Description

CommonSpirit Health is the second largest health system in the United States, operating in 140 hospitals and over 1,000 care sites across 21 states. CommonSpirit Health confirmed that threat actors accessed the personal data of 623,774 patients during the October 2022 ransomware attack, which was published on the U.S. Department of Health breach portal because the healthcare organizations are legally required to report data breaches impacting over 500 individuals to the U.S Health Department. At the beginning of October 2022, CommonSpirit Health first informed the public of a cyberattack, as on December 1, 2022, CommonSpirit published the latest results of an internal investigation on the incident, admitting that the ransomware actors had accessed data for the first time, revealing that the unauthorized third party gained access to files that contained personal information. Also, CommonSpirit identified that some of these files contained personal information of individuals who may have received services in the past and affiliates of those individuals from Franciscan Medical Group and Fransiscan Health of Washington state. The data compromised during the attack includes the full name, address, phone numbers, date of birth and unique IDs used internally by the organization, while fortunately CommonSpirit also clarified that insurance IDs and medical record numbers are not exposed. The notification sent to the impacted individuals says that data was exposed on September 16 through October 3, 2022, at the time when ransomware actors maintained unauthorized access to CommonSpirit Health's network. Currently, CommonSpirit Health has not disclosed which ransomware group had conducted the attack and no group claimed responsibility for the attack.