
MicroCode Software Services Inc., an IT vendor of CommonSpirit Health, disclosed a data breach linked to a ransomware attack. According to the company's notification to consumers, MicroCode hosted and supported a database that CommonSpirit Health used to track medical malpractice insurance records.
The breach was disclosed to the Washington Attorney General on July 30, 2026, with 4,096 Washington residents identified as affected.
On April 14, 2026, MicroCode experienced a ransomware event involving the system that hosted the CommonSpirit Health database and its associated documents. MicroCode launched an investigation with a forensic vendor to determine what happened.
The forensic investigation found that unauthorized access to the MicroCode server hosting CommonSpirit Health's database occurred between Jan. 19, 2026, and April 14, 2026.
After an extensive review of the data on the impacted server, MicroCode determined on July 1, 2026, that personal information belonging to affected individuals was contained on the compromised system.
The types of personally identifiable information on the server included names and dates of birth. Social Security numbers, financial account information and other sensitive personal data were not compromised in the incident.
MicroCode retained Kroll, a third-party firm, to manage a call center for affected individuals who have questions about the incident. Individuals with questions can call 844-958-8933, Monday through Friday from 8:00 a.m. to 5:30 p.m. Central Time, excluding major U.S. holidays.
The notification letter mailed to affected individuals included a list of additional resources, such as contact information for the three major credit reporting agencies and instructions on how to place fraud alerts or credit freezes on their credit files.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)