
5.4 million patient records exposed in healthcare data breach
Print Close
By Kurt Knutsson, CyberGuy Report
Published June 28, 2025
Over the past decade, software companies have built solutions for nearly every industry, including healthcare. One term you might be familiar with is software as a service (SaaS), a model by which software is accessed online through a subscription rather than installed on individual machines.
In healthcare, SaaS providers are now a common part of the ecosystem. But, recently, many of them have made headlines for the wrong reasons.
Several data breaches have been traced back to vulnerabilities at these third-party service providers. The latest incident comes from one such firm, which has now confirmed that hackers stole the health information of over 5 million people in the United States during a cyberattack in January.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you'll get instant access to my Ultimate Scam Survival Guide — free when you join.
ASCENSION HEALTHCARE DATA BREACH EXPOSES 430,000 PATIENT RECORDS
SaaS firm leads to major healthcare blunder
Episource, a big name in healthcare data analytics and coding services, has confirmed a major cybersecurity incident (via Bleeping Computer ). The breach involved sensitive health information belonging to over 5 million people in the United States. The company first noticed suspicious system activity Feb. 6, 2025, but the actual compromise began ten days earlier.
An internal investigation revealed that hackers accessed and copied private data between Jan. 27 and Feb. 6. The company insists that no financial information was taken, but the stolen records do include names, contact details, Social Security numbers, Medicaid IDs and full medical histories.
Episource claims there's no evidence the information has been misused, but because they haven't seen the fallout yet doesn't mean it isn't happening. Once data like this is out, it spreads fast, and the consequences don't wait for official confirmation.
OVER 8 MILLION PATIENT RECORDS LEAKED IN HEALTHCARE DATA BREACH Why healthcare SaaS is a growing target
The healthcare industry has embraced cloud-based services to improve efficiency, scale operations and reduce overhead. Companies like Episource enable healthcare payers to manage coding and risk adjustment at a much larger scale. But this shift has also introduced new risks. When third-party vendors handle patient data, the security of that data becomes dependent on their infrastructure.
Healthcare data is among the most valuable types of personal information for hackers. Unlike payment card data, which can be changed quickly, medical and identity records are long-term assets on the dark web. These breaches can lead to insurance fraud, identity theft and even blackmail.
Episource is not alone in facing this kind of attack. In the past few years, several healthcare SaaS providers have faced breaches, including Accellion and Blackbaud. These incidents have affected millions of patients and have led to class-action lawsuits and stricter government scrutiny.
WHAT IS ARTIFICIAL INTELLIGENCE (AI)?
5.5 MILLION PATIENTS EXPOSED BY MAJOR HEALTHCARE DATA BREACH 5 ways you can protect yourself from healthcare data breach
If your information was part of the healthcare breach or any similar one, it's worth taking a few steps to protect yourself.
1. Consider identity theft protection services: Since the healthcare data breach exposed personal and financial information, it's crucial to stay proactive against identity theft. Identity theft protection services offer continuous monitoring of your credit reports, Social Security number and even the dark web to detect if your information is being misused.
These services send you real-time alerts about suspicious activity, such as new credit inquiries or attempts to open accounts in your name, helping you act quickly before serious damage occurs. Beyond monitoring, many identity theft protection companies provide dedicated recovery specialists who assist you in resolving fraud issues, disputing unauthorized charges and restoring your identity if it's compromised. See my tips and best picks on how to protect yourself from identity theft.
2. Use personal data removal services: The healthcare data breach leaks loads of information about you, and all this could end up in the public domain, which essentially gives anyone an opportunity to scam you.
One proactive step is to consider personal data removal services, which specialize in continuously monitoring and removing your information from various online databases and websites. While no service promises to remove all your data from the internet, having a removal service is great if you want to constantly monitor and automate the process of removing your information from hundreds of sites continuously over a longer period of time. Check out my top picks for data removal services here.
Get a free scan to find out if your personal information is already out on the web.
3. Have strong antivirus software: Hackers have people's email addresses and full names, which makes it easy for them to send you a phishing link that installs malware and steals all your data. These messages are socially engineered to catch them, and catching them is nearly impossible if you're not careful. However, you're not without defenses.
The best way to safeguard yourself from malicious links is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe. Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices .
4. Enable two-factor authentication: While passwords weren't part of the data breach, you still need to enable two-factor authentication (2FA). It gives you an extra layer of security on all your important accounts, including email, banking and social media. 2FA requires you to provide a second piece of information, such as a code sent to your phone, in addition to your password when logging in. This makes it significantly harder for hackers to access your accounts, even if they have your password. Enabling 2FA can greatly reduce the risk of unauthorized access and protect your sensitive data.
5. Be wary of mailbox communications: Bad actors may also try to scam you through snail mail. The data leak gives them access to your address. They may impersonate people or brands you know and use themes that require urgent attention, such as missed deliveries, account suspensions and security alerts.
WINDOWS 10 SECURITY FLAWS LEAVE MILLIONS VULNERABLE Kurt's key takeaways
What makes this breach especially alarming is that many of the affected patients may have never even heard of Episource. As a business-to-business vendor, Episource operates in the background, working with insurers and healthcare providers, not with patients directly. The people affected were customers of those companies, yet it's their most sensitive data now at risk because of a third party they never chose or trusted. This kind of indirect relationship muddies the waters when it comes to responsibility and makes it even harder to demand transparency or hold anyone accountable.
CLICK HERE TO GET THE FOX NEWS APP
Do you think healthcare companies are investing enough in their cybersecurity infrastructure? Let us know by writing us at Cyberguy.com/Contact
For more of my tech tips and security alerts, subscribe to my free CyberGuy Report Newsletter by heading to Cyberguy.com/Newsletter
Ask Kurt a question or let us know what stories you'd like us to cover
Follow Kurt on his social channels
Answers to the most asked CyberGuy questions:
New from Kurt:
Copyright 2025 CyberGuy.com. All rights reserved.
Print Close
URL
https://www.foxnews.com/tech/5-4-million-patient-records-exposed-healthcare-data-breach
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Medscape
9 minutes ago
- Medscape
Headache Common After Hemorrhagic Stroke, Often Overlooked
MINNEAPOLIS — Roughly half of patients experience headaches following a hemorrhagic stroke, with more than one third reporting severe pain — yet headache management remains a largely neglected aspect of post-stroke care. 'What we found is that headaches are far more common after hemorrhagic stroke than people might think. For many, the headache lingers even for months-years.' study investigator Bradley Ong, MD, a neurology resident at the Cleveland Clinic in Cleveland, told Medscape Medical News . Patients often mention headaches while recovering from hemorrhagic stroke, but post-stroke headache tends to not be a focus of care, Ong added. The findings were presented at American Headache Society (AHS) Annual Meeting 2025. Knowledge Gap 'So much of stroke research focuses on the acute event, like how to stop the bleeding, and reduce disability, but I kept thinking about what happens after,' said Ong. Ong added that when he looked into the literature he was 'struck by how little we know about post-stroke headaches — particularly following hemorrhagic stroke.' This aspect of the patient experience has been largely overlooked, with surprisingly little research available on post-stroke headaches, particularly following hemorrhagic stroke. The researchers conducted a systematic review and meta-analysis, identifying 24 studies published through December 2024. The databases included MEDLINE (1964-2024), Embase (1947-2024), and Central (1996-2024). In all there were data on 4671 individuals who experienced a hemorrhagic stroke and were assessed for acute and chronic post-stroke headache. The majority patients were women (58.2%) living in Europe (70.8%) with a mean age of 56.9 years. Results showed 47% (95% CI, 39%-87%) developed a headache after a hemorrhagic stroke, with 56% of patients (95% CI, 42%-97%) developing an acute or subacute headache within 30 days post-stroke, and 39% of patients (95% CI, 30%-48%) developing a chronic headache more than 3 months post-stroke. Patients developed severe headache in over one third of cases (36.9%; 95% CI, 14.4%-67.0%), which was defined as a Numeric Rating Scale score ≥ 8. Among patients who developed post-stroke headache, 48% experienced it following a subarachnoid hemorrhage (SAH), while 38% developed it after an intracerebral hemorrhage (ICH). In both cases, post-stroke headache often progressed to a chronic, persistent condition, with nearly 38% continuing into the chronic phase, the researchers reported. 'In aneurysmal SAH, most headaches had a migrainous phenotype; in contrast, most headaches in ICH had tension-type features, which ranged from moderate to severe in intensity,' the researchers noted. Little Clinical Guidance The likelihood of developing a post-stroke headache after a hemorrhagic stroke was influenced by several factors. Male sex was associated with lower odds of headache (pooled odds ratio [OR], 0.82; 95% CI, 0.68-0.99), while a prior history of headache significantly increased the risk (pooled OR, 4.83; 95% CI, 2.10-11.10). Although the researchers observed considerable heterogeneity among the studies reviewed, the meta-regression analysis showed no statistically significant differences related to the risk of bias, region, population source, or human development index. Headache does not get the same level of urgency in neurology as other symptoms such as weakness, speech problems, or seizures. 'But for patients, these headaches are very real and can be debilitating. We just haven't done enough to listen to that part of their recovery,' said Ong. More prospective studies are necessary to improve the understanding of headaches, which frequently receive insufficient attention in research. Ong emphasized that treating headaches in stroke patients is challenging because common over-the-counter medications like nonsteroidal anti-inflammatory drugs are often unsuitable for those who have suffered a brain bleed. 'Long-term follow-up data would also be incredibly valuable, especially since a lot of these patients continue to struggle with headaches well after discharge,' said Ong. Clinicians should be more intentional in including headache treatment as a part of stroke rehabilitation, he added. 'Right now, there's very little guidance on how to even define post-stroke headache, and that makes it harder to study and treat. Most of the existing research also comes from a few regions in the world, so we're missing a truly global picture. We need better, more consistent data from diverse populations to really understand how common this is and what treatments might help,' he added. More Data Needed Commenting on the research, Robert G. Kaniecki, MD, founder and director of the UPMC Headache Center in Pittsburgh, noted that the study's size and scope were strengths. He added that the data are valuable because they specifically focus on patients who have experienced hemorrhagic stroke and subsequently develop headaches. 'Most prior papers have addressed headaches following stroke of any kind — hemorrhagic or the more common ischemic nonhemorrhagic stroke cases,' Kaniecki told Medscape Medical News . The finding that acute or subacute headache affected 56% of patients was surprising — Kaniecki said he had anticipated a higher rate — while the 39% prevalence of chronic headache was also unexpected, as he had predicted it would be lower. One limitation in the research was that the studies were mostly published before the third edition of the International Classification of Headache Disorders (ICHD-3) were developed and post-stroke headache was defined with specific criteria, Kaniecki said. More data on patients with preexisting headaches are also needed, Kaniecki said, and he is interested in knowing how many patients in the study with post-stroke depression ended up developing headaches. 'Post-stroke depression is common, and headache a frequent symptom reported by patients with depression,' Kaniecki said.


Medscape
18 minutes ago
- Medscape
JAK1 Inhibitor Shows Promise for Ankylosing Spondylitis
TOPLINE: Ivarmacitinib, a highly selective Janus kinase 1 (JAK1) inhibitor, tamed ankylosing spondylitis with sustained efficacy through 24 weeks in a phase 2/3 trial. METHODOLOGY: A phase 2/3 trial in China evaluated the efficacy and safety of ivarmacitinib in 504 adults with active ankylosing spondylitis who did not benefit from nonsteroidal anti-inflammatory drugs (NSAIDs). In phase 2, patients were randomly assigned to receive ivarmacitinib (2 mg, 4 mg, or 8 mg) or placebo once daily for 12 weeks; 4 mg was selected as the recommended dose based on an interim analysis. In phase 3, 373 patients (mean age, 33.8 years; 79.6% men) were randomly assigned to receive 4 mg ivarmacitinib (n = 187) or placebo (n = 186) once daily for 12 weeks, after which all patients got ivarmacitinib for 12 weeks. The primary endpoint in both phases was the proportion of patients achieving an Assessment of Spondyloarthritis International Society (ASAS) 20 response at week 12. TAKEAWAY: At week 12, 48.7% of patients who received 4 mg ivarmacitinib achieved an ASAS20 response compared with 29% of those who received placebo (P = .0001). More patients on 4 mg ivarmacitinib vs placebo achieved an ASAS40 response (32.1% vs 18.3%; P = .0011) and an ASAS5/6 response (42.8% vs 15.6%; P < .0001) at week 12, with efficacy sustained at week 24. After 12 weeks of treatment, patients receiving 4 mg ivarmacitinib had greater improvements in disease symptoms, physical function, spinal mobility, and quality of life. During the first 12-week period, treatment-emergent adverse events occurred in 79.7% of patients in the ivarmacitinib group and 65.6% in the placebo group but caused few treatment discontinuations. IN PRACTICE: 'Ivarmacitinib 4 mg once daily provided rapid, sustained, and clinically meaningful improvements in disease activity, signs and symptoms, function, and MRI-detected inflammation in patients with active AS [ankylosing spondylitis] who had an inadequate response to NSAIDs, with a manageable safety profile,' the authors wrote. SOURCE: This study was led by Xu Liu, MD, and Liling Xu, MD, of Peking University People's Hospital in Beijing, China. It was published online on June 12, 2025, in Arthritis & Rheumatology. LIMITATIONS: The 24-week efficacy of ivarmacitinib may not reflect long-term outcomes. The absence of an active comparator limited the comparison of ivarmacitinib with other disease-modifying antirheumatic drugs used for active ankylosing spondylitis. These findings in Chinese patients with radiographic axial spondyloarthritis may not be generalizable to other populations. DISCLOSURES: Jiangsu Hengrui Pharmaceuticals Co. Ltd. sponsored and designed the trial. Two authors reported being employees of the sponsor company while the study was conducted. This article was created using several editorial tools, including AI, as part of the process. Human editors reviewed this content before publication.
Yahoo
an hour ago
- Yahoo
Trump global aid cuts risk 14 million deaths in five years, report says
Donald Trump's move to cut most of the US funding towards foreign humanitarian aid could cause more than 14 million additional deaths by 2030, according to research published in The Lancet medical journal on Monday. A third of those at risk of premature deaths are children, the research finds. US Secretary of State Marco Rubio said in March that President Trump's administration had cancelled over 80% of all programmes at the US Agency for International Development, or USAID. "For many low- and middle-income countries, the resulting shock would be comparable in scale to a global pandemic or a major armed conflict," Davide Rasella, who co-authored the Lancet report, said in a statement. The funding cuts "risk abruptly halting - and even reversing - two decades of progress in health among vulnerable populations," added Rasella, a researcher at the Barcelona Institute for Global Health. The report comes as dozens of world leaders are meeting in the Spanish city of Seville this week for a United Nations-led aid conference, the biggest one in a decade. Looking back over data from 133 nations, the team of researchers estimated that USAID funding had prevented 91 million deaths in developing countries between 2001 and 2021. They also used modelling to project how funding being slashed by 83% – the figure announced by the US government earlier this year – could affect death rates. The cuts could lead to more than 14 million avoidable deaths by 2030, the projections found. That number included over 4.5 million children under the age of five – or around 700,000 child deaths a year. The Trump administration, previously led by billionaire Elon Musk's cost-cutting initiative, aimed to shrink the federal workforce. It has also accused USAID of supporting liberal projects. The US, by far the world's largest humanitarian aid provider, has operated in more than 60 countries, largely through contractors. According to Rubio, there were still approximately 1,000 remaining programmes that would be administered "more effectively" under the US State Department and in consultation with Congress. Still, the situation on the ground has not been improving, according to UN workers. Last month, a UN official told the BBC that hundreds of thousands of people were "slowly starving" in Kenyan refugee camps after US funding cuts reduced food rations to their lowest ever levels. At a hospital in Kakuma, in northwestern Kenya, the BBC witnessed a baby who could barely move and was showing signs of malnutrition, including having parts of her skin wrinkled and peeling.