CareOregon is a nonprofit health plan headquartered in Portland, Oregon, covering more than 500,000 low-income Oregonians through Medicaid and Medicare managed care. Founded in 1994, the organization coordinates integrated medical, dental, and behavioral health benefits across a family of entities - Columbia Pacific CCO, Jackson Care Connect, CareOregon Advantage (Medicare Advantage), CareOregon Dental, and Housecall Providers. That's a sprawling attack surface: PHI at rest and in transit across multiple care delivery models, partner networks, and community investment programs that touch social determinants like housing and transportation data.
The threat model is the one you'd expect for a large nonprofit payer - ransomware targeting clinical operations, credential stuffing against member portals, third-party risk from a dense network of care coordination partners, and the regulatory pressure of HIPAA alongside Oregon-specific health data requirements. The organization has operated statewide for over 30 years, meaning legacy systems and accumulated technical debt are almost certainly part of the landscape. Security here isn't perimeter defense for a single product; it's protecting an ecosystem of benefits administration, claims processing, and care delivery that spans the state.
There's no public detail on the security stack, team structure, or specific tooling - typical for mission-driven healthcare orgs that tend to fly under the radar. What's legible is the scope: half a million members, multiple subsidiary organizations, and millions invested annually in community health infrastructure. If you're looking to build security practice around real-world impact - protecting healthcare access for vulnerable populations rather than defending a SaaS margin - the stakes are concrete and the attack surface is wide open.






