Providence
ent_019e0bd30f0c89d3f5e4be8243803987
Disclosures
7
State AG · HHS OCR · 3 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
56,578
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Providence
- Normalized
- providence— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 96950056BU2GTL8VWX88
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- providence.org
Disclosure history (7)newest first
- 🌲Washington State AGas victim2026-04-16
Providence, a health sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2026-02-11 and filed notice on 2026-04-16. 838 Washington residents were affected. 64 days elapsed between awareness and notification. 530 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGas victim2026-04-16
Providence notified patients of a data breach involving Health Gorilla, a health information network connected to Providence's Epic EHR system. Between August 30, 2024, and December 8, 2025, patient health information may have been accessed or shared by HIE participants without a defined business need. Providence was notified of the issue on February 11, 2026. Affected data includes names, dates of birth, addresses, insurance policy numbers, test results, medications, and diagnoses. Social Security numbers were not involved. Providence is reviewing data-sharing practices and offering one year of identity protection services.
- WASHINGTONHHS OCRas victim2026-01-16
Providence reported to HHS on 2026-01-16 a Hacking/IT Incident affecting 22701 individuals. Breached information located on Network Server. Business Associate was present.
- WASHINGTONHHS OCRas reporting2024-08-01
Providence Pediatrics Manito (WA) reported to HHS on 2024-08-01 an Unauthorized Access/Disclosure affecting 1,166 individuals. A mailing error by an employee of its business associate resulted in PHI — including names and treatment information — being sent to incorrect addresses (Paper/Films). The BA implemented additional administrative safeguards and retrained workforce members. Substitute notice, individual notification, and media notification were all provided.
- 🌲Washington State AGas victim2022-10-25
Providence WA Anesthesia Services PC, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2022-07-11 and filed notice on 2022-10-25. 56,578 Washington residents were affected. 106 days elapsed between awareness and notification. 2 days to identify the breach. 0 days to contain the breach.
- 🦬Montana State AGas victim2022-10-24
Providence WA Anesthesia Services PC reported a data breach to the Montana Attorney General. The breach was reported on 2022-10-24. The breach occurred on 7/11/2022. 72 Montana residents were affected.
- 🦬Montana State AGas victim2022-08-19
Providence reported a data breach to the Montana Attorney General. The breach was reported on 2022-08-19. The breach occurred from 3/21/2022 to 4/19/2022. 1 Montana residents were affected.