Supply chain
β Supply Chain
Sharp HealthCare Episource Third-Party Breach
Primary Source βIncident Details
Sharp HealthCare, a major integrated regional health system in San Diego, California, disclosed in June 2025 that a breach at Episource, its third-party healthcare risk adjustment and analytics vendor, had exposed patient records. Exposed data included Social Security numbers, health insurance plan IDs, medical records and chart information, diagnoses, clinical notes, images, and diagnostic test results. The depth of clinical data exposed β including imaging and test results β was particularly severe. Sharp HealthCare filed notifications with HHS OCR and notified affected patients. Episource provides risk adjustment documentation and analytics to health plans and provider groups across the US; this breach affected patients whose data had been shared for clinical documentation improvement purposes.
Technical Details
- Initial Attack Vector
- Episource, a healthcare risk adjustment and analytics vendor, was breached, exposing patient records for Sharp HealthCare clients that had been shared with Episource for clinical documentation and risk adjustment analytics services
- Vendor / Product
- Episource (healthcare risk adjustment analytics)
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-05-01 Breach occurred
- 2025-06-15 Publicly disclosed
- 2025-06-15 Customers notified