AgeRight Clinical Services Data Breach Notice (Oregon Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
AgeRight Clinical Services notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on November 21, 2025. The filing puts the incident itself on August 09, 2025.
The filing from AgeRight Clinical Services confirms that personal information belonging to 4,897 people was exposed in an incident on August 09, 2025. The organisation submitted its formal notice to the Oregon Department of Justice on November 21, 2025 — 104 days later.
No passwords or credentials were exposed
This is genuinely good news. The record lists only personal information and contains no mention of passwords, login details, or any other credential material. You do not need to change any passwords because of this incident.
What the exposed personal information actually means for you
Personal information in this context typically includes details such as name combined with identifiers that can support identity theft or fraud attempts. Because no permanent government identifiers such as Social Security numbers were exposed, the long-term risk profile is lower than in many healthcare-related breaches. However, the data still carries value to fraudsters for targeted phishing, account takeover attempts on other services, or building synthetic identities over time.
AgeRight Clinical Services provides clinical and care coordination services. The people whose records were included are therefore likely to have had some interaction with the organisation for care, billing, or administrative purposes. If you received a notification letter from them, your information was part of this filing.
The 104-day gap between incident and notification
The breach occurred on August 09, 2025 and the filing reached the Oregon Attorney General on November 21, 2025. That interval of roughly three and a half months is the most notable detail in the public record. Notification timelines can vary depending on when an investigation concludes and which specific state requirements apply. The record itself does not disclose when AgeRight discovered the incident or the root cause.
How to know if this breach affects you
AgeRight Clinical Services is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not included. However, if you have moved since August 09, 2025, letters may have gone to an old address. In that case, contact AgeRight Clinical Services directly to confirm whether your records were involved.
The lasting value of health-adjacent personal data
Even without Social Security numbers or medical records explicitly listed beyond the general category of personal information, data tied to clinical services often includes dates of birth, addresses, and contact details. These pieces do not expire. A name and date of birth cannot be reissued like a credit card. Fraudsters can use them for years in combination with information obtained from other sources.
The absence of passwords in the exposed categories means this incident does not put any AgeRight account directly at risk of takeover. The primary concern remains downstream identity-related fraud rather than immediate account compromise.
What remains under your control
You cannot change the fact that this data now exists outside the organisation’s systems. You can, however, reduce how useful it is to attackers by tightening controls on the accounts and services where that personal information could be used to gain entry.
- Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name even if someone has enough personal details to attempt it.
- Review your Explanation of Benefits statements from any health plans you hold. Look for claims or services you do not recognise that could indicate someone is using your information for medical identity fraud.
- Enable two-factor authentication everywhere it is offered, preferably using an authenticator app rather than SMS. While no credentials were lost here, the personal details exposed can make targeted phishing more convincing.
- Monitor your bank and credit card statements for small test charges or unfamiliar transactions. Set up transaction alerts for any amount.
- Be especially cautious with unsolicited calls, texts, or emails claiming to be from AgeRight Clinical Services or any healthcare provider. Verify requests for information by contacting the organisation through a known good number.
The record does not disclose the root cause, whether data was exfiltrated, or the precise fields accessed for each individual. It establishes only that personal information for 4,897 people was involved in the August 09, 2025 incident. The notification letter you may have received will provide the most specific details about what applied to you.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
Trailer Transit Inc Listed by metaencryptor Ransomware Group
Nationwide power-only transport services with 40+ years of experience. Trust Trailer Transit for dep…