An unauthorized actor accessed systems belonging to Pinnacle Holdings Ltd., a healthcare consulting vendor, between November 11 and November 25, 2024. Pinnacle Holdings Ltd. served Northgauge Healthcare Advisors, which in turn provided services to CommonSpirit Health. CommonSpirit Health learned of the incident affecting its Washington residents on February 2, 2026.
The exposed data for at least 19,027 Washington residents may have included names, dates of birth, Social Security numbers, addresses, phone numbers, email addresses, driver’s license numbers, state ID numbers, medical diagnosis and treatment information, prescription information, service dates, patient IDs, provider names, medical record numbers, Medicare and Medicaid numbers, health insurance data, claim numbers, policy numbers, and treatment-cost information. The full extent of data affected, beyond the specifically identified Washington residents, remains unclear.
CommonSpirit Health filed a disclosure with the Washington State Attorney General on February 25, 2026. Details regarding the full scope of the breach and potential further notifications may emerge.