2026 Mt Spokane Pediatrics (WA) — network intrusion; PHI exfiltration affecting ~29,410 residents
Data compromised
Names, dates of birth, Social Security numbers, health insurance identifiers, medical treatment and diagnostics documentation, beneficiary numbers and service dates per published consumer breach summaries
Technical writeup
Mt. Spokane Pediatrics, operating outpatient pediatric clinics across Spokane County, disclosed that January 1, 2026 activity involved unauthorized access to network systems storing HIPAA‑regulated PHI. Assisted forensics surfaced on April 22 2026 that files encompassing names, dates of birth, government identifiers (SSNs where present), payer information, diagnoses, prescriptions, beneficiary numbers and service dates left the environment via the intrusion pathway. Notifications to Washington residents enumerated in jurisdictional trackers began mailing April 30 2026 with multi‑thousand state resident denominators aligning with OCR-adjacent press aggregation.
Root cause
Unauthorized network intrusion with confirmed data exfiltration post forensic investigation