Providence
ent_019e0bd30f0c89d3f5e4be8243803987
Disclosures
4
State AG · HHS OCR · 3 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
22,701
nationwide · HHS OCR WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Providence
- Normalized
- providence— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 96950056BU2GTL8VWX88
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- providence.org
Disclosure history (4)newest first
- Washington State AGas victim2026-04-16
Providence reported unauthorized access and sharing of patient data via Health Gorilla HIE between Aug 2024 and Dec 2025. Discovered Feb 11, 2026. 838 WA residents affected. Data included names, DOB, addresses, insurance, and clinical records. No SSNs involved. Providence is offering 1 year of identity protection.
- California State AGas victim2026-04-16
Providence notified patients of a data breach involving Health Gorilla, a health information network connected to Providence's Epic EHR system. Between August 30, 2024, and December 8, 2025, patient health information may have been accessed or shared by HIE participants without a defined business need. Providence was notified of the issue on February 11, 2026. Affected data includes names, dates of birth, addresses, insurance policy numbers, test results, medications, and diagnoses. Social Security numbers were not involved. Providence is reviewing data-sharing practices and offering one year of identity protection services.
- WASHINGTONHHS OCRas victim2026-01-16
Providence reported to HHS on 2026-01-16 a Hacking/IT Incident affecting 22701 individuals. Breached information located on Network Server. Business Associate was present.
- Montana State AGas victim2022-08-19
Providence St. Joseph Health notified Montana residents that an internal caregiver accessed electronic medical information in violation of policy between March 21 and April 19, 2022. The incident was discovered on July 19, 2022. Data exposed included PHI and basic PII; no SSN or financial data was involved. Corrective action was taken.