Skip to content
Back to Blog
low severity November 21, 2025 · 3 min read

AgeRight Clinical Services Data Breach Notice (Oregon Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

AgeRight Clinical Services notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on November 21, 2025. The filing puts the incident itself on August 09, 2025.

AgeRight Clinical Services Data Breach Notice (Oregon Attorney General)

The filing from AgeRight Clinical Services confirms that personal information belonging to 4,897 people was exposed in an incident on August 09, 2025. The organisation submitted its formal notice to the Oregon Department of Justice on November 21, 2025 — 104 days later.

No passwords or credentials were exposed

This is genuinely good news. The record lists only personal information and contains no mention of passwords, login details, or any other credential material. You do not need to change any passwords because of this incident.

What the exposed personal information actually means for you

Personal information in this context typically includes details such as name combined with identifiers that can support identity theft or fraud attempts. Because no permanent government identifiers such as Social Security numbers were exposed, the long-term risk profile is lower than in many healthcare-related breaches. However, the data still carries value to fraudsters for targeted phishing, account takeover attempts on other services, or building synthetic identities over time.

AgeRight Clinical Services provides clinical and care coordination services. The people whose records were included are therefore likely to have had some interaction with the organisation for care, billing, or administrative purposes. If you received a notification letter from them, your information was part of this filing.

The 104-day gap between incident and notification

The breach occurred on August 09, 2025 and the filing reached the Oregon Attorney General on November 21, 2025. That interval of roughly three and a half months is the most notable detail in the public record. Notification timelines can vary depending on when an investigation concludes and which specific state requirements apply. The record itself does not disclose when AgeRight discovered the incident or the root cause.

How to know if this breach affects you

AgeRight Clinical Services is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not included. However, if you have moved since August 09, 2025, letters may have gone to an old address. In that case, contact AgeRight Clinical Services directly to confirm whether your records were involved.

The lasting value of health-adjacent personal data

Even without Social Security numbers or medical records explicitly listed beyond the general category of personal information, data tied to clinical services often includes dates of birth, addresses, and contact details. These pieces do not expire. A name and date of birth cannot be reissued like a credit card. Fraudsters can use them for years in combination with information obtained from other sources.

The absence of passwords in the exposed categories means this incident does not put any AgeRight account directly at risk of takeover. The primary concern remains downstream identity-related fraud rather than immediate account compromise.

What remains under your control

You cannot change the fact that this data now exists outside the organisation’s systems. You can, however, reduce how useful it is to attackers by tightening controls on the accounts and services where that personal information could be used to gain entry.

  • Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name even if someone has enough personal details to attempt it.
  • Review your Explanation of Benefits statements from any health plans you hold. Look for claims or services you do not recognise that could indicate someone is using your information for medical identity fraud.
  • Enable two-factor authentication everywhere it is offered, preferably using an authenticator app rather than SMS. While no credentials were lost here, the personal details exposed can make targeted phishing more convincing.
  • Monitor your bank and credit card statements for small test charges or unfamiliar transactions. Set up transaction alerts for any amount.
  • Be especially cautious with unsolicited calls, texts, or emails claiming to be from AgeRight Clinical Services or any healthcare provider. Verify requests for information by contacting the organisation through a known good number.

The record does not disclose the root cause, whether data was exfiltrated, or the precise fields accessed for each individual. It establishes only that personal information for 4,897 people was involved in the August 09, 2025 incident. The notification letter you may have received will provide the most specific details about what applied to you.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed November 21, 2025
Last reviewed July 22, 2026
Affected 4897
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email