SAG-AFTRA Health Plan Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
SAG-AFTRA Health Plan reported a data breach affecting 95,104 individuals to the Oregon Attorney General on March 14, 2025; the incident itself occurred on September 17, 2024. If you received health-plan services from SAG-AFTRA, review any notice you receive and consider placing a fraud alert or credit freeze.
SAG-AFTRA Health Plan notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on March 14, 2025. According to that notice, the incident itself occurred on September 17, 2024, and an estimated 95,104 people were affected. The notification describes the exposed material as personal information. For members and dependents whose records may have been involved, the gap between the incident date and the public filing, together with the scale of the reported population, makes clear why the disclosure matters even when many technical details remain limited in the public record.
Because the notice comes through a state attorney general filing, the core facts—who was hit, when the organization says the event took place, how many people it counts as affected, and the broad category of data named—can be stated directly from that disclosure. Other elements, including how the intrusion unfolded and exactly which fields were involved beyond “personal information,” are not spelled out in the available summary.
Breaking down the breach
Public detail rests on the Oregon Department of Justice filing dated March 14, 2025. In that notice, SAG-AFTRA Health Plan reported a data breach with an incident date of September 17, 2024. The organization stated that 95,104 people were affected and that the exposed data consisted of personal information, as characterized in the breach notification. The filing indicates that Oregon residents were among those notified.
The public record provided here does not describe the attack method, whether ransomware or another form of unauthorized access was involved, what systems were touched, how long any unauthorized access lasted, or whether data was confirmed exfiltrated versus accessed. It also does not break down the 95,104 figure by state or by membership status, nor does it quote additional technical findings. Those points remain undisclosed in the facts at hand. What is established is the organization’s report of the date, the headcount, the general data category, and the regulatory notification channel.
How a breach like this happens
Incidents that lead to notices like this often begin with compromised credentials, a vulnerable remote access path, a phishing message that yields a foothold, or unpatched software on a system that holds member or patient-related files. Once inside, an attacker may move laterally, locate databases or document stores, and copy or encrypt information. In health-plan environments, the attractive targets are usually enrollment, claims, or benefits systems that concentrate identity and coverage data in one place.
Detection can lag weeks or months if logging is incomplete or if the activity blends with normal administrative traffic. Organizations then investigate, determine scope, and prepare regulatory and individual notices—steps that explain why a September 2024 incident date can appear in a March 2025 filing. No specific threat group is named in the SAG-AFTRA Health Plan disclosure, and none should be assumed. The pattern above is general background on how breaches of this broad type commonly unfold, not a reconstruction of this event.
About SAG-AFTRA Health Plan
SAG-AFTRA Health Plan provides health coverage and related benefits to eligible members of SAG-AFTRA, the labor union representing performers and media professionals, and often to their dependents. Like other multi-employer or entertainment-industry health plans, it sits at the intersection of labor benefits administration and health-care data handling. Plans of this kind routinely maintain enrollment records, contact details, coverage elections, and information needed to process claims or coordinate care.
A breach affecting such an organization is consequential because the population served may include working actors, background performers, and families whose livelihoods already involve public visibility or irregular income. Health-plan data is also regulated under privacy rules that treat medical and benefits information as sensitive. Even when a notice only labels the exposure as “personal information,” the sector context means the underlying systems are built to hold more than a simple mailing list, which raises the practical stakes for anyone whose record was in scope.
The information in question
The breach notification, as summarized in the Oregon filing, names the exposed data as personal information. It does not itemize fields such as Social Security numbers, dates of birth, addresses, claims details, or financial account numbers in the facts provided here. Those specifics are unconfirmed in the public summary.
Organizations that administer health benefits typically hold identity data used to verify eligibility, contact information for notices and cards, and records tied to coverage and claims. That is the ordinary profile of the sector; it is not a statement that any particular field was proven exposed in this incident. Readers should treat only “personal information,” as the notice describes it, as the confirmed category until fuller inventories appear in official updates.
What's at stake
For affected individuals, the main risks are misuse of identity details for fraud, targeted phishing that references real plan or union affiliation, and long-term uncertainty about whether residual copies of their data remain outside the organization’s control. Even without a public list of exact data elements, a headcount above 95,000 means a large number of households may need to monitor credit, benefits correspondence, and unexpected account activity for an extended period.
For SAG-AFTRA Health Plan, the stakes include regulatory follow-up, the cost of investigation and notification, potential member concern about benefits confidentiality, and the operational work of hardening systems after the fact. None of that establishes negligence as a proven fact; it simply describes the ordinary consequences when a benefits administrator reports a sizable personal-information incident. Trust in a health plan depends in part on confidence that enrollment and coverage data stay protected, so clear communication and concrete remediation matter as much as the initial filing.
What to do if you're exposed
If you are a SAG-AFTRA Health Plan participant or dependent, or if you receive a notice tied to this event, start by reading the official letter carefully for any reference numbers, the exact data categories it lists for you, and any enrollment offers such as credit monitoring. Place a fraud alert or credit freeze with the major credit bureaus if identity elements may have been involved, and review Explanation of Benefits statements and plan portals for unfamiliar activity. Use unique passwords and multi-factor authentication on email and benefits accounts so a single compromised credential is less useful to outsiders.
Keep copies of any notice you receive and note the September 17, 2024 incident date and the March 14, 2025 reporting date for your own records. You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets elsewhere, which can help you prioritize password changes and monitoring. If new official details are released by the plan or by regulators, update your steps accordingly rather than relying on incomplete secondary summaries.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.