Incident

Catholic Health Initiatives hit by data breach affecting over 600,000 persons


Learn More

Catholic Health Initiatives, part of the CommonSpirit health-care system, has been impacted by a ransomware attack, affecting hospitals in 13 states, including Kentucky. The data breach notification process began in December and was completed in April 2023. The unauthorized access to the network occurred between September 16 and October 3, with the unauthorized party obtaining copies of data from file-share servers. The compromised information includes demographics, medical records, billing information, and in some cases, Social Security numbers. CommonSpirit has taken steps to secure the network, and although there is no evidence of misuse, caution is advised. The data breach has cost CommonSpirit approximately $150 million, and over 623,700 individuals have been affected according to the U.S. Department of Health & Human Services Office for Civil Rights.
Catholic Health Initiatives hit by data breach affecting over 600,000 persons