CommonSpirit Health
ent_019e5a1cb082ccd08d99740c380685c0
Disclosures
3
State AG · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
582,285
as filed · State AG WA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CommonSpirit Health
- Normalized
- commonspirit health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 4SXHN5XW08IBO0UG2V58
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (3)newest first
- 🌲Washington State AGas victim2026-02-25
CommonSpirit Health, a health sector entity reported a unauthorized access incident to the Washington Attorney General. The organization became aware of the incident on 2024-11-25 and filed notice on 2026-02-25. 19,027 Washington residents were affected. 457 days elapsed between awareness and notification. 14 days to identify the breach. 0 days to contain the breach.
- 🦬Montana State AGas victim2023-04-06
CommonSpirit Health reported a data breach to the Montana Attorney General. The breach was reported on 2023-04-06. The breach occurred from 9/16/2022 to 10/3/2022. 17 Montana residents were affected.
- 🌲Washington State AGas victim2022-12-01
CommonSpirit Health, a health sector entity reported a ransomware incident to the Washington Attorney General. The organization became aware of the incident on 2022-10-02 and filed notice on 2022-12-01. 582,285 Washington residents were affected. 60 days elapsed between awareness and notification. 16 days to identify the breach. 1 days to contain the breach.
Subsidiary disclosures (4)filed by group companies
◈ These filings were made by or about subsidiaries of CommonSpirit Health — not by CommonSpirit Health itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- IDAHOHHS OCRvia ST. LUKE'S HEALTH SYSTEM CORPORATION2023-04-06
St. Luke's Health System, Ltd. (ID) reported to HHS on 2023-04-06 an Unauthorized Access/Disclosure affecting 15,246 individuals. A business associate employee inadvertently mailed PHI — including names, financial information, and treatment information — to the wrong recipient. Breached information was in Paper/Films format. In response, the CE and BA corrected and updated the printing system to prevent recurrence. Affected individuals, media, and HHS were notified; substitute notice was provided.
- 🦫Oregon State AGvia ST. LUKE'S HEALTH SYSTEM CORPORATION2022-08-02
St. Luke’s Health System reported a data breach to the Oregon Attorney General. The breach was reported on 2022-08-02. The breach occurred during 5/18/2022 - 6/2/2022. The breach was discovered on 7/6/2022. 31,573 individuals were affected. Notice was sent on 8/1/2022.
- IDAHOHHS OCRvia ST. LUKE'S HEALTH SYSTEM CORPORATION2022-08-02
St. Luke's Health System, Ltd. (Idaho healthcare provider) reported to HHS OCR on 2022-08-02 that its business associate suffered a hacking/IT cybersecurity incident on a network server, affecting PHI of 31,573 individuals. PHI included names, dates of birth, addresses, and treatment and financial information. St. Luke's notified HHS, affected individuals, the media, provided substitute notice, terminated the BA relationship, and offered complimentary credit monitoring.
- 🦬Montana State AGvia ST. LUKE'S HEALTH SYSTEM CORPORATION2022-08-01
St. Luke's Health System reported a data breach to the Montana Attorney General. The breach was reported on 2022-08-01. The breach occurred from 5/15/2022 to 5/31/2022. 25 Montana residents were affected.