CareOregon Confirms Data Breach Incident Reported in Oregon
CareOregon, an Oregon-based healthcare organization, has confirmed a data security incident. This breach, discovered on May 25, 2025, and reported on December 26, 2025, potentially exposed personal information. Individuals who received a notification letter should review its details carefully to understand potential impacts.
- State
- Oregon
- Breach date
- May 25, 2025
- Reported
- December 26, 2025
CareOregon, a healthcare organization serving members of the Oregon Health Plan, has filed a notice regarding a data breach. The incident, which led to unauthorized access to systems, reportedly occurred on May 25, 2025. CareOregon subsequently filed an official report on December 26, 2025, indicating the matter is currently under investigation.
The specific nature of the breach and the categories of personal information involved were not detailed in the public filing. However, given CareOregon’s role in managing health benefits, the systems involved likely contained sensitive data. The official notice indicates that the information involved may have been accessed or acquired by an unauthorized party.
This public record confirms that individuals who received a direct notification letter from CareOregon were affected by this security incident. The number of individuals impacted by this breach has not been specified in the available public documentation. Affected individuals should refer to their personalized letter for the most precise details regarding their situation.
If you received a notification from CareOregon, it is important to review it thoroughly. Consider monitoring your account statements and credit reports for any unusual activity. Remain vigilant for suspicious communications that might attempt to leverage this incident. Any unauthorized transactions or suspicious inquiries should be reported promptly to relevant financial institutions or authorities.
What to do if you were affected
These general steps can help limit the risk of identity theft and fraud after any data breach.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Related data breach cases
- Kaniksu Community Health
- Craneware, Inc.
- See's Candies - Corporate Office
- zHealth, Inc.
- Greenberg Traurig, LLP (“GT”)
- Northwest Paper Box Manufacturers
- Quatrro Business Support Services, Inc.
- ASOS US Sales LLC
- BestCare treatment Services, Inc.
- Catalyst Brands LLC
- Bimbo Bakeries USA
- American Addiction Centers
- Boston Health Care for the Homeless Program
- RB American Group LLC