Data Breach

CommonSpirit confirms data breach impacts 623K patients

CommonSpirit Health confirmed that the October security breach resulted in the exposure of the personal data of 623,774 patients.

In early October, Common Spirit, one of the largest hospital chains in the US, suffered a ransomware cyberattack that caused severe inconvenience to the facilities and to patients.

The security breach led to delayed surgeries, hold-ups in patient care and forced the chain to reschedule doctor appointments across the country.

“CommonSpirit Health has identified an IT security issue that is impacting some of our facilities. We have taken certain systems offline. We are continuing to investigate this issue and follow existing protocols for system outages.” reads the statement published by the company.

CommonSpirit Health confirmed it had experienced an IT security issue that forced it to take part of its infrastructure offline.

NBC News, citing a person familiar with its remediation efforts, revealed that the organization suffered a ransomware attack.

“While CommonSpirit declined to share specifics, a person familiar with its remediation efforts confirmed to NBC News that it had sustained a ransomware attack.” reported NBC News.

NBC News added that multiple facilities have been impacted the ransomware attacks. The media reported that CHI Memorial Hospital (Tennessee), some St. Luke’s hospitals (Texas), and Virginia Mason Franciscan Health (Seattle) were impacted.

Now the company confirmed that threat actors had access to the personal data of 623,774 patients during the ransomware attack. Exposed data includes full name, address, phone number(s), date of birth, and a unique ID used only internally by the organization.

The exact number of impacted individuals was reported through the U.S. Department of Health breach portal.

“As you are aware, on October 2, 2022, CommonSpirit Health experienced a ransomware attack that impacted some of our systems. Our ongoing investigation shows that the unauthorized third party gained access to certain files, including files that contained personal information.” reads an update provided by the company on December 1st, 2022. “While our review of these files is ongoing, we identified that some of these files contained personal information for individuals who may have received services in the past, or affiliates of those individuals, from Franciscan Medical Group and/or Franciscan Health in Washington state.”

CommonSpirit Health added it has no evidence that any personal information has been misused by the threat actors. The company is notifying the impacted individuals.

According to the data breach notification sent to impacted individuals, an unauthorized third party gained access to the company’s network between September 16, 2022 and October 3, 2022. Threat actors gained access to certain files, including files that contained personal information.

CommonSpirit quickly adopted measures to contain the incident and notified law enforcement, it also added to have adopted additional security and monitoring tools.  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, data breach)

[adrotate banner=”5″]

[adrotate banner=”13″]

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

20 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

21 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…

2 days ago

Google: state-backed hackers exploit Gemini AI for cyber recon and attacks

Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…

2 days ago

This website uses cookies.