Skip to content
Back to Blog
low severity June 06, 2025 · 3 min read

Episource, LLC Data Breach Notice (Oregon Attorney General)

If you received a notice from Episource, LLC, here’s what the filing says was exposed, and what to do about it.

Episource, LLC notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on June 06, 2025. The filing puts the incident itself on January 27, 2025.

Episource, LLC Data Breach Notice (Oregon Attorney General)

The filing from Episource, LLC states that personal information belonging to 5,418,866 people was exposed in an incident that occurred on January 27, 2025. The company submitted its formal notice to the Oregon Department of Justice on June 06, 2025 — an interval of 130 days, or roughly 4.3 months.

What This Exposure Actually Means for You

If you received a notification letter from Episource or one of its partners, the records tied to your name are now outside the company’s control. The filing lists personal information as the category involved. No passwords, no financial account numbers, and no permanent government identifiers such as Social Security numbers were included in the exposed data according to the record.

That absence is important. Without those high-value identifiers, the immediate risk of new account fraud or tax-related identity theft drops significantly. The data that was exposed — primarily names, addresses, dates of birth, and health-related details — still carries long-term value to fraudsters who specialize in medical identity theft, insurance fraud, or building synthetic identities over time.

The Gap Between Incident and Notification

The 130 days between the January 27 incident and the June 06 filing is the most noticeable fact in this record. State notification laws allow companies time to investigate and determine the scope before they must notify affected residents. The filing does not disclose when Episource discovered the incident or how long any unauthorized access may have lasted. What matters to you is that the company has now made the required disclosure and is obligated to notify the individuals whose information was included.

How to Determine Whether You Were Affected

Episource is required to notify affected individuals directly, usually by mail to the last known address on file. If you have not received a letter, it is likely your information was not part of this incident. However, if you have moved since January 27, 2025, letters may have gone to an old address. In that case, contact Episource directly to confirm whether your records were involved.

What the Exposed Personal Information Enables

Health-related data combined with basic personal details is particularly useful for impersonating patients to obtain medical services, prescription drugs, or insurance reimbursements in your name. These consequences can appear months or years later on Explanation of Benefits statements or credit reports as unexpected medical debt.

Because no passwords were exposed, there is no need to change any credentials specifically for this incident. That is genuinely good news in a breach of this size. Your existing account security measures remain unaffected by this particular event.

The Long-Term Nature of Health and Personal Data

Unlike a credit card that can be canceled and reissued, personal and health information cannot be replaced. Once it is out, it remains usable for fraud. The scale — more than 5.4 million people — makes this one of the larger healthcare-related notifications reported in Oregon this year, though the filing itself does not compare it to other incidents.

The records most likely relate to individuals whose insurance claims, eligibility verification, or medical billing were processed through Episource’s services. If you have had health insurance claims handled by a provider that uses Episource, this filing applies to that population.

Practical Steps That Address This Specific Exposure

  • Monitor your Explanation of Benefits statements. Review every EOB from your health insurer for services you did not receive. Dispute anything unfamiliar immediately.
  • Place a free fraud alert with the three major credit bureaus. This requires lenders to verify your identity before opening new accounts and lasts for one year. It is the most effective step given the personal information involved.
  • Review your medical records and Explanation of Benefits for the next 24 months. Medical identity theft often surfaces slowly through unexpected bills or denied claims.
  • Contact Episource directly if you moved after January 27, 2025. Confirm whether your information was in the affected group and request any additional details they can provide.
  • Consider freezing your credit if you rarely open new accounts. A credit freeze stops new applications in your name and is more protective than a fraud alert for long-term risks.

The record establishes that personal information for 5,418,866 people was exposed. It does not state the precise fields for each person, the root cause, or whether data was copied. What is known is now public, and the direct notification letter remains the clearest way for any individual to determine their own exposure.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed June 06, 2025
Last reviewed July 22, 2026
Affected 5418866
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email