a selection of X-ray scans of a human head
Image Credits:Real444 / Getty Images
Security

Episource is notifying millions of people that their health data was stolen

Medical billing giant Episource is notifying millions of people across the United States that their personal and health information was stolen in a cyberattack earlier this year.

The breach affects more than 5.4 million people, according to a listing with the U.S. Department of Health and Human Services, making it one of the largest healthcare breaches of the year so far. 

Episource, owned by health insurance giant UnitedHealth Group’s subsidiary Optum, provides billing adjustment to the doctors, hospitals, and other organizations that work in the healthcare industry. As such, the company handles large amounts of patients’ personal and medical data to process claims through their health insurance.

In notices filed in California and Vermont on Friday, Episource said a criminal was able to “see and take copies” of patient and member data from its systems during the weeklong breach ending February 6.

The stolen information includes personal information, such as names, postal and email addresses, and phone numbers, as well as protected health data, including medical record numbers, and data relating to doctors, diagnoses, medications, test results, imaging, care, and other treatment. The stolen data also contains health insurance information, like health plans, policies, and member numbers.

Episource did not describe the nature of the incident, but Sharp Healthcare, one of the companies that works with Episource and was affected by the cyberattack, told its customers that the Episource hack was caused by ransomware

This is the latest cybersecurity incident to hit UnitedHealth in recent years. 

Change Healthcare, one of the largest companies in the U.S. healthcare industry that processes billions of health transactions each year, was hacked by a ransomware gang in February 2024, leading to the theft of more than 190 million Americans’ personal and health information. The cyberattack was the largest healthcare data breach in U.S. history. 

Several months later, UnitedHealth’s Optum unit left exposed to the internet an internal chatbot used by employees to ask about claims.

Techcrunch event

Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

Netflix, Box, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, Vinod Khosla — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss the 20th anniversary of TechCrunch, and a chance to learn from the top voices in tech. Grab your ticket before doors open to save up to $444.

Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

Netflix, Box, a16z, ElevenLabs, Wayve, Hugging Face, Elad Gil, Vinod Khosla — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss a chance to learn from the top voices in tech. Grab your ticket before doors open to save up to $444.

San Francisco | October 27-29, 2025

Topics

, , , , , ,
Loading the next article
Error loading the next article