Another 5.4 Million Records Exposed: What the Episource Breach Teaches Us About Encryption‑in‑Use

This month’s major breach headline details how healthcare services firm Episource disclosed that threat actors exfiltrated sensitive data belonging to 5.4 million individuals, including names, Social Security numbers, dates of birth and medical details. While the disclosure by Episource—a subsidiary of UnitedHealth Group’s (UHG) Optum arm—arrived in mid‑July 2025, the incident traces back to a ransomware intrusion that began January 27, 2025 and remained undetected for ten days.

Episource’s announcement follows a brutal year for UHG after the Change Healthcare mega‑breach exposed an estimated 190 million people. The latest event underscores a stubborn reality: as long as protected health information (PHI) can be viewed in plaintext during everyday processing, attackers will keep coming back.

What Happened at Episource?

According to the breach notice filed with the U.S. Department of Health & Human Services (HHS), the attackers gained access to Episource’s network between January 27 and February 6, 2025, siphoning off roughly 6 TB of PHI before deploying ransomware.

Impacted data includes:
• Full names and addresses
• Dates of birth and Social Security numbers
• Medical record and account numbers
• Diagnosis and treatment codes
• Health insurance information

By July 2025, at least 22 health systems had confirmed downstream exposure because Episource processes risk‑adjustment coding on their behalf.

A Symptom of a Larger Epidemic

Healthcare remains ransomware’s favorite target. IBM’s 2024 Cost of a Data Breach report puts the average healthcare breach at USD 9.77 million—double the cross‑industry mean. Meanwhile, the 2025 HIMSS Cybersecurity Survey found that only 41 % of U.S. providers encrypt data while it is actively processed in memory—and this number is likely much lower than the survey indicates. Encryption-in-use and/or searchable encryption continues to be poorly defined, leaving users confused when responding to surveys related to adoption. In any case, the gap between the value of PHI and the controls that protect it is widening, and attackers continue to take advantage of it.

Episource’s breach also highlights third‑party risk. Even if a hospital’s own environment is hardened, vendors that handle claims, coding, patient data, or analytics are still exposing critical patient data. Every link in the data supply chain must adopt controls that prevent plaintext exposure—no exceptions.

Why Traditional Encryption Isn’t Enough

Most healthcare organizations already encrypt data at rest (when stored on disk) and in transit (when sent over networks). The weak spot is data in use—those moments when databases decrypt information in CPU and memory so applications can read or manipulate it. Ransomware and memory‑scraping malware target this clear‑text window. If attackers can grab PHI before it’s written back to disk, traditional encryption provides zero protection.

How Paperclip SAFE® Closes the Gap

  • 🔒 Encryption‑in‑Use – SAFE’s patented shred‑salt‑hash‑encrypt workflow keeps each data element encrypted—even while queried and processed—so there is no plaintext for malware to steal.
  • 🚀 Minimal Performance Impact – <100ms query overhead proven on real‑time claims datasets, ensuring coding productivity isn’t sacrificed for security. SAFE is also designed to support AI training models and LLMs.
  • ⚖️ Built for Compliance – Provides cryptographic evidence for HIPAA §164.312(a)(2)(iv) and aligns with HITRUST CSF v11 and forthcoming NIST post‑quantum standards. SAFE is also post-quantum resistant now and applies crypto-agility-by-design. Meaning, that as post-quantum cryptographic algorithms evolve, they become simple plug-ins for data protected within the SAFE datastore.
  • 🔗 Easy Integration – REST / OpenJSON APIs drop into Epic, Cerner, and SaaS clearinghouse pipelines with no application rebuilds, no network redesigns, and no end-user disruption.
  • 🛡️ Client‑Controlled Lawful Access – Organizations, not vendors, decide when and how to decrypt specific records for subpoenas or patient access requests—without the need for vendor managed backdoors. Paperclip never has access to unencrypted data and takes the position that the data is not ours to ever provide “backdoor” access to.

Takeaways for CISOs and Compliance Officers

  • Review vendor contracts for Encryption‑in‑Use requirements—third‑party PHI processors must secure data during computation. Do more than ask, make sure they understand what encryption-in-use is, and require them to demonstrate how PHI is always encrypted.
  • Implement continuous threat‑hunting focused on credential abuse and memory scraping.
  • Plan now for post‑quantum cryptography migration; data stolen today may be decrypted tomorrow. This is referred to as harvest now, decrypt later (HNDL). Nation-state threat actors are relying on the rapid advancement of quantum computing and a future “Q-Day” to warrant theft of encrypted data.
  • Schedule a Paperclip SAFE proof‑of‑concept to see Encryption‑in‑Use on live operational data.

When critical data is not encrypted, It’s vulnerable. SAFE makes encryption in all states a reality, and is it’s developed to support the way healthcare operations leverage data. Learn more at www.paperclip.com/safe/.

 

References