DataBreachSearch.com
Investigation OpenOregon AG filing · December 26, 2025

CareOregon Confirms Data Breach Involving Personal Information

CareOregon reported a data breach to the Oregon Attorney General on December 26, 2025, stemming from an incident on May 25, 2025. This means that personal information maintained by the healthcare organization may have been accessed by an unauthorized party. Individuals who received a notification letter should review it for specific details and recommended actions.

State
Oregon
Breach date
May 25, 2025
Reported
December 26, 2025

CareOregon, an Oregon-based healthcare provider, formally reported a data security incident to the Oregon Attorney General on December 26, 2025. The organization identified an event on May 25, 2025, which may have compromised the integrity of its systems. This public filing confirms that CareOregon has acknowledged a breach.

While the specific categories of information involved were not detailed in the public record, CareOregon's filing indicates that personal information was affected. As a healthcare entity, CareOregon typically manages a broad range of sensitive member data to administer medical benefits.

If you received a data breach notification letter from CareOregon, it means that your personal information was identified as potentially exposed in this incident. Such letters are issued to inform affected individuals about the nature of the breach and to provide guidance.

It is advisable to remain vigilant for any unusual activity across your accounts. Consider monitoring your financial statements and credit reports for unauthorized transactions or suspicious inquiries. You may also want to change passwords for online accounts that might share information with the affected entity.

Always refer to the official notification letter from CareOregon for the most accurate and personalized advice. This document will contain specific recommendations tailored to the details of the breach and the information involved.

What to do if you were affected

These general steps can help limit the risk of identity theft and fraud after any data breach.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Related data breach cases