Episource, LLC Data Breach Notice (Oregon Attorney General)
If you received a notice from Episource, LLC, here’s what the filing says was exposed, and what to do about it.
Episource, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on June 06, 2025. The filing puts the incident itself on January 27, 2025.
The filing from Episource, LLC states that personal information belonging to 5,418,866 people was exposed in an incident that occurred on January 27, 2025. The company submitted its formal notice to the Oregon Department of Justice on June 06, 2025 — an interval of 130 days, or roughly 4.3 months.
What This Exposure Actually Means for You
If you received a notification letter from Episource or one of its partners, the records tied to your name are now outside the company’s control. The filing lists personal information as the category involved. No passwords, no financial account numbers, and no permanent government identifiers such as Social Security numbers were included in the exposed data according to the record.
That absence is important. Without those high-value identifiers, the immediate risk of new account fraud or tax-related identity theft drops significantly. The data that was exposed — primarily names, addresses, dates of birth, and health-related details — still carries long-term value to fraudsters who specialize in medical identity theft, insurance fraud, or building synthetic identities over time.
The Gap Between Incident and Notification
The 130 days between the January 27 incident and the June 06 filing is the most noticeable fact in this record. State notification laws allow companies time to investigate and determine the scope before they must notify affected residents. The filing does not disclose when Episource discovered the incident or how long any unauthorized access may have lasted. What matters to you is that the company has now made the required disclosure and is obligated to notify the individuals whose information was included.
How to Determine Whether You Were Affected
Episource is required to notify affected individuals directly, usually by mail to the last known address on file. If you have not received a letter, it is likely your information was not part of this incident. However, if you have moved since January 27, 2025, letters may have gone to an old address. In that case, contact Episource directly to confirm whether your records were involved.
What the Exposed Personal Information Enables
Health-related data combined with basic personal details is particularly useful for impersonating patients to obtain medical services, prescription drugs, or insurance reimbursements in your name. These consequences can appear months or years later on Explanation of Benefits statements or credit reports as unexpected medical debt.
Because no passwords were exposed, there is no need to change any credentials specifically for this incident. That is genuinely good news in a breach of this size. Your existing account security measures remain unaffected by this particular event.
The Long-Term Nature of Health and Personal Data
Unlike a credit card that can be canceled and reissued, personal and health information cannot be replaced. Once it is out, it remains usable for fraud. The scale — more than 5.4 million people — makes this one of the larger healthcare-related notifications reported in Oregon this year, though the filing itself does not compare it to other incidents.
The records most likely relate to individuals whose insurance claims, eligibility verification, or medical billing were processed through Episource’s services. If you have had health insurance claims handled by a provider that uses Episource, this filing applies to that population.
Practical Steps That Address This Specific Exposure
- Monitor your Explanation of Benefits statements. Review every EOB from your health insurer for services you did not receive. Dispute anything unfamiliar immediately.
- Place a free fraud alert with the three major credit bureaus. This requires lenders to verify your identity before opening new accounts and lasts for one year. It is the most effective step given the personal information involved.
- Review your medical records and Explanation of Benefits for the next 24 months. Medical identity theft often surfaces slowly through unexpected bills or denied claims.
- Contact Episource directly if you moved after January 27, 2025. Confirm whether your information was in the affected group and request any additional details they can provide.
- Consider freezing your credit if you rarely open new accounts. A credit freeze stops new applications in your name and is more protective than a fraud alert for long-term risks.
The record establishes that personal information for 5,418,866 people was exposed. It does not state the precise fields for each person, the root cause, or whether data was copied. What is known is now public, and the direct notification letter remains the clearest way for any individual to determine their own exposure.
Report details & sourcing
Related breaches
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…