25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

CommonSpirit Health Says Patient Information Accessed in October 2022 Cyberattack

CommonSpirit Health has provided an update on its October 2022 ransomware attack and has confirmed that the threat actors behind the attack accessed files containing patient information.

The attack was detected by CommonSpirit Health on October 2, 2022, and action was immediately taken to secure its network. While the attack caused disruption at its healthcare facilities due to systems being taken offline to contain the incident, CommonSpirit Health said there was no impact on clinic, patient care, and associated systems at Dignity Health, Virginia Mason Medical Center, TriHealth, or Centura Health facilities. The forensic investigation confirmed that the attackers had access to its network between September 16, 2022, and October 3, 2022.

CommonSpirit Health has now confirmed that the attackers gained access to parts of its network containing files that included the protected health information of patients of Franciscan Medical Group and Franciscan Health in Washington state, including patients that had received medical services at St. Michael Medical Center (formerly Harrison Hospital), St. Anne Hospital (formerly Highline Hospital), St. Anthony Hospital, St. Clare Hospital, St. Elizabeth Hospital, St. Francis Hospital, and St. Joseph Hospital. Those facilities are now known collectively as Virginia Mason Franciscan Health, which is an affiliated entity of CommonSpirit Health.

ComnmonSpirit Health has confirmed that the affected files contained the information of patients and their family members and caregivers, including names, addresses, phone numbers, birth dates, and unique internal patient identifiers. At this stage, no evidence has been found of attempted or actual misuse of the data stored on its systems.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

CommonSpirit Health said the majority of EHRs across the CommonSpirit Health system are now back online and patient portals can now be accessed. The review of the affected files has been completed, and it has been confirmed that the protected health information of 623,774 patients has been exposed or compromised. CommonSpirit Health has recommended patients check their account statements for accuracy and should report any services or charges that were not incurred to their provider or insurance carrier.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist