Cambia Health Solutions, Inc. Data Breach Notice (Oregon Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Cambia Health Solutions, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on May 21, 2026. The filing puts the incident itself on January 01, 2026.
The filing from Cambia Health Solutions shows that personal information belonging to 2,856 people was exposed in an incident that occurred on January 1, 2026. The company did not notify Oregon authorities until May 21, 2026 — an interval of 140 days, or roughly 4.6 months.
That delay is the single most striking fact in the record. While notification deadlines vary by state and depend on when an investigation concludes, the gap between the incident date and the filing date is long enough to stand out. Anyone who had an account or received services from Cambia during that period should treat the exposure as real.
No passwords or credentials were involved
The record lists only personal information. No passwords, no login details, and no permanent government identifiers such as Social Security numbers appear in the disclosed categories. This is genuinely good news. It means the breach does not put your Cambia account itself at immediate risk of takeover, and you do not need to change any password connected to this service.
What the exposed personal information actually enables
Even without SSNs or financial account numbers, the personal information listed in the filing can still be valuable to identity thieves. Medical and insurance-related details often remain sensitive for decades. Fraudsters can use them to file fake claims, request medical services in your name, or combine them with information obtained elsewhere to build a convincing identity profile.
Because the filing does not name every specific data point, the safest assumption is that any personal details Cambia held about you at the time of the incident may have been included. The company is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not part of this group. However, if you have moved since January 1, 2026, you should contact Cambia directly to confirm whether you were affected.
The lifelong nature of medical and insurance data
Unlike a credit card number that can be replaced, medical and insurance information cannot be reissued. Once it is out, it stays out. Thieves can use it years later when combined with newer data breaches. This is why the 140-day gap between the incident and the notification matters: the longer the information may have circulated before anyone was told, the greater the chance it has already been shared or sold.
The record does not disclose the root cause, whether data was exfiltrated, or how the incident occurred. It also does not state whether any specific individual’s full set of records was taken. What it does state clearly is that personal information of 2,856 Oregon residents was exposed.
How this changes your risk profile today
Your risk is now permanently elevated for medical identity theft and fraud that relies on health-related records. You cannot erase the exposure, but you can reduce what an attacker can do with it by monitoring for misuse and limiting new opportunities for fraud.
- Review every Explanation of Benefits statement from Cambia and any other insurer carefully. Look for services you did not receive or providers you did not visit. Report anything suspicious immediately.
- Place a fraud alert with the three major credit bureaus even though no credit-related data was listed. This adds a layer of friction that can stop attempts to open accounts using medical details paired with other stolen information.
- Consider freezing your credit if you rarely open new accounts. The inconvenience is minor compared with the difficulty of cleaning up medical identity theft.
- Keep records of the breach notice and any correspondence from Cambia. You may need them later if fraudulent claims appear on your insurance or tax records.
The gap between incident and notification
The 140 days between January 1 and May 21, 2026, is the longest single fact this filing gives us. During that period, the people whose records were exposed had no way to protect themselves because they had not been told. That interval is now fixed history. What you control is how you respond from today forward.
The letter from Cambia remains the most reliable way to know for certain whether you were included. Absence of a letter usually means you were not affected, but anyone who changed addresses after the January 1, 2026 incident date should reach out to the company to verify their status.
This breach does not require you to take dramatic steps such as closing accounts or changing every password you own. It does require steady, ongoing attention to your medical and insurance statements for the foreseeable future. The personal information exposed here retains its value far longer than most people expect.
Report details & sourcing
Related breaches
Figure Technology Solutions 967K Accounts — February 2026
Lending and home-equity tech firm Figure Technology Solutions disclosed a social-engineering breach …
el-group Listed by Inc Ransom Ransomware Group
el-group was listed on the Inc Ransom ransomware leak site. The group claims to have stolen internal…
Integrated Health Systems Listed by coinbasecartel Ransomware Group
Integrated Health Systems was listed on the coinbasecartel ransomware leak site. The group claims to…