Skip to main content
Breach Signal

Breach report

Healthcare

Episource (Optum / UnitedHealth Group)

Data Breach at Healthcare Services Firm Episource Impacts 5.4 Million People

A cyberattack on Episource, a medical coding firm owned by UnitedHealth's Optum, exposed insurance, medical and Social Security data on millions of patients, adding to scrutiny of UnitedHealth after the Change Healthcare disaster.

Reported by SecurityWeek

Records exposed

6.7M

About 5.4 million people (later updated to roughly 6.7 million)

Scale vs. largest on file

When
2025
How they got in
Network intrusion and data theft (suspected ransomware)
Sector
Healthcare

Episource, a California company that provides medical coding and risk adjustment services to health plans and provider groups, detected unusual activity in its computer systems on February 6, 2025. An investigation found that an unauthorized party had been able to view and copy data between January 27 and February 6. Episource has been owned by Optum, part of UnitedHealth Group, since 2023.

In June 2025, Episource reported to federal regulators that about 5.4 million people were affected, making it one of the largest healthcare breaches of the year. HIPAA Journal later reported that the figure was updated to about 6.7 million. The company did not publicly name the attacker or describe how access was gained, and no group claimed responsibility, though some reporting indicated ransomware was involved and systems were taken offline.

Because Episource reviews medical charts on behalf of insurers and doctors, the exposed data was extensive. Depending on the person, it included contact details, dates of birth, Social Security numbers, health plan and Medicaid or Medicare identifiers, medical record numbers, doctors, diagnoses, test results, medications and treatment dates. Patients were notified through the health plans and providers that used Episource, including Sharp HealthCare, and were offered two years of credit monitoring.

The breach intensified political pressure on UnitedHealth. In August 2025, Senators Bill Cassidy and Maggie Hassan wrote to the company's leadership, citing Episource alongside the 2024 Change Healthcare attack as evidence of a pattern of security failures at one of the country's largest health conglomerates. Class-action suits were filed on behalf of affected patients. UnitedHealth, which completed its acquisition of Change Healthcare in 2022, has faced persistent questions about security across its many acquired subsidiaries. Episource urged patients to watch insurance statements for services they did not receive.

Like Conduent and Change Healthcare, Episource is a business associate that most patients never interact with directly. Its breach shows how data flows from doctors' offices and insurers into specialized contractors that can become single points of failure. For patients, the combination of Social Security numbers and diagnoses raises risks of medical identity theft, in which fraudsters use someone's insurance to obtain care or file false claims.

More from the wire

More in Healthcare.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.