In 2026, Washington Gastroenterology, specifically its subsidiary Spokane Digestive Disease Center, experienced a data breach stemming from unauthorized access to an employee's email account. The breach was confirmed on May 8, 2026, and affected individuals were notified starting May 26, 2026. This incident is related to a broader phishing incident at its parent company, Gastro Health, which also occurred in 2026.
The breach involved sensitive data, including names, dates of birth, Social Security numbers, driver's licenses or state IDs, financial account data, credit card information, electronic signatures, and medical records. It impacted at least 37,260 individuals in total, with 2,093 Washington residents specifically affected by the Spokane Digestive breach. Other states potentially affected by the broader Gastro Health incident include Florida, Alabama, Virginia, Ohio, Massachusetts, and Maryland.
While notification letters have been sent and credit monitoring offered, details such as the specific date the breach occurred beyond the confirmation date for Spokane Digestive remain unclear for the initial breach. More information about the full scope of the breach and potential legal actions may emerge.