CareOregon Reports Data Security Incident to Oregon Regulators
CareOregon, an Oregon-based organization, filed a data security incident notice with state regulators on December 26, 2025. The report indicates an event affecting personal information occurred, with a breach date of May 25, 2025. The company has stated that an investigation into the scope and nature of the incident is currently underway.
- State
- OR
- Breach date
- May 25, 2025
- Reported
- December 26, 2025
CareOregon, an organization based in Oregon, recently filed a report with state regulators concerning a data security incident. This filing, submitted on December 26, 2025, indicates that an event impacting personal information occurred, with a breach date recorded as May 25, 2025.
As found in public records, the company's report currently states that an investigation into the incident is ongoing. The specific nature of the breach, such as how it occurred, and the types of personal information involved have not been detailed in the publicly available filing at this time.
Since details are still being investigated, CareOregon has not yet specified the exact categories of personal information that may have been compromised. Individuals who receive a notification from CareOregon should review its contents carefully for any specific instructions provided by the company.
For general protective measures, individuals potentially affected by a data security incident should consider monitoring their account statements and credit reports for any unusual activity. If you identify any suspicious transactions or inquiries, report them immediately to the relevant financial institutions or credit bureaus.
Additionally, it is advisable to be vigilant against unsolicited communications, such as emails, texts, or calls, that request personal information. These could be phishing attempts designed to exploit data revealed in a breach. Always verify the authenticity of such requests directly with the organization through official channels.
What to do if you were affected
These general steps can help limit the risk of identity theft and fraud after any data breach.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: OR Attorney General filing
Related data breach cases
- Abbott Cancer Diagnostics
- Aesto LLC
- CareCloud, Inc.
- JRK Property Holdings, Inc.
- CTS Journey Holdings, LLC, a Delaware limited liability company (DBA Corporate Travel Service)
- The Moody Bible Institute of Chicago
- SM Energy Company
- ADT, Inc.
- Bridgeway Benefit Technologies LLC
- YouLend US LLC
- Oaks Park Association
- The Washington Post
- Robinson Nursery, Inc
- Rogue fabrication llc