In November 2024, CommonSpirit Health experienced a data breach involving its vendor, Pinnacle Holdings Ltd. Unauthorized access to Pinnacle’s systems occurred from November 11 to November 25, 2024, and was detected on November 25, 2024. The incident was disclosed through a filing with the Washington Attorney General, and CommonSpirit Health has acknowledged a ransomware attack on a vendor that exposed patient data.
The compromised data includes highly sensitive information such as names, dates of birth, addresses, Social Security numbers, driver’s license and state ID numbers, financial account and payment card information, medical treatment and diagnosis details, Medicare and Medicaid numbers, prescription information, and biometric and digital signature data. At least 19,027 individuals in Washington State were affected. The full geographic scope remains unclear as the incident has not yet appeared on the U.S. Department of Health and Human Services Office for Civil Rights breach portal. CommonSpirit Health has offered complimentary credit monitoring and identity theft protection to affected Washington residents.
Further details, including the total number of affected individuals across CommonSpirit’s nationwide system, may emerge as investigations continue. Notices may be delayed as updated contact information is obtained.