← Blog

Rockwood Retirement Breach: SSNs and Health Data

Share on X

Spokane United Methodist Homes, doing business as Rockwood Retirement Communities, began mailing notices on 20 August 2026 about a network intrusion first spotted around 16 February 2026. Independent forensics found that certain files may have been acquired without authorization. A later file review confirmed personal and protected health information in that data. Not every field applied to every person. Rockwood says it has no evidence of misuse so far and has notified HHS OCR.

If you are a resident, former resident, employee, or family contact tied to Rockwood’s Spokane senior living community, treat this as a confirmed Rockwood Retirement Communities data breach involving high-sensitivity identity and health fields. Canonical record: rockwood-retirement2026.

What happened in the Rockwood Retirement Communities data breach

Rockwood’s website notice dated 20 August 2026 lays out a slow, documented timeline. On or around 16 February 2026, the organization saw suspicious activity on its network. It secured internal systems and hired independent forensic experts. The investigation concluded that certain files may have been taken without authorization. A separate independent team then reviewed those files. On 8 June 2026, that review found that personal information may have been inside the affected data. Rockwood finished identifying potentially affected people, validating contact information, and scoping impacted fields on 27 July 2026. Formal individual notices went out 20 August 2026, with a web posting as substitute notice when mail addresses could not be found.

HIPAA Journal summarizes the same arc as a February 2026 hacking incident with unauthorized network access and file exfiltration, OCR notified, and no public headcount yet on the HHS breach portal at the time of that reporting.

What this is not: a published ransomware leak-site census, a claim that every Rockwood resident lost every data type on the list, or evidence that thieves already opened new credit lines in residents’ names. Rockwood explicitly says it has no evidence of misuse or attempted misuse for identity theft at notice time. That sentence is an early-investigation posture, not a lifetime guarantee.

What data may have been involved

Based on Rockwood’s review of the data set, information that may have been involved includes:

  • Name
  • Social Security number
  • Date of birth
  • Driver’s license or state identification number
  • Passport number
  • Financial account information
  • Medicaid or Medicare number
  • Medical information
  • Health insurance information

Rockwood stresses that not all information was involved for all individuals. Your letter — if you received one — is the person-specific inventory. The web notice is the population-level menu.

That menu is senior-living catastrophic: government ID plus SSN plus Medicare/Medicaid identifiers plus clinical and insurance fields. It is the toolkit for tax fraud, benefits fraud, medical identity theft, and highly credible “Rockwood billing” calls aimed at adult children who pay mom’s fees.

Timeline in plain English

  • ~16 February 2026 — Suspicious network activity detected; containment and forensics begin.
  • Investigation — Files may have been acquired without authorization.
  • 8 June 2026 — File review confirms personal information may be in the affected data.
  • 27 July 2026 — Individual identification and contact validation completed.
  • 20 August 2026 — Formal notices mailed; web substitute notice posted; call center live.

Roughly six months separate detection and mail. That lag is common when healthcare and senior-living operators review unstructured file shares before they can truthfully say whose SSN sat in which PDF. It is also long enough for opportunistic fraudsters to prepare scripts that cite “the Rockwood letter you should have gotten.”

Who is at risk

Current and former residents whose administrative or clinical files lived on the hit network shares. Senior living generates dense paperwork: admissions, billing, pharmacy, insurance authorizations, emergency contacts.

People with Medicare or Medicaid numbers in Rockwood’s systems. Benefits identity theft does not always show up as a credit-card charge. It shows up as a rejected claim or a strange Explanation of Benefits.

Individuals whose driver’s license, state ID, or passport was copied into admissions packets. Those numbers power synthetic identity and account-opening fraud.

Family members and responsible parties who share financial account information for automatic rent or care payments. The notice lists financial account information among possible fields. Adult children who never lived on campus can still be in the file.

Employees or contractors if HR or payroll files sat in the same acquired set. Rockwood’s public web notice is framed around resident-facing PHI/PII; do not invent an employee census — do read your own letter carefully if one arrives.

Not automatically every senior in Spokane. Other facilities have other networks. Brand-jacking will still use “Rockwood” in regional SMS because the story is local news.

What Rockwood said — and what it offered

The web notice apologizes for concern, points people to a toll-free call center at 1-866-898-5714 (Monday–Friday, 5:00 a.m. to 5:00 p.m. Pacific Time, excluding major U.S. holidays), and states that HHS OCR has been notified. The companion individual letter (also dated 20 August 2026, signed by President & CEO Jim Maxwell) offers complimentary single-bureau credit monitoring and fraud assistance through Cyberscout / TransUnion for 24 months from enrollment, with enrollment instructions at bfs.cyberscout.com/activate and a deadline of 20 November 2026. Letters include a unique enrollment code; do not trust a code that arrives only by SMS from an unknown number.

Rockwood’s “no evidence of misuse” line is standard and honest about what forensics can see early. Criminals who buy a file months later will not appear in February logs. Treat monitoring enrollment as useful, not optional theater, especially when SSNs and Medicare numbers are in play.

Why senior-living breaches cut deeper

Residents may have limited ability to police credit portals, spot fake IRS letters, or challenge a Medicare claim. Family caregivers become the real security operations center. Attackers know that. A voice call that opens with a resident’s full name, date of birth, and “Rockwood business office” framing will land harder than a generic bank phishing text.

Medical information plus insurance identifiers enables a quieter crime: receiving care or prescriptions in someone else’s identity. Credit freezes help with new-account fraud. They do not automatically stop every medical identity issue. Residents and families still need to watch EOBs and Explanation of Benefits language for services no one received.

HIPAA Journal places Rockwood alongside other 2026 rehabilitative and senior-living hacking notices. The sector pattern is familiar: long file reviews, broad PII/PHI menus, delayed OCR portal visibility, and phishing that outruns the mail. Rockwood’s case is notable for passport numbers appearing in the public field list — less common than DL/SSN in some skilled-nursing notices, and useful for international travel and identity-document fraud narratives.

Was I affected?

Rockwood has not published a public lookup form or a nationwide headcount in the materials cited here. HIPAA Journal noted the incident had not yet appeared with a count on the OCR portal at the time of its write-up. Practical rules:

  • You received a Rockwood letter dated around 20 August 2026 → you are in the notified set; follow the letter’s field list and enrollment code.
  • You lived at, worked with, or paid for care at Rockwood and got no letter → you may still be covered by substitute web notice if Rockwood lacked your address; call the call center with questions rather than a random “breach checker” site.
  • You have no Rockwood relationship → outside the attested file set, still inside regional phishing.

Do not upload a resident’s full SSN to a third-party “Rockwood breach search.” Do not give a Cyberscout code to a caller who claims to “activate monitoring for you.”

What you should do after the Rockwood data breach

  1. Read the letter end to end. Note which data types Rockwood says may apply to you. Keep the enrollment code offline.
  2. Enroll in the offered monitoring at the official Cyberscout activate URL from the letter before the 20 November 2026 deadline, typing the hostname yourself.
  3. Place a credit freeze with Equifax, Experian, and TransUnion if SSNs or government IDs may be involved. Freezes are free under U.S. law and beat monitoring alone for new-account fraud.
  4. Order free credit reports and scan for new inquiries or accounts you did not open.
  5. Watch Medicare / Medicaid / insurance EOBs for services, DME, or pharmacy claims nobody received. Report anomalies to the plan and to Medicare’s fraud lines as applicable.
  6. Call the Rockwood call center at 1-866-898-5714 for incident questions — not a number from an unexpected text.
  7. Tell family caregivers the exact scam patterns below. Adult children are the high-value social-engineering target.
  8. Never pay a “Rockwood ransomware recovery fee” or wire money to “release medical records.”
  9. File an IRS Identity Protection PIN consideration if an SSN was involved and tax fraud is a concern for that household.
  10. Document suspicious contacts (date, number, what they already knew) before you engage Rockwood or law enforcement.

Phishing and social engineering to expect

  • “This is Rockwood billing — we need to re-verify the bank account on file after the cyberattack.”
  • “HHS OCR requires you to confirm your Medicare number at this portal.”
  • “Your Cyberscout enrollment failed — read me the code from the letter.”
  • “Mom’s passport was in the breach — overnight a replacement via this courier link.”
  • Lookalike domains swapping characters in “rockwood” or “cyberscout.”

Real Rockwood staff will not need you to read an enrollment code over the phone to a surprise caller. Real OCR will not demand portal logins via SMS. Hang up. Use the letter. Use numbers you already have.

How the attack is described

Public sources describe suspicious network activity, unauthorized access, and files acquired or exfiltrated. Rockwood has not published a malware family, ransomware affiliate name, initial access path (VPN, phishing, vulnerable appliance), or dwell-time metrics beyond the February detection date. HIPAA Journal characterizes it as a hacking incident with file exfiltration. That is enough to treat it as an external intrusion with data loss risk — not enough to blame a specific branded ransomware crew in the catalog.

Until Rockwood publishes a deeper post-mortem, assume classic senior-living file-server exposure: mixed administrative and clinical documents, inconsistent retention, and identity fields repeating across PDFs. The June–July review duration fits that kind of corpus.

Industry and campaign context

2026 has already seen multiple rehabilitative care and senior living hacking notices in U.S. trade press. Operators hold SSNs because billing and benefits demand them. They hold clinical detail because care demands it. They often discover, months later, that a “temporary” share still held passport scans from an admissions packet. Rockwood’s field list reads like that reality.

Compare lightly, without inventing links: other skilled-nursing and rehab notices in the same HIPAA Journal roundup also cite stolen credentials or network intrusions and broad PHI menus. Rockwood’s differentiating public facts are the clear February–August timeline, passport numbers in the menu, Cyberscout offer details, and the Spokane United Methodist Homes legal name on the letter.

For Washington residents, state AG resources and credit-freeze guidance still apply regardless of whether the OCR portal count appears tomorrow or next quarter.

Canonical record and sources

Canonical BreachHistory page: 2026 Rockwood Retirement Communities — network intrusion, PII/PHI in acquired files.

Sources: Rockwood web notice PDF; individual notice letter PDF; HIPAA Journal senior living hacking roundup.

For family caregivers

You may be the person who opens the mail. You may also be the person scammers call first. Agree with siblings who handles credit freezes and who watches Medicare EOBs. Do not split the Cyberscout code across group chats where a compromised phone can screenshot it. If the resident has cognitive impairment, assume they will say “yes” to a calm caller who knows their date of birth — brief them with a simple rule: no codes, no wires, call you first.

If financial accounts used for automatic Rockwood payments may be in scope, talk to the bank about alerts and whether account numbers should be rotated. Do that from a number on the back of the card, not from a “fraud department” inbound call.

For Rockwood and peer operators reading this

Six months from detection to notice is legally navigable when file review is real work. It is operationally painful for residents. Pre-segment which shares hold SSNs and passport images. Know your substitute-notice plan before you need it. Staff the call center before the letters hit mailboxes. The phishing wave starts the morning local news picks up the story — not the morning OCR updates its portal.

FAQ

Did Rockwood confirm a census? Not in the public web notice or letter materials cited here. OCR portal listing may add a count later.

Is misuse confirmed? Rockwood says it has no evidence of misuse or attempted misuse at notice time.

Was OCR notified? Yes, per Rockwood and HIPAA Journal.

What is the call center number? 1-866-898-5714, weekdays 5 a.m.–5 p.m. Pacific, excluding major U.S. holidays.

How long is free monitoring? The letter offers 24 months of single-bureau credit monitoring via Cyberscout from enrollment, with a 20 November 2026 enrollment deadline.

Did everyone lose every data type? No. Rockwood says not all information was involved for all individuals.

Substitute notice and people Rockwood could not mail

Rockwood’s web posting exists partly because some potentially affected people had no usable mailing address. That group is easy to miss in “I never got a letter” conversations. If you moved after leaving the community, changed names, or were listed only as an emergency contact with a stale phone number, the substitute notice is meant for you. Call the call center with enough identifying detail to ask whether you are in the reviewed set — without reading a full SSN into a voicemail box you do not trust.

Mail delays also matter. Letters dated 20 August 2026 can arrive days later. Scammers will claim your “second notice” is coming by email attachment. Rockwood’s verified channels in the public materials are First-Class Mail, the website notice, and the toll-free line — not a sudden PDF from a Gmail lookalike.

Medical identity theft: what “watch EOBs” actually means

When medical information and health insurance fields may be involved, the actionable habit is calendar-based, not panic-based. Once a month for the next year, open the insurance portal or paper EOB and scan for providers, dates of service, and durable medical equipment you do not recognize. A single fraudulent physical-therapy claim is enough to create billing hell for a resident on a fixed income.

If something looks wrong, contact the insurer’s fraud number from the back of the insurance card and Rockwood’s call center for context on whether similar reports are coming in. Do not “verify the claim” by calling a number printed in a threatening SMS that cites the Rockwood Retirement Communities data breach as urgency bait.

Massachusetts and multi-state notice clutter

Trade coverage noted a Massachusetts consumer-affairs filing around 25 August 2026 alongside the Spokane web notice. Multi-state notice is common when affected individuals live outside Washington. It does not by itself publish a national headcount. If you live in Massachusetts or another state and receive a Rockwood letter, treat it as your personal inventory — the same field menu, the same monitoring offer rules, the same freeze advice.

Law-firm intake pages will ask you to “see if you qualify.” That is optional civil process, not a substitute for freezes and EOB monitoring. Prioritize the protective steps in the company letter before you prioritize plaintiffs’ questionnaires.

What remains unknown

Exact population, initial access vector, whether a ransomware note was involved, and whether any subset of files will appear on criminal forums are unpublished. BreachHistory will update the catalog if OCR posts a verified count or Rockwood revises the field list. Forum screenshots are not that update.

The Rockwood Retirement Communities data breach is a verified senior-living intrusion with a hard timeline and a hard field menu. Act on SSNs, government IDs, Medicare/Medicaid numbers, and medical information as if they travel — because the company’s own notice says they may.