Episource Lawsuit: Data Breach Class Action and Congress Inquiry

The Episource data breach lawsuit is a consolidated federal class action in the U.S. District Court for the Central District of California brought on behalf of the roughly 5.4 million people whose personal and medical information was stolen in a ransomware attack on Episource LLC in early 2025. The case, In re Episource LLC Data Breach Litigation, names Episource, an Optum-owned healthcare data analytics company, alongside more than a dozen health plans whose members’ records were exposed.1PACER Monitor. In re Episource LLC Data Breach Litigation2Bloomberg Law. Episource Data Breach Class Action Gets Significantly Narrowed

What Happened in the Breach

Episource detected suspicious activity on its systems on February 6, 2025. A forensic investigation later showed that a criminal actor had been inside the network since January 27, copying files during that ten-day window.3Infosecurity Magazine. 5.4 Million Affected by Episource Data Breach Sharp Healthcare, one of Episource’s clients, publicly described the incident as a “ransomware data breach.”4Healthcare Dive. Episource Healthcare Data Breach Impacts 5.4 Million Episource shut its systems down, brought in outside cybersecurity experts, and notified law enforcement. It has not publicly identified the attacker.5HIPAA Journal. Episource Data Breach

What Information Was Exposed

The breach affected approximately 5,418,866 individuals.5HIPAA Journal. Episource Data Breach The stolen files included names, addresses, phone numbers, email addresses, and dates of birth, along with, for some people, Social Security numbers and driver’s license numbers. They also contained health information: diagnoses, treatment records, prescriptions, test results, medical images, medical record numbers, and doctors’ names. Health plan details were caught up as well, including member and group ID numbers, policy information, and Medicaid and Medicare payor IDs.3Infosecurity Magazine. 5.4 Million Affected by Episource Data Breach

Whose Members Were Affected

Episource works behind the scenes for health plans and provider groups, handling medical coding, risk adjustment, and data analytics. Not every client was touched, but the breach reached members of many organizations.4Healthcare Dive. Episource Healthcare Data Breach Impacts 5.4 Million5HIPAA Journal. Episource Data Breach6WellCare. Notice of Data Breach7WellCare Superior HealthPlan. Data Breach Notice

Episource notified its health plan clients on February 7, 2025 and began sending individual notification letters on a rolling basis starting April 23, 2025. Because Episource handled notifications directly on behalf of its clients, most affected patients received a single letter from Episource rather than a separate notice from their insurer.5HIPAA Journal. Episource Data Breach6WellCare. Notice of Data Breach The breach was reported to the U.S. Department of Health and Human Services’ Office for Civil Rights and to attorneys general in California, Texas, Massachusetts, Vermont, Montana, Washington, and New Hampshire.

The Class Action in California

Dozens of individual lawsuits were filed after the breach and consolidated into In re Episource LLC Data Breach Litigation, Case No. 2:25-cv-05330, before Judge Stanley Blumenfeld Jr. in the Central District of California. The consolidated case was filed on June 12, 2025.1PACER Monitor. In re Episource LLC Data Breach Litigation

Episource is the lead defendant. The complaint also names more than a dozen health plans, including WellCare Health Plans, Elevance Health, Aetna, Humana, Blue Cross and Blue Shield of Arizona, Blue Shield of California Life and Health Insurance Company, Molina Healthcare of California, Devoted Health, VNS Choice (doing business as VNS Health Plans), Triple-S Advantage, The Health Plan of West Virginia, InnovaCare, and Archwell Health MSO. The case is pleaded as a contract dispute under diversity jurisdiction and seeks to represent the more than 5.4 million people whose data was compromised.1PACER Monitor. In re Episource LLC Data Breach Litigation2Bloomberg Law. Episource Data Breach Class Action Gets Significantly Narrowed

How the Court Narrowed the Case

On January 22, 2026, Judge Blumenfeld dismissed most of the named plaintiffs and several health plan defendants. Of 23 original named plaintiffs, only four survived. The court found that the dismissed plaintiffs had not adequately shown subject matter jurisdiction, and it held that it lacked personal jurisdiction over several of the health plans in California.2Bloomberg Law. Episource Data Breach Class Action Gets Significantly Narrowed Sharp Healthcare, SCAN Health Plan, and CarePlus Health Plans had already been terminated from the case on September 26, 2025.1PACER Monitor. In re Episource LLC Data Breach Litigation

The litigation remains active as of mid-2026, with the four remaining plaintiffs pursuing claims on behalf of the proposed class. No settlement has been reached or proposed.1PACER Monitor. In re Episource LLC Data Breach Litigation

What Affected People Can Do Now

Episource is offering affected individuals two years of complimentary credit monitoring and identity theft protection through IDX. The package includes credit report monitoring, dark web scanning for stolen personal information, up to $1 million in identity theft insurance reimbursement, and access to fraud resolution specialists.8ClassAction.org. Episource IDX Response Data Breach Notice If you received a notification letter, it contains an enrollment code and a link to the dedicated breach response website where you can sign up.5HIPAA Journal. Episource Data Breach

Because the class action is still in an early stage, there is no claims process to join and no settlement fund to file against. Affected individuals who want to preserve any right to participate in a future settlement generally do not need to do anything now; class members are typically identified from the breach notification list if and when a settlement is approved.

Why Congress Got Involved

Episource was acquired by Optum in 2023, making it part of UnitedHealth Group.9HIPAA Journal. Senators Demand Answers on UHG Episource Cybersecurity10Healthcare Finance News. Senators Criticize UnitedHealth Group’s Cybersecurity After Episource Breach

One point worth flagging for anyone tracking the case: UnitedHealth Group itself is not a defendant in the class action. The claims run against Episource and the health plans whose member data it held.2Bloomberg Law. Episource Data Breach Class Action Gets Significantly Narrowed