UnknownOtherDelayed DiscoveryMedium
CommonSpirit Health
bd_4825e4a7e8b8ec91 · schema v1 · pii pii-v1
Full breach record for CommonSpirit Health →CommonSpirit Health, a health sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2024-11-25 and filed notice on 2026-02-25. 19,027 Washington residents were affected. 457 days elapsed between awareness and notification. 14 days to identify the breach. 0 days to contain the breach.
Washington clock✗ WA AG >90d15 months discovery → filing
⚠ AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed19,027 affectedView incident
Source provenance
- Source URL
- https://data.wa.gov/resource/sb4j-ca4h.json?id=21751
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 25, 2026
- Raw hash
- 15f4a0ad2b751fe84b041989e2165ca725418f580b5af7e00ab865ab49aa0d79
Reporting entity
- Name
- CommonSpirit Healthnorm: commonspirit health
Victim entity
- Name
- CommonSpirit Healthnorm: commonspirit health
- Industry
- Otherllm
Incident
- Discovered
- Nov 25, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 19,027
- Data types
- —
- Attack vector
- Unknown
- Threat actor
- External
Compliance
- Time to disclose
- 15 months(457 days from discovery to filing)
- Compliance flags
- WA AG >90d
- Discovery-date grounding
- AG web formThe discovery date came from the AG web-form field, which is systematically later than the detection date stated in the letter. Treat the clock as indicative.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.