CommonSpirit Health
ent_019e5a1cb082ccd08d99740c380685c0
Disclosures
6
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
633,031
nationwide · HHS OCR IL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- CommonSpirit Health
- Normalized
- commonspirit health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 4SXHN5XW08IBO0UG2V58
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (6)newest first
- Washington State AGas victim2026-02-25
CommonSpirit Health reported a data breach impacting 19,027 Washington residents. The breach originated from a third-party vendor, Pinnacle Holdings, LTD, which experienced unauthorized access between Nov 11 and Nov 25, 2024. Pinnacle copied personal information including names. CommonSpirit was notified in Feb 2026. Affected individuals are offered credit monitoring.
- Montana State AGas victim2023-04-06
CommonSpirit Health notified Montana residents of a ransomware attack detected on October 2, 2022. Unauthorized access occurred between September 16 and October 3, 2022. The attacker accessed file share servers containing patient information (names, addresses). SSNs and financial data were not compromised. CommonSpirit engaged forensic vendors, notified law enforcement, and enhanced security monitoring.
- Indiana State AGas victim2023-04-06
CommonSpirit Health reported a data breach to the Indiana Attorney General. The breach occurred on 2022-09-16 and was reported on 2023-04-06. 6 Indiana residents were affected. 58,820 individuals affected in total.
- Massachusetts State AGas victim2023-04-06
CommonSpirit Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-04-06. 1 Massachusetts residents were affected. The report records the breach type as electronic.
- Washington State AGas victim2022-12-01
CommonSpirit Health filed a supplemental notice with the Washington AG regarding a ransomware attack detected on October 2, 2022. Unauthorized access occurred between September 16 and October 3, 2022, affecting patient and employee data including SSNs and health info. 317 Washington residents were notified on April 6, 2023. Total affected individuals estimated at 582,285.
- ILLINOISHHS OCRas victim2022-12-01
CommonSpirit Health reported to HHS on 2022-12-01 a Hacking/IT Incident affecting 633,031 individuals. Breached information located on Network Server. The incident involved a ransomware attack compromising PHI including names, addresses, DOBs, SSNs, and treatment data.
Subsidiary disclosures (4)filed by group companies
◈ These filings were made by or about subsidiaries of CommonSpirit Health — not by CommonSpirit Health itself. Corporate relationships are mapped from GLEIF relationship records and SEC Exhibit 21 filings.
- IDAHOHHS OCRvia ST. LUKE'S HEALTH SYSTEM CORPORATION2023-04-06
St. Luke's Health System, Ltd. (ID) reported to HHS on 2023-04-06 an Unauthorized Access/Disclosure affecting 15,246 individuals. A business associate employee inadvertently mailed PHI — including names, financial information, and treatment information — to the wrong recipient. Breached information was in Paper/Films format. In response, the CE and BA corrected and updated the printing system to prevent recurrence. Affected individuals, media, and HHS were notified; substitute notice was provided.
- Oregon State AGvia ST. LUKE'S HEALTH SYSTEM CORPORATION2022-08-02
St. Luke’s Health System reported a data breach to the Oregon Attorney General. The breach was reported on 2022-08-02. The breach occurred during 5/18/2022 - 6/2/2022. The breach was discovered on 7/6/2022. 31,573 individuals were affected. Notice was sent on 8/1/2022.
- IDAHOHHS OCRvia ST. LUKE'S HEALTH SYSTEM CORPORATION2022-08-02
St. Luke's Health System, Ltd. (Idaho healthcare provider) reported to HHS OCR on 2022-08-02 that its business associate suffered a hacking/IT cybersecurity incident on a network server, affecting PHI of 31,573 individuals. PHI included names, dates of birth, addresses, and treatment and financial information. St. Luke's notified HHS, affected individuals, the media, provided substitute notice, terminated the BA relationship, and offered complimentary credit monitoring.
- Montana State AGvia ST. LUKE'S HEALTH SYSTEM CORPORATION2022-08-01
St. Luke's Health System notified Montana residents of a data breach involving a business associate vendor in late May 2022. The incident potentially exposed patient names, DOBs, partial SSNs, service details, and financial account information. St. Luke's suspended vendor processing and offered 12 months of credit monitoring and identity theft protection to affected individuals.