Skip to content
Back to Blog
low severity March 14, 2025 · 4 min read

SAG-AFTRA Health Plan Data Breach Notice (Oregon Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

SAG-AFTRA Health Plan notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on March 14, 2025. The filing puts the incident itself on September 17, 2024.

SAG-AFTRA Health Plan Data Breach Notice (Oregon Attorney General)

The SAG-AFTRA Health Plan notified Oregon residents of a data breach that occurred on September 17, 2024. The filing reached the Oregon Department of Justice on March 14, 2025 — 178 days later. This interval between the incident and the official notification is the single most striking fact in the record.

Personal information belonging to 95,104 people was exposed. The filing lists this single broad category and nothing more. No passwords, no financial account numbers, and no permanent government identifiers such as Social Security numbers appear in the disclosed data fields.

The gap between incident and notification

When an organisation takes nearly six months to notify affected individuals, the delay itself becomes the story. State law allows time for investigation and remediation, so the record does not label the interval as improper. Still, the dates are now public. Anyone whose records were part of this incident waited 178 days for confirmation that their information had been involved in an event on September 17, 2024.

What the exposed personal information actually means

The term “personal information” in breach filings typically covers name combined with date of birth, address, or other contact details. Because the filing does not list Social Security numbers, driver’s license numbers, or medical eligibility data, those elements were not reported as exposed. This is genuinely good news. The absence of those higher-risk identifiers sharply limits what criminals can do with the stolen data.

Without a Social Security number or comparable identifier, the records cannot easily be used to open new credit accounts, file fraudulent tax returns, or impersonate someone for government benefits. The information is still valuable for targeted phishing or identity verification attempts that rely on basic biographical details, but it does not carry the long-term, irreplaceable risk that comes with an SSN.

Who was affected and how you find out

The SAG-AFTRA Health Plan is required to notify affected individuals directly, usually by mail to the last known address. If you have not received a letter, it is likely your records were not part of the 95,104 affected. However, if you have moved since September 17, 2024, a letter may have gone to an old address. In that case, contact the SAG-AFTRA Health Plan directly to confirm whether your information was included.

Why this exposure still matters even without an SSN

Names, dates of birth, and addresses remain useful to fraudsters. They can support social engineering attacks, help criminals answer security questions on other accounts, or be sold on dark-web marketplaces where buyers combine them with data from other breaches. The value does not disappear quickly. While the risk is lower than in breaches that expose government IDs, the information cannot be changed and will remain attached to you indefinitely.

The filing does not reveal how the incident occurred, whether data was copied or simply viewed, or how long any unauthorised access lasted. Those details are outside the record. What the record does establish is that personal information of 95,104 people was involved on September 17, 2024, and that notification came 178 days later.

The difference between what you can control and what you cannot

You cannot change your name, date of birth, or past addresses. Those facts are now potentially known to unknown parties. What you can control is how future attempts to use that information are met. Strong, unique passwords on every account, especially those that hold health or financial data, remain important even though no credentials were exposed here. Enabling multi-factor authentication wherever available adds a layer that stolen personal details alone cannot defeat.

Continued monitoring of your credit reports and explanation of benefits statements from health plans is sensible practice. Because medical eligibility data was not listed in the filing, the risk of fraudulent claims against your SAG-AFTRA coverage is lower, but reviewing statements for unexpected activity is still worthwhile.

Placing this breach in perspective

A breach of this size is significant, yet the limited categories exposed prevent it from reaching the severity of incidents that release Social Security numbers or full medical histories. The 178-day notification window is the element that deserves the most attention. It tells you that even well-established health plans can take half a year to move from incident to public disclosure.

The record contains no information about the attack method or the organisation’s security posture. Speculation on those points is unsupported by the filing. What matters to you is the concrete exposure: personal information, no passwords, no SSNs, and a nearly six-month delay before you were told.

If you received a notification letter, treat the contents of that letter as authoritative for your specific records. The filing gives the overall picture; your letter gives the personal one. For anyone who has changed addresses since the September 17, 2024 incident date, reaching out to the plan directly is the only way to close the uncertainty.

Report details & sourcing

Severity Low contact details only, none of them permanent
Disclosed March 14, 2025
Last reviewed July 22, 2026
Affected 95104
Data exposed Personal information (per the breach notification)
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email