CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise IT Services & Support in Houston, TX
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Managed Service Provider Houston Cybersecurity
Shane Stevens
Shane Stevens June 19th, 2025

CinchOps Alerts Houston Healthcare Providers: Episource Ransomware Attack Exposes 5.4 Million Patient Records

Major Healthcare Data Breach Highlights Critical Security Gaps in Medical Technology

Breach Alert
One Vendor Breach Exposed 5.4 Million Patients.

Most of them had never heard of Episource. That is the point: a breach at a healthcare vendor you have no direct relationship with can still expose your patients' most sensitive data.

TL;DR
Episource, a California medical-coding and risk-adjustment company owned by UnitedHealth's Optum, was breached in early 2025. Attackers were inside its systems for about ten days (January 27 to February 6) and stole a huge volume of protected health information before being detected. The result: more than 5.4 million people had data exposed - names, Social Security numbers, birthdates, diagnoses, medications, and more - making it one of the largest healthcare breaches of the year. At least one affected partner, Sharp HealthCare, confirmed it was ransomware. The lesson is about the supply chain: most victims never used Episource directly. Their health plans and providers did. For any medical practice, this is a warning that your biggest data risk may be a vendor you have never heard of - which makes vendor risk management essential.
🔍 What Happened 🔗 The Vendor Risk 🛡️ How to Protect Yourself 🚀 How CinchOps Helps

The scariest healthcare breaches are not always at the hospital - they are at the quiet back-office vendor that processes data for hundreds of them at once.

Episource is not a name most patients know, but it handles medical coding and risk-adjustment data for many healthcare providers and health plans. That is exactly what made its breach so damaging: a single intrusion exposed the records of millions of people across many organizations. Here is what happened, why the supply chain makes these attacks so far-reaching, and what a medical practice should do about it.

The key point: your patients can be breached through a vendor they - and sometimes you - never chose directly. That is why knowing who touches your data matters.

What Happened

One intrusion at a business associate, millions of patients exposed.

Attackers spent about ten days inside Episource stealing protected health information before anyone noticed.

ONE VENDOR BREACH, MILLIONS EXPOSED 1 vendor Episource (Optum) → many providers health plans & practices → 5.4M+ patients PHI stolen
How a single business-associate breach cascaded to millions of patients.

The intrusion ran from January 27 to February 6, 2025, when Episource detected unusual activity. It filed breach notifications with regulators months later, in June 2025. The stolen data was unusually complete - names, addresses, Social Security numbers, birthdates, insurance details, diagnoses, treatment and prescription information, and more - the kind of full profile that enables medical and insurance fraud. It is the second major breach tied to UnitedHealth in about a year, following the Change Healthcare attack, and drew letters from U.S. senators demanding answers.

Why a Vendor You Never Chose Can Breach Your Patients

Business associates concentrate data - and risk.

When one vendor processes data for hundreds of providers, breaching it once compromises all of them at once.

  • Business associates hold a lot of data. Coding and risk-adjustment firms process protected health information for many providers, so one breach reaches far.
  • The impact cascades. Affected clients ranged from large systems to smaller groups - many patients were exposed through a vendor they never dealt with directly.
  • It was ransomware. Episource was not fully explicit, but affected partner Sharp HealthCare confirmed the breach was caused by ransomware.
  • The goal was the data. Attackers focused on stealing complete patient profiles - valuable for identity theft, medical fraud, and dark-web sale.
  • Detection was slow. Ten days of undetected access, then months to public disclosure - time in which the data was already gone.

How to Protect Your Practice

You cannot control a vendor's security - but you can manage the risk.

The defense is knowing who touches your data, watching your own systems, and being ready to respond fast.

  • Manage vendor risk. Know which business associates handle your patient data and hold them to real security standards.
  • Monitor around the clock. Continuous detection catches an intruder in hours, not the ten days Episource took.
  • Lock down access. Phishing-resistant MFA and least-privilege access limit what a stolen login can reach.
  • Keep tested backups. Isolated, tested backups let you recover from ransomware without paying.
  • Have an incident response plan. A rehearsed plan - including notifying affected patients - turns a crisis into a managed process.
100% Free

Free Cybersecurity Assessment

Do you know which vendors touch your patient data - and how secure they are? Get a FREE review of your security and vendor risk.

Get Your Free Assessment

Millions of people were breached by a company they had never heard of. In healthcare, your security is only as strong as the weakest vendor holding your patients' data - which is why you have to know who they are.
Shane Stevens, CEO, CinchOps - LinkedIn

Protect Patient Data - Yours and Your Vendors'

CinchOps helps Houston-area healthcare practices with 24/7 monitoring, access controls, tested backups, and vendor risk management - so a supply-chain breach does not become your breach - through our cybersecurity and managed IT services.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure Your Business

CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, including healthcare practices that must protect patient data.

  • 24/7 security monitoring. Rapid detection and response before an intruder can exfiltrate data.
  • Vendor risk management. Assess and monitor the security of the business associates that touch your data.
  • Advanced threat protection. Firewalls, endpoint detection, email security, and behavioral analytics.
  • Backup and disaster recovery. Tested backups to recover from ransomware without paying.
  • Staff training and testing. Awareness training plus assessments to find weaknesses before attackers do.

Do not wait to be the next breach headline. Contact CinchOps to protect your patients and your practice.

Frequently Asked Questions

What is Episource and what happened?

Episource is a California medical-coding and risk-adjustment company owned by UnitedHealth's Optum. In early 2025 attackers spent about ten days inside its systems and stole protected health information, exposing data on more than 5.4 million people - one of the largest healthcare breaches of the year.

Was the Episource breach ransomware?

Episource was not fully explicit about the attack type, but Sharp HealthCare, an affected partner, confirmed the breach was caused by ransomware. Either way, the attackers stole large amounts of patient data.

How can a vendor breach expose my patients if I never used Episource?

Because business associates like Episource process data on behalf of many health plans and providers. When one is breached, every organization whose data it held - and their patients - can be exposed at once. That is the nature of supply-chain risk.

What data was exposed?

A very complete set: names, addresses, Social Security numbers, birthdates, insurance details, diagnoses, treatment and prescription information, and more. That combination makes identity theft and medical or insurance fraud far easier.

What should a healthcare practice do about vendor breaches?

Know which vendors handle your patient data, hold them to real security standards, monitor your own systems around the clock, enforce MFA and least privilege, keep tested backups, and have an incident response plan ready. A managed IT provider can run all of it.

Discover More

CinchOps Cybersecurity Services
Healthcare Cyber Crisis: 89% Run Exploitable Systems
Healthcare Data Breaches Threatening Patient Safety

Sources

  • TechCrunch, Episource Is Notifying Millions That Their Health Data Was Stolen
  • Infosecurity Magazine, Over 5.4 Million Affected in Healthcare Data Breach at Episource
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

October 17th, 2025
Managed Service Provider Houston Cybersecurity
Cyber Insecurity in Healthcare: 2025 Findings and What It Means for Patient Safety

When Cybersecurity Becomes the New Standard of Patient Care

March 11th, 2026
Stryker Attack
Iran-Linked Hackers Cripple Medical Tech Giant Stryker in Devastating Wiper Attack

When Hackers Don’t Want Your Money, They Want Your Business Offline – No Ransom, No Negotiation, No Recovery, The Reality of Wiper Attacks

February 19th, 2026
Construction IT
Managed IT Services for Houston Construction Companies

When Your Job Site Goes Dark, So Does Your Bottom Line – Managed IT Built Around How Construction Companies Actually Work

November 19th, 2025
Managed Service Provider Houston
Sneaky2FA Phishing Kit Evolves with Browser-in-the-Browser Pop-ups Targeting Houston Businesses

Houston Businesses Face Sophisticated Phishing Attacks Targeting Microsoft 365 Accounts – Browser-In-The-Browser Attacks Display Fake URLs

August 19th, 2025
Managed Service Provider Houston
CinchOps’ Guide to Houston Data Protection: 5 Scenarios Every Business Should Know

Turn Data Disasters Into Quick Recovery Success Stories – Smart Data Backup Solutions For Houston’s Growing Businesses

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery
  • Cloud Services
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy