In letter, U.S. senators admonish UnitedHealth after second major cyberattack in a year

Episource, a data and technology business that is part of Optum, was hacked this year, exposing the data of 5.4 million people.

The Minnesota Star Tribune
August 8, 2025 at 9:23PM
Sen. Bill Cassidy, R-La., along with Sen. Maggie Hassan, D-N.H., sent a letter to UnitedHealth Group CEO Stephen Hemsley asking for more information about a data breach earlier this year at subsidiary Episource. (Kevin Dietsch/Getty Images)

Another major computer breach involving UnitedHealth Group has prompted two U.S. senators this week to query the health care giant about the adequacy of its cyber defenses.

Episource, a UnitedHealth subsidiary, had its systems hacked last winter, exposing the data of 5.4 million people.

The cyberattack appears to be the second-largest U.S. health care hack this year and follows a record-breaking breach in February 2024 of another United subsidiary, Change Healthcare.

The Change cyberattack is regarded as the largest ever U.S. health care hack. It affected the data of 190 million people — about half the country’s population.

“The recently reported hack of Episource, a subsidiary of UnitedHealth Group (UHG), raises significant questions about UHG’s efforts to safeguard patient information,” Sen. Bill Cassidy, R-La., and Sen. Maggie Hassan, D-N.H., wrote Monday to UnitedHealth CEO Stephen Hemsley.

Sen. Maggie Hassan, D-N.H., along with Sen. Bill Cassidy, R-La., said in a letter to UnitedHealth CEO Stephen Hemsley that the Episource breach raises questions about the company's commitment to protecting patient data. (Rod Lamkey/The Associated Press)

“We have seen the recent threat that hostile actors, including Iran may pose on health care entities and UHG’s repeated failures to protect against such attacks jeopardizes patient health.”

The senators asked UnitedHealth to respond by Aug. 18.

In a statement, the company said: “We are in receipt of the senators’ letter and look forward to providing them the information they requested.”

Eden Prairie-based UnitedHealth is one the nation’s largest companies and the biggest U.S. health insurer. Episource, like Change Healthcare, is part of the company’s Optum group, which runs clinics, manages pharmacy benefits and provides other services to health care companies.

Episource is part of UnitedHealth Group's Optum unit. (Alex Kormann/The Minnesota Star Tribune)

California-based Episource specializes in health care technology and data services. Its customers include medical providers and health care plans.

Episource said in a statement that it found “unusual activity in its computer systems” on Feb. 6.

An investigation found that a “cybercriminal was able to see and take copies of some data” between Jan. 27 and Feb. 6. The breach didn’t affect all of Episource’s customers.

Data that may have been compromised included contact information — names, addresses, phone numbers — and health insurance information such as “Medicaid-Medicare government payor ID numbers.”

Hackers also accessed health data – diagnoses, test results, medicines, treatment records – and to a limited extent, Social Security numbers, according to Episource.

After completing its investigation, the company said it started notifying customers about the breach on April 23.

Episource reported the hack to the U.S. Department of Health and Human Service on June 6, saying it affected 5.4 million people, according to the department’s website.

At the time, Episource said it was unaware of any misuse of the exposed data.

In their letter to Hemsley, Hassan and Cassidy asked UnitedHealth for more information about the Episource hack and for updates on the company’s handling of the Change Healthcare breach.

Change Healthcare shut down its computer systems in February 2024 to contain the cyber debacle, throwing a wrench into the nation’s health care system.

When the hack hit, Change Healthcare processed a large share of all health care claims and payments in the U.S. — roughly 15 billion transactions annually.

UnitedHealth’s then-CEO Andrew Witty was compelled to testify before Congress in May 2024 about the breach.

The hack has produced a storm of litigation, too, as heath care companies seek compensation from UnitedHealth for millions of dollars of alleged losses.

More than 70 separate lawsuits against Change Healthcare have been consolidated in a multidistrict litigation case in federal court in Minnesota. Such cases are used in the federal court system for complex legal matters involving many separate but similar claims.

about the writer

about the writer

Mike Hughlett

Reporter

Mike Hughlett covers energy and other topics for the Minnesota Star Tribune, where he has worked since 2010. Before that he was a reporter at newspapers in Chicago, St. Paul, New Orleans and Duluth.

See Moreicon

More from Health Care

See More
card image
Leila Navidi/The Minnesota Star Tribune

Following concerns that Medtronic was overspending on the high-tech system and not developing it fast enough, FDA clearance is a major victory for the Minnesota-run medtech company.

Nancy Ingham gives newborn Sophia Rash a hepatitis B shot several hours after she was born, Jan. 17, 2006.
card image