OnePoint Patient Care Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
OnePoint Patient Care has disclosed a data breach affecting 93,672 individuals, as reported to the Oregon Attorney General on February 6, 2025. If you received services from the organization, review the official notice and follow any instructions provided to protect your information.
In a threat landscape where healthcare and pharmacy-adjacent organisations remain frequent targets for credential theft, ransomware, and large-scale data exposure, notices filed with state attorneys general continue to surface incidents that affect tens of thousands of people at a time. OnePoint Patient Care is among the organisations that have publicly notified residents through such a channel.
According to a filing reported to the Oregon Department of Justice on February 06, 2025, OnePoint Patient Care notified Oregon residents of a data breach. The notice indicates that 93,672 people were affected and that personal information was involved. Exact technical details of how the incident unfolded remain limited in the public record.
What happened
OnePoint Patient Care submitted a data breach notice that was reported to the Oregon Attorney General’s office, reflected in Oregon Department of Justice records dated February 06, 2025. The organisation notified Oregon residents in connection with the incident. Public figures associated with the notice state that 93,672 people were affected.
The breach notification describes the exposed material as personal information. Timing of the underlying intrusion or discovery beyond the February 06, 2025 reporting date, the specific attack method, whether systems were encrypted or data was exfiltrated in bulk, and any containment steps are not detailed in the facts available from the disclosure. No threat actor is named in the notice materials summarized here.
How a breach like this happens
Incidents that lead to notifications of this kind commonly begin with one of several well-understood paths. Attackers may obtain valid credentials through phishing or reused passwords, exploit an unpatched remote-access or web application flaw, or use malware that provides a foothold inside a network. Once inside, they often move laterally to systems that store customer, patient, or employee records.
In many cases the goal is to copy databases or document stores containing names, contact details, identifiers, and related personal data, sometimes alongside pressure tactics such as encryption of operational systems. Healthcare and specialty pharmacy environments are attractive because they routinely concentrate identity and health-adjacent information in connected systems. The precise path used against OnePoint Patient Care is not described in the public notice summary, so the above is general background only, not a reconstruction of this event.
About OnePoint Patient Care
OnePoint Patient Care operates in the patient-care and specialty pharmacy space, supporting medication access and related services for people who often have complex or ongoing treatment needs. Organisations of this type typically maintain records needed to dispense medications, coordinate with prescribers and insurers, and communicate with patients—work that inherently involves identity data and sensitive personal details.
A breach affecting such an organisation matters because the people served may already be managing health conditions, and because the same identifiers used for care coordination can be misused for fraud or further social engineering if they leave controlled systems. The Oregon filing underscores that residents of that state were among those the company determined it needed to notify.
What data was at risk
The breach notification names personal information as the category of data exposed. It does not, in the facts provided, itemize every field—such as whether Social Security numbers, dates of birth, addresses, prescription details, insurance identifiers, or clinical notes were included.
Organisations in patient care and specialty pharmacy commonly hold names, contact information, dates of birth, government or insurance identifiers, and medication- or treatment-related records. Those are the kinds of data such entities typically process; they are not confirmed as the exact contents of this incident beyond the notice’s reference to personal information. Exact contents beyond that label remain unconfirmed in the public summary.
The real-world impact
For the 93,672 people reflected in the notice, the practical risks center on misuse of personal information: account takeover attempts, identity fraud, targeted phishing that references a real pharmacy or care relationship, and long-term uncertainty about where copies of the data may circulate. Even when clinical detail is limited or unconfirmed, basic identity data is enough for criminals to open accounts or impersonate victims with other institutions.
For the organisation, consequences typically include notification and support costs, regulatory attention from state authorities, possible contractual issues with partners, and the operational burden of investigation and hardening. Public detail does not establish negligence as fact; it establishes that a notifiable incident occurred and that a large population was determined to be in scope.
What to do if you're exposed
If you believe you may be among those affected—especially if you have been a OnePoint Patient Care patient or customer in Oregon or elsewhere—consider the following practical steps:
- Watch account statements, credit reports, and insurance or pharmacy-related correspondence for unfamiliar activity.
- Treat unexpected emails, texts, or calls that reference your care or medications with caution; verify through official channels you already trust.
- Place a fraud alert or credit freeze with the major consumer reporting agencies if you are concerned about identity theft.
- Change passwords on related accounts and enable multi-factor authentication where available.
- Retain any notice letter you receive from the organisation; it may describe specific protections offered and the categories of data involved for you.
- Run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets.
Public detail on this incident remains anchored to the February 06, 2025 Oregon filing, the figure of 93,672 people affected, and the description of personal information. Further technical or forensic findings, if released later by the organisation or regulators, would be needed to refine the picture beyond what has been disclosed.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.