MicroCode Software Services Discloses Ransomware Breach Affecting CommonSpirit Health Data
MicroCode Software Services Inc., an IT vendor for CommonSpirit Health, reported a data breach stemming from a ransomware attack that exposed sensitive medical malpractice insurance records. The incident was disclosed to the Washington Attorney General on July 30, 2026, with 4,096 Washington residents confirmed as affected.
The breach occurred after unauthorized access to MicroCode’s server hosting CommonSpirit Health’s database was detected between January 19 and April 14, 2026. A forensic investigation revealed that the ransomware attack on April 14, 2026, compromised the system, prompting MicroCode to review the impacted data. By July 1, 2026, the company confirmed that personally identifiable information (PII), including names and dates of birth, was exposed. However, Social Security numbers, financial account details, and other highly sensitive data were not accessed.
In response, MicroCode engaged Kroll, a third-party firm, to operate a call center for affected individuals. The company also mailed notification letters with resources for credit monitoring and fraud protection. The breach highlights ongoing risks in third-party vendor security within the healthcare sector.
Source: https://www.claimdepot.com/data-breach/commonspirit-health-2026-95150
Microcode Software Services, Inc. cybersecurity rating report: https://www.rankiteo.com/company/microcode-software-services
CommonSpirit Health cybersecurity rating report: https://www.rankiteo.com/company/commonspirithealth
"id": "MICCOM1786570654",
"linkid": "microcode-software-services, commonspirithealth",
"type": "Ransomware",
"date": "1/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '4,096 Washington residents',
'industry': 'Healthcare',
'name': 'CommonSpirit Health',
'type': 'Healthcare Provider'},
{'industry': 'Information Technology',
'name': 'MicroCode Software Services Inc.',
'type': 'IT Vendor'}],
'attack_vector': 'Unauthorized server access',
'customer_advisories': 'Notification letters with credit monitoring and fraud '
'protection resources',
'data_breach': {'data_encryption': 'Yes (ransomware encryption)',
'number_of_records_exposed': '4,096',
'personally_identifiable_information': 'Names, dates of birth',
'sensitivity_of_data': 'Moderate (names, dates of birth; no '
'SSNs or financial data)',
'type_of_data_compromised': 'Personally identifiable '
'information (PII), medical '
'malpractice insurance records'},
'date_detected': '2026-01-19',
'date_publicly_disclosed': '2026-07-30',
'description': 'MicroCode Software Services Inc., an IT vendor for '
'CommonSpirit Health, reported a data breach stemming from a '
'ransomware attack that exposed sensitive medical malpractice '
'insurance records. The breach occurred after unauthorized '
'access to MicroCode’s server hosting CommonSpirit Health’s '
'database was detected between January 19 and April 14, 2026. '
'A forensic investigation revealed that the ransomware attack '
'on April 14, 2026, compromised the system, exposing '
'personally identifiable information (PII), including names '
'and dates of birth. Social Security numbers, financial '
'account details, and other highly sensitive data were not '
'accessed.',
'impact': {'data_compromised': 'Personally identifiable information (PII), '
'medical malpractice insurance records',
'identity_theft_risk': 'Yes',
'payment_information_risk': 'No',
'systems_affected': 'Server hosting CommonSpirit Health’s '
'database'},
'initial_access_broker': {'entry_point': 'Server hosting CommonSpirit '
'Health’s database',
'reconnaissance_period': '2026-01-19 to 2026-04-14'},
'investigation_status': 'Completed (forensic investigation concluded)',
'lessons_learned': 'Highlights ongoing risks in third-party vendor security '
'within the healthcare sector',
'post_incident_analysis': {'root_causes': 'Unauthorized access to third-party '
'vendor server'},
'ransomware': {'data_encryption': 'Yes'},
'references': [{'source': 'Washington Attorney General'}],
'regulatory_compliance': {'regulatory_notifications': 'Disclosed to '
'Washington Attorney '
'General'},
'response': {'communication_strategy': 'Public disclosure to Washington '
'Attorney General, notification '
'letters to affected individuals',
'remediation_measures': 'Notification letters mailed to affected '
'individuals, credit monitoring and '
'fraud protection resources provided',
'third_party_assistance': 'Kroll (call center and credit '
'monitoring services)'},
'title': 'MicroCode Software Services Discloses Ransomware Breach Affecting '
'CommonSpirit Health Data',
'type': 'Ransomware'}