The Chicago, IL-based Catholic health system CommonSpirit Health has announced that it has been affected by a security incident at a vendor of one of its business associates. The healthcare consulting company Pinnacle Holdings Ltd experienced network disruption on November 25, 2024, as a result of a ransomware attack. The ransomware group had access to Pinnacle’s network from November 11, 2024, to November 25, 2024. During that time, files were exfiltrated from Pinnacle’s network.
Pinnacle was a vendor of CommonSpirit Health’s vendor, NorthGauge Healthcare Advisors. In a breach notice issued to the Washington Attorney General on behalf of CommonSpirit Health, NorthGauge explained that Pinnacle immediately isolated its network when the attack was detected and has since implemented additional security measures to prevent similar incidents in the future. NorthGauge explained that Pinnacle had strict policies and procedures in place concerning data retention and data destruction, which limited the amount of data compromised in the incident.
Pinnacle engaged a third-party vendor to review the exposed data, and in November 2025 – a year after the attack – Pinnacle notified NorthGauge about the incident. NorthGuage said it did not receive confirmation about the identities of the affected individuals until January 30, 2026, and notified CommonSpirit Health about the affected Washington residents on February 2, 2026. NorthGauge said individual notification letters will be mailed to the affected Washington residents as soon as up-to-date contact information has been obtained. Those individuals are being offered complimentary credit monitoring and identity theft protection services.
The breach notice does not state the types of data compromised in the incident; however, they are stated in the individual notification letters to the affected individuals. According to the Washington Attorney General, the breach affected 19,027 Washington residents. The incident is not currently listed on the HHS’ Office for Civil Rights website, so it is unclear if individuals in other states have also been affected.
The post CommonSpirit Health Patients Affected by Vendor Data Breach appeared first on The HIPAA Journal.