields such as name, address, phone number, and email address. In addition, there may be health insurance fields such as health plan and policy information, insurance company information, member or group identification numbers, Medicaid, Medicare, or public payment program identifiers. On the health data side, fields such as medical record number, doctor name, diagnosis information, medication information, test results, images, and care and treatment information have been disclosed.\u003C\u002Fp>\n\u003Cp>For some individuals, their Social Security number, date of birth, or other identification number may also have been affected. This data combination is high-risk because it supports both identity verification and healthcare fraud scenarios. An attacker could use details such as insurance plan, member number, diagnosis, medication, or doctor information to create very convincing fake calls and messages. For individuals with a Social Security number or date of birth, the risk of credit and identity theft is even higher.\u003C\u002Fp>\n\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\n\u003Cp>The verified access range of the incident is between January 27, 2025 and February 6, 2025; the discovery date is taken as February 6, 2025. The number of 6,725,572 people in the record is the total number of affected individuals from the latest federal health breach report. The type of incident has been classified as a cyberattack on a network server. The company stated that after the incident, it contacted law enforcement, worked with external experts, and strengthened its systems.\u003C\u002Fp>\n\u003Cp>This record does not claim that the same types of data are present for all individuals. The notification text states that the data observed and copied varies from person to person. Financial and banking information, as well as payment card details, are largely unaffected, so these areas were not used as a primary data class in the risk text. The record also does not assume that the incident affects all health plan customers; the company notification only refers to the affected customers and data related to their patients or members.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Individuals at risk are patients and members whose files are processed through health plans, doctors, and health companies served by Episource. Episource may not be known directly as a consumer brand by every user; therefore, the affected person may realize that the incident originated from Episource when they see the notification coming through their own health plan or provider. This situation is especially common in supplier incidents within the healthcare ecosystem.\u003C\u002Fp>\n\u003Cp>The highest risk is seen in individuals who have their Social Security number, date of birth, diagnosis, medication, test result, or medical record number along with health insurance information. These individuals can be targeted with scenarios such as fake health plan updates, incorrect invoice corrections, prescription verifications, laboratory results, care coordination, or insurance membership verification. Since health data cannot be altered, the risk is not limited to the period during which the incident is announced.\u003C\u002Fp>\n\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\n\u003Cp>Users who may be affected should first regularly check explanation of benefits, benefit statements, and billing documents from their health plans and providers. If any unreceived service, unknown prescription, diagnosis, test, or payment request is observed, they should contact the health plan or healthcare provider directly. If Social Security number or date of birth has been included, additional measures such as checking credit reports, freezing credit, and fraud alerts should be considered.\u003C\u002Fp>\n\u003Cp>Information should not be provided to people claiming to be representatives of a health plan, doctor's office, insurance company, or protection service in unexpected emails, text messages, or phone calls. Communications requesting member number, Social Security number, verification code, account password, or payment information should be verified through an independent channel. Users should use unique passwords and two-step verification for their health account and email accounts, and carefully review suspicious account recovery notifications.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>This incident demonstrates how far-reaching the impact of supplier and partner systems in the healthcare sector can be. Medical coding, risk adjustment, and quality measurement processes can bring together sensitive data from numerous health plans. Therefore, organizations need to continuously implement data minimization, customer-based segregation, file access logs, network segmentation, encryption, rapid breach detection, and supplier security audits.\u003C\u002Fp>\n\u003Cp>Long-term protection on the user side should be considered more broadly due to the permanent nature of health data. Diagnosis, medication, test results, and insurance membership information can be used in targeted fraud even years later. Affected individuals should continue to review statement and benefit summaries, health portal notifications, authentication messages, and credit records at regular intervals. If a health service or insurance transaction appears unexpected, verification should be done quickly.\u003C\u002Fp>\n\u003Ch2>Record Control and User Action\u003C\u002Fh2>\n\u003Cp>This record on LeakData has been prepared to show the current number of affected individuals, the date of the incident, and the disclosed data fields of the Episource 2025 breach to the user in an understandable manner. The appearance of this record in an email or domain check alone does not prove which health plan or provider the individual was affected through; however, it indicates that users with notifications related to health plans, risk adjustment, medical coding, or affiliated health services should check their alerts.\u003C\u002Fp>\n\u003Cp>When users see this record, they should first review their own health plan notifications, any breach letters received by mail, and their health account transactions. If a suspicious medical service, insurance claim, identity verification attempt, or account change is noticed, they should contact the relevant health plan, provider, or financial institution directly. The record has been classified with critical sensitivity because it contains health insurance, medical data, and Social Security number risks for some individuals.\u003C\u002Fp>","Episource 2025 Data Breach (6.7 Million Reported Records)","Episource 2025 Data Breach. 6.7 Million reported records are reported. Reported data: Names, Physical addresses, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fepisource-2025.svg",false,{"name":56,"sector":57,"country":58,"website":10,"websiteArchiveUrl":59,"websiteStatus":59,"websiteCheckedAt":13},"Episource, LLC","Healthcare technology","United States",""]