MicroCode Software Services Inc. and CommonSpirit Health: MicroCode Breach Affects 4,096 Residents

MicroCode Software Services Inc. and CommonSpirit Health: MicroCode Breach Affects 4,096 Residents

MicroCode Software Services Discloses Ransomware Breach Affecting CommonSpirit Health Data

MicroCode Software Services Inc., an IT vendor for CommonSpirit Health, reported a data breach stemming from a ransomware attack that exposed sensitive medical malpractice insurance records. The incident was disclosed to the Washington Attorney General on July 30, 2026, with 4,096 Washington residents confirmed as affected.

The breach occurred after unauthorized access to MicroCode’s server hosting CommonSpirit Health’s database was detected between January 19 and April 14, 2026. A forensic investigation revealed that the ransomware attack on April 14, 2026, compromised the system, prompting MicroCode to review the impacted data. By July 1, 2026, the company confirmed that personally identifiable information (PII), including names and dates of birth, was exposed. However, Social Security numbers, financial account details, and other highly sensitive data were not accessed.

In response, MicroCode engaged Kroll, a third-party firm, to operate a call center for affected individuals. The company also mailed notification letters with resources for credit monitoring and fraud protection. The breach highlights ongoing risks in third-party vendor security within the healthcare sector.

Source: https://www.claimdepot.com/data-breach/commonspirit-health-2026-95150

Microcode Software Services, Inc. cybersecurity rating report: https://www.rankiteo.com/company/microcode-software-services

CommonSpirit Health cybersecurity rating report: https://www.rankiteo.com/company/commonspirithealth

"id": "MICCOM1786570654",
"linkid": "microcode-software-services, commonspirithealth",
"type": "Ransomware",
"date": "1/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '4,096 Washington residents',
                        'industry': 'Healthcare',
                        'name': 'CommonSpirit Health',
                        'type': 'Healthcare Provider'},
                       {'industry': 'Information Technology',
                        'name': 'MicroCode Software Services Inc.',
                        'type': 'IT Vendor'}],
 'attack_vector': 'Unauthorized server access',
 'customer_advisories': 'Notification letters with credit monitoring and fraud '
                        'protection resources',
 'data_breach': {'data_encryption': 'Yes (ransomware encryption)',
                 'number_of_records_exposed': '4,096',
                 'personally_identifiable_information': 'Names, dates of birth',
                 'sensitivity_of_data': 'Moderate (names, dates of birth; no '
                                        'SSNs or financial data)',
                 'type_of_data_compromised': 'Personally identifiable '
                                             'information (PII), medical '
                                             'malpractice insurance records'},
 'date_detected': '2026-01-19',
 'date_publicly_disclosed': '2026-07-30',
 'description': 'MicroCode Software Services Inc., an IT vendor for '
                'CommonSpirit Health, reported a data breach stemming from a '
                'ransomware attack that exposed sensitive medical malpractice '
                'insurance records. The breach occurred after unauthorized '
                'access to MicroCode’s server hosting CommonSpirit Health’s '
                'database was detected between January 19 and April 14, 2026. '
                'A forensic investigation revealed that the ransomware attack '
                'on April 14, 2026, compromised the system, exposing '
                'personally identifiable information (PII), including names '
                'and dates of birth. Social Security numbers, financial '
                'account details, and other highly sensitive data were not '
                'accessed.',
 'impact': {'data_compromised': 'Personally identifiable information (PII), '
                                'medical malpractice insurance records',
            'identity_theft_risk': 'Yes',
            'payment_information_risk': 'No',
            'systems_affected': 'Server hosting CommonSpirit Health’s '
                                'database'},
 'initial_access_broker': {'entry_point': 'Server hosting CommonSpirit '
                                          'Health’s database',
                           'reconnaissance_period': '2026-01-19 to 2026-04-14'},
 'investigation_status': 'Completed (forensic investigation concluded)',
 'lessons_learned': 'Highlights ongoing risks in third-party vendor security '
                    'within the healthcare sector',
 'post_incident_analysis': {'root_causes': 'Unauthorized access to third-party '
                                           'vendor server'},
 'ransomware': {'data_encryption': 'Yes'},
 'references': [{'source': 'Washington Attorney General'}],
 'regulatory_compliance': {'regulatory_notifications': 'Disclosed to '
                                                       'Washington Attorney '
                                                       'General'},
 'response': {'communication_strategy': 'Public disclosure to Washington '
                                        'Attorney General, notification '
                                        'letters to affected individuals',
              'remediation_measures': 'Notification letters mailed to affected '
                                      'individuals, credit monitoring and '
                                      'fraud protection resources provided',
              'third_party_assistance': 'Kroll (call center and credit '
                                        'monitoring services)'},
 'title': 'MicroCode Software Services Discloses Ransomware Breach Affecting '
          'CommonSpirit Health Data',
 'type': 'Ransomware'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.