Skip to main content
Jump to a category page

A ransomware attack at MicroCode, a small vendor that manages a malpractice-insurance tracking database for CommonSpirit Health, went undiscovered for months. Some individuals had their Social Security numbers and financial information exposed; others’ letters say only their name and birth date were involved.

MicroCode, Inc., a Florida-based company that hosts and supports a database used by CommonSpirit Health, one of the largest Catholic hospital systems in the United States, to track medical malpractice insurance, has notified individuals of a data breach. MicroCode says a ransomware event on April 14, 2026 led to unauthorized access to the server hosting this database between January 19, 2026 and April 14, 2026. MicroCode reported the breach to the Washington Attorney General on July 30, 2026, confirming 4,096 affected Washington residents.

Source: MicroCode’s own Notice of Privacy Incident letter; Washington Attorney General data-breach notification (reported 07/30/2026, breach date 01/19/2026).

What Was Exposed Appears to Differ by Individual

MicroCode’s regulatory filing with the Washington Attorney General lists a broad set of exposed data categories for this incident: names, Social Security numbers, driver’s license numbers, and financial account information. But the individual notice letter Emery | Reddy reviewed tells a narrower story for that specific recipient, stating only their name and date of birth were involved, and explicitly noting that their Social Security number, financial information, and other sensitive personal information were not compromised. Read together, this suggests the scope of exposed information varied by individual, some people’s Social Security and financial data was involved, while others had only more limited information exposed. Anyone who received a letter should read it carefully to see which category applies to them.

A Vendor Breach Tied to One of the Largest U.S. Hospital Systems

MicroCode is a business-associate vendor, meaning it processes data on behalf of another organization rather than serving patients directly. CommonSpirit Health, the health system whose malpractice-insurance-tracking database MicroCode hosts, is one of the largest nonprofit hospital systems in the country. That relationship means people connected to CommonSpirit Health, potentially including physicians, providers, or staff covered under its malpractice insurance program, may be affected even though MicroCode itself is a company most of them had never heard of before receiving this letter.

What Information Was Exposed?

Depending on the individual, MicroCode’s Washington Attorney General filing and notice letters describe exposure of:

  • Name
  • Date of birth
  • Social Security number (confirmed for some individuals per the Washington AG filing; explicitly not involved for others per individual letters)
  • Driver’s license number (confirmed for some individuals per the Washington AG filing)
  • Financial account information (confirmed for some individuals per the Washington AG filing)

How Many People Are Affected?

MicroCode confirmed 4,096 affected Washington residents through its filing with the Washington Attorney General. Given CommonSpirit Health’s national scale, the true total number of affected individuals nationwide has not been disclosed and may be larger.

What Is MicroCode Offering Affected Individuals?

MicroCode has retained Kroll to operate a call center for individuals with questions about this incident. Representatives are available at 1-844-958-8933, Monday through Friday, 8 a.m. to 5:30 p.m. Central Time. MicroCode’s letter did not confirm a specific credit-monitoring enrollment offer for the recipient reviewed; individuals whose Social Security or financial information was involved should check their own letter for enrollment details, since the remedy offered may depend on which categories of information were exposed for that person.

Your Information Is at Risk

For individuals whose Social Security number and financial account information were exposed, the risk is serious: that combination is enough to open new credit or access existing accounts. Even for individuals whose letter states only a name and date of birth were involved, that information can still be combined with other publicly available details to attempt identity theft or targeted phishing. MicroCode says it has no reason to believe information was used for any unlawful purpose, but affected individuals should still monitor their accounts and credit reports.

Do You Have Legal Options?

Vendors that store Social Security numbers, driver’s license numbers, and financial information on behalf of a healthcare system have a legal duty to secure that data and to notify affected individuals without unreasonable delay.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice letter from MicroCode.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

FAQ

Who is affected by the MicroCode data breach?

MicroCode confirmed 4,096 affected Washington residents through its filing with the Washington Attorney General. Those affected are connected to CommonSpirit Health’s malpractice-insurance-tracking database, which MicroCode hosts as a vendor.

What information was exposed?

It appears to vary by individual. MicroCode’s Washington regulatory filing lists names, Social Security numbers, driver’s license numbers, and financial account information as exposed for this incident overall. An individual notice letter reviewed by Emery | Reddy states that for that specific recipient, only a name and date of birth were involved, and that their Social Security number and financial information were not compromised. Check your own letter to see which categories apply to you.

When did the breach happen?

MicroCode says a ransomware event occurred on April 14, 2026, and that unauthorized access to the affected server occurred between January 19, 2026 and April 14, 2026. MicroCode determined in July 2026 that specific individuals’ information was on the affected server, and reported the breach to the Washington Attorney General on July 30, 2026.

Why does CommonSpirit Health matter if my letter came from MicroCode?

MicroCode is a vendor that hosts a database CommonSpirit Health, one of the largest hospital systems in the country, uses to track medical malpractice insurance. People connected to that system may receive a letter from MicroCode, a company they may not recognize, because MicroCode was the one holding the affected data.

Is MicroCode offering credit monitoring?

MicroCode has set up a Kroll-run call center for questions at 1-844-958-8933. Whether a specific credit-monitoring offer applies to you may depend on which categories of your information were exposed; check your individual letter for enrollment details.

Do I have a legal claim?

Vendors that store Social Security numbers and financial information on behalf of a healthcare system have a legal duty to secure that data and to notify affected individuals without unreasonable delay. If you received a notice letter from MicroCode, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now