← Corewell Health

2026 Corewell Health — ~19K patients (vendor Pinnacle Holdings; incident Nov 2024; disclosed Mar 2026)

2026 19.0K records affected Share on X

Data compromised

PHI/PII as described in patient notifications (varies by individual)

Technical writeup

Corewell Health, a Michigan integrated health system, notified approximately 19,000 patients in March 2026 after a former vendor, Pinnacle Holdings, LTD (Colorado), experienced unauthorized activity on its network. Public materials summarized access between roughly November 11 and November 25, 2024, with disruption noted around November 25, 2024. Depending on the individual, disclosed data categories could include names, contact information, SSN/taxpayer IDs, government ID numbers, financial and payment card data, credentials, signatures, biometrics, dates of birth, clinical and billing information, prescriptions, and insurance identifiers. Pinnacle and Corewell described remediation, notifications, and offers of credit monitoring where applicable; treat exact categories as listed in official letters.

Root cause

Unauthorized access to vendor (Pinnacle Holdings) systems

References