Episource Class Action – Best Proven Guide (2026)

Recall Summary

Recall number None
Issued by Issuing agency
Date 2026-07-24
Company Episource
Units affected Not disclosed
Severity Not classified

Remedy: Follow the instructions in the official notice linked below. The agency record for this recall did not contain remedy text we could verify against this product, so we have not reproduced it here.

Read the official Issuing agency recall notice

A filed episource class action is now moving through the federal courts over the 2025 data security incident at Episource LLC, a California-based medical coding and risk adjustment vendor that handles patient records on behalf of health plans and provider groups. This article explains, in plain language, what the verified court filings show, who may fall inside the proposed class, what the current procedural status actually is, and what practical steps a person who received a breach notice can take right now. Nothing here is legal advice.

Advertisement

Case Timeline

Last checked: July 26, 2026

  • January 22, 2026 (Ruling): The court granted motions to dismiss in substantial part, dismissing most of the 23 named plaintiffs for lack of Article III standing/subject matter jurisdiction and dismissing claims against several health-plan customer defendants, including Devoted Health, for lack of personal jurisdiction. (Court Record)
  • October 10, 2025 (Latest Activity): Newest lawsuit filed — Lowell Dunlap, Jr. v. Episource LLC, C. District of California (Docket 2:25-cv-09719) (Court Record)
  • July 23, 2025 (Consolidation): Judge Stanley Blumenfeld Jr. granted a stipulated request consolidating the Episource data breach class actions in the Central District of California under In re Episource LLC Data Breach Litigation, No. 2:25-cv-05330, and set a briefing schedule for appointment of interim class counsel. (Court Record)

What happened to Episource

Episource is a healthcare services company that performs risk adjustment coding and data analytics for insurers and medical groups. Because of that role, it holds large volumes of patient information without ever treating a patient directly. Public reporting and regulatory filings describe a cyberattack in early 2025 in which an intruder accessed Episource systems and copied data before the company detected the activity and shut systems down.

According to public breach reporting, the unauthorized access occurred over roughly a ten-day window between late January and February 6, 2025, when Episource identified unusual activity on its network. The company contacted law enforcement, engaged investigators, and began notifying affected health plans and individuals in the following months. The incident was reported to the U.S. Department of Health and Human Services Office for Civil Rights under HIPAA breach notification rules.

The categories of information described in public notices vary by person, but reportedly include names, addresses, phone numbers, email addresses, dates of birth, Social Security numbers, health insurance and plan identifiers, Medicare and Medicaid information, and clinical details such as diagnoses, medications, and treatment records. The publicly reported figure most commonly cited is roughly 5.4 million individuals, with later reporting describing a higher revised total.

What the episource class action alleges

The docket entries verified for this article confirm that litigation has been filed against Episource LLC in federal court in California. The claims are categorized on the docket under “Personal Property: Other,” a civil classification commonly used for data breach and privacy suits rather than for physical injury claims. One of the verified filings is designated as a class action, meaning the named plaintiff seeks to represent a broader group of similarly situated people.

In general terms, a data breach case of this type asserts that a company holding sensitive personal and health information failed to protect it adequately, and that people whose data was taken were harmed as a result. The specific legal theories, defenses, and factual findings in this episource class action have not been resolved by any court. Allegations in a complaint are claims, not proven facts, and Episource is entitled to contest them.

The four verified filings

There are exactly four verified court filings against Episource LLC reflected in the docket list used for this article. Three were filed on September 10, 2025 in the Eastern District of California, and one was filed on October 10, 2025 in the Central District of California. The named plaintiff on the docket captions is Dunlap, including one caption identifying Lowell Dunlap, Jr.

No other plaintiffs, firms, injuries, or case totals are asserted here, because only these four filings were verified. Anyone tracking the episource class action can read the official record directly at the CourtListener docket for Lowell Dunlap, Jr. v. Episource LLC, which reflects filings as entered by the court.

Who may be in the proposed class

In a data breach class action, the proposed class typically consists of people whose personal or protected health information was involved in the incident. For Episource, that generally points to individuals whose records were held by Episource through its work for health plans and provider organizations, rather than people who dealt with Episource directly.

📨 Get Free Mass Tort Guides Alerts

Free · No spam · Unsubscribe anytime

Importantly, no class has been certified. Class definitions are proposed by plaintiffs in a complaint and must later be approved by a judge, and the definition can change or be narrowed during that process. Until a court rules, there is no confirmed list of who is inside or outside the class in this episource class action.

A practical signal is the breach notification letter itself. Many affected individuals received notice from their health plan rather than from Episource, since the plan was the covered entity. Keeping that letter matters because it documents that a specific person’s data was involved.

Current status: early, and no settlement exists

The verified filings are recent, dating from September and October 2025. Cases at this stage are in the earliest procedural phase, which typically involves service, responsive pleadings, possible motions to dismiss, and potential consolidation or transfer where multiple related suits exist in different districts.

There is no settlement in the episource class action. No settlement fund, no approved claims process, no claim deadline, and no payment amounts exist. Any website, email, or text message telling someone they are owed a specific sum from this matter should be treated with caution, because no such determination has been made by any court.

What an affected person can do now

The most useful step is recordkeeping. Keep the breach notice, the envelope, and any correspondence from a health plan or from Episource. Save documentation of anything unusual afterward: unfamiliar medical bills, explanation-of-benefits statements for care that was never received, new accounts, credit inquiries, or tax filing problems. Contemporaneous records are far more persuasive than later recollection.

Independent of the episource class action, standard identity protection steps remain available to anyone. These include reviewing credit reports, considering a credit freeze or fraud alert, monitoring insurance statements for services never received, and enrolling in any complimentary monitoring offered in a breach notice. Background on health data breach reporting obligations is available from the HHS Office for Civil Rights breach portal.

Deadlines exist and they vary

Time limits apply to civil claims, and they differ by state, by legal theory, and by the date a person is deemed to have learned of the harm. There is no single universal deadline for data breach claims, and a deadline in one state may be substantially shorter than in another. Waiting can foreclose options.

Because the episource class action is early, procedural dates will continue to change as the courts act. Anyone with questions about their own situation, their own deadlines, or whether to remain in or opt out of a class should consult a licensed attorney in their state. This article is general information about publicly filed court records and is not a substitute for individualized legal counsel.

Following the record yourself

Because the episource class action is public, anyone can follow it without paying a firm for updates. Docket entries on CourtListener and PACER show filings as they are entered, including motions, orders, and any consolidation. Reading the record directly is the most reliable way to know the real status of the case at any given time, rather than relying on secondhand summaries or marketing pages.

Were You Injured by a Recalled Product?

A recall by itself is a safety action, not a legal claim. However, if a recalled product caused a real injury, you may be eligible to pursue compensation. A licensed attorney can review your situation at no upfront cost — most work on contingency, meaning you pay nothing unless you recover.

Official Sources & Resources

Verify every recall against the issuing agency before acting:

  • the issuing agency: official recall database — the record of truth for this notice
  • CPSC: cpsc.gov — household goods, toys, furniture, appliances
  • FDA: fda.gov — food, drugs, and medical devices
  • NHTSA: nhtsa.gov — vehicles, tires, and child car seats
  • USDA FSIS: fsis.usda.gov — meat, poultry, and egg products

Content last reviewed July 2026. This is general educational information, not legal advice. If you notice outdated information, please contact us.

Related Guides

Going through divorce too? Compare state laws at Divorce Help Guide. Affected by a recalled drug as a Medicare patient? See Medicare Cover Guide. Just diagnosed with a serious illness? Compare life insurance at Life Insure Guide. PFAS in your water? Check homeowners coverage at Home Insure Guide.