CinchOps Alerts Houston Healthcare Providers: Episource Ransomware Attack Exposes 5.4 Million Patient Records
Major Healthcare Data Breach Highlights Critical Security Gaps in Medical Technology
Most of them had never heard of Episource. That is the point: a breach at a healthcare vendor you have no direct relationship with can still expose your patients' most sensitive data.
The scariest healthcare breaches are not always at the hospital - they are at the quiet back-office vendor that processes data for hundreds of them at once.
Episource is not a name most patients know, but it handles medical coding and risk-adjustment data for many healthcare providers and health plans. That is exactly what made its breach so damaging: a single intrusion exposed the records of millions of people across many organizations. Here is what happened, why the supply chain makes these attacks so far-reaching, and what a medical practice should do about it.
What Happened
One intrusion at a business associate, millions of patients exposed.
Attackers spent about ten days inside Episource stealing protected health information before anyone noticed.
The intrusion ran from January 27 to February 6, 2025, when Episource detected unusual activity. It filed breach notifications with regulators months later, in June 2025. The stolen data was unusually complete - names, addresses, Social Security numbers, birthdates, insurance details, diagnoses, treatment and prescription information, and more - the kind of full profile that enables medical and insurance fraud. It is the second major breach tied to UnitedHealth in about a year, following the Change Healthcare attack, and drew letters from U.S. senators demanding answers.
Why a Vendor You Never Chose Can Breach Your Patients
Business associates concentrate data - and risk.
When one vendor processes data for hundreds of providers, breaching it once compromises all of them at once.
- Business associates hold a lot of data. Coding and risk-adjustment firms process protected health information for many providers, so one breach reaches far.
- The impact cascades. Affected clients ranged from large systems to smaller groups - many patients were exposed through a vendor they never dealt with directly.
- It was ransomware. Episource was not fully explicit, but affected partner Sharp HealthCare confirmed the breach was caused by ransomware.
- The goal was the data. Attackers focused on stealing complete patient profiles - valuable for identity theft, medical fraud, and dark-web sale.
- Detection was slow. Ten days of undetected access, then months to public disclosure - time in which the data was already gone.
How to Protect Your Practice
You cannot control a vendor's security - but you can manage the risk.
The defense is knowing who touches your data, watching your own systems, and being ready to respond fast.
- Manage vendor risk. Know which business associates handle your patient data and hold them to real security standards.
- Monitor around the clock. Continuous detection catches an intruder in hours, not the ten days Episource took.
- Lock down access. Phishing-resistant MFA and least-privilege access limit what a stolen login can reach.
- Keep tested backups. Isolated, tested backups let you recover from ransomware without paying.
- Have an incident response plan. A rehearsed plan - including notifying affected patients - turns a crisis into a managed process.
Millions of people were breached by a company they had never heard of. In healthcare, your security is only as strong as the weakest vendor holding your patients' data - which is why you have to know who they are.
Protect Patient Data - Yours and Your Vendors'
CinchOps helps Houston-area healthcare practices with 24/7 monitoring, access controls, tested backups, and vendor risk management - so a supply-chain breach does not become your breach - through our cybersecurity and managed IT services.
Explore CinchOps cybersecurity →How CinchOps Helps Secure Your Business
CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, including healthcare practices that must protect patient data.
- 24/7 security monitoring. Rapid detection and response before an intruder can exfiltrate data.
- Vendor risk management. Assess and monitor the security of the business associates that touch your data.
- Advanced threat protection. Firewalls, endpoint detection, email security, and behavioral analytics.
- Backup and disaster recovery. Tested backups to recover from ransomware without paying.
- Staff training and testing. Awareness training plus assessments to find weaknesses before attackers do.
Do not wait to be the next breach headline. Contact CinchOps to protect your patients and your practice.
Frequently Asked Questions
What is Episource and what happened?
Episource is a California medical-coding and risk-adjustment company owned by UnitedHealth's Optum. In early 2025 attackers spent about ten days inside its systems and stole protected health information, exposing data on more than 5.4 million people - one of the largest healthcare breaches of the year.
Was the Episource breach ransomware?
Episource was not fully explicit about the attack type, but Sharp HealthCare, an affected partner, confirmed the breach was caused by ransomware. Either way, the attackers stole large amounts of patient data.
How can a vendor breach expose my patients if I never used Episource?
Because business associates like Episource process data on behalf of many health plans and providers. When one is breached, every organization whose data it held - and their patients - can be exposed at once. That is the nature of supply-chain risk.
What data was exposed?
A very complete set: names, addresses, Social Security numbers, birthdates, insurance details, diagnoses, treatment and prescription information, and more. That combination makes identity theft and medical or insurance fraud far easier.
What should a healthcare practice do about vendor breaches?
Know which vendors handle your patient data, hold them to real security standards, monitor your own systems around the clock, enforce MFA and least privilege, keep tested backups, and have an incident response plan ready. A managed IT provider can run all of it.