Spokane Digestive Disease Center Data Breach Exposes Patient Health Records

Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: May 2026

What Happened in the Spokane Digestive Disease Center Data Breach?

Spokane Digestive Disease Center, P.S. recently filed a formal data breach notification with the Washington State Attorney General. This filing confirms that the medical practice experienced a security incident involving sensitive patient information. As a result, patients who received care through this gastroenterology practice may now face exposure of their personal and health data.

The notification submitted to Washington regulators does not include extensive public detail about how the intrusion occurred. However, the filing itself signals that an unauthorized party accessed, or potentially accessed, systems containing patient records. Because healthcare providers are legally required to report breaches involving protected health information, this filing represents an official acknowledgment that patient data security was compromised.

Following discovery of the incident, the practice appears to have launched a review process to determine the scope of the exposure. This type of investigation typically involves forensic specialists who examine which systems were accessed and which specific records were involved. In addition, the practice would have needed to determine which patients require direct notification under state and federal law.

At this time, specific details about the exact intrusion method have not been publicly disclosed. Nevertheless, the filing with the Washington Attorney General confirms that this breach is real and that patient notifications are underway or have already occurred.

Who was affected?

The individuals affected by this breach are primarily patients who received digestive health services through Spokane Digestive Disease Center, P.S. Because the practice specializes in gastroenterology, affected patients likely include individuals who underwent diagnostic testing, procedures, or ongoing treatment for digestive conditions. This means the exposed information may be tied directly to sensitive medical histories.

The exact number of affected individuals has not been publicly disclosed in available records. However, any healthcare breach reported to a state attorney general typically involves a meaningful number of patients, since minor incidents rarely trigger this level of regulatory filing. Patients across the Spokane, Washington region who used this provider should consider themselves potentially affected until they receive official confirmation.

What Information Was Potentially Exposed?

Because this incident involves a medical practice, the data at risk likely includes both personal identifiers and clinical health information. Healthcare breaches of this nature commonly expose a combination of demographic details and treatment records tied to a patient’s identity.

  • Full names
  • Contact information such as addresses and phone numbers
  • Dates of birth
  • Medical record numbers
  • Diagnosis and treatment information
  • Health insurance details
  • Potentially Social Security numbers

If Social Security numbers or insurance identifiers were part of the exposed data, affected patients face a real risk of identity theft. Criminals can use this type of information to open fraudulent credit accounts, file false tax returns, or apply for loans in a victim’s name. Because medical identity theft often goes undetected for longer periods, victims may not notice the damage until significant harm has occurred.

In addition, exposure of diagnosis and treatment details creates a separate risk of medical fraud. Bad actors can use stolen health insurance information to receive treatment or submit fraudulent claims under someone else’s identity. This can lead to inaccurate medical records for the actual patient, which may later interfere with their own care or insurance coverage.

What is the company doing?

In response to the breach, Spokane Digestive Disease Center, P.S. filed the required notification with the Washington State Attorney General’s office. This step reflects compliance with state breach notification laws that require timely disclosure once a compromise is confirmed. The practice also appears to be notifying affected patients directly, as required under both state and federal healthcare privacy regulations.

Beyond notification, healthcare providers facing this type of incident typically work to strengthen their network security following an investigation. This can include resetting credentials, patching vulnerable systems, and reviewing access controls to prevent future unauthorized access. Although the source filing does not detail every remediation step taken, these measures are standard practice for medical providers responding to a confirmed breach.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Affected patients should request copies of their credit reports from all three major credit bureaus. Reviewing these reports carefully can help identify unfamiliar accounts or inquiries tied to identity theft. Because federal law allows consumers to access free credit reports, this step costs nothing and takes only a few minutes.

In addition, individuals should repeat this review periodically over the coming months. Identity thieves sometimes wait before using stolen information, so ongoing vigilance matters just as much as an immediate check. If anything looks unfamiliar, reporting it quickly can limit potential damage.

Consider a Fraud Alert or Credit Freeze

Because this breach may include Social Security numbers, affected patients should strongly consider placing a fraud alert or credit freeze on their credit files. A fraud alert requires lenders to verify identity before opening new credit, while a freeze blocks new account approval entirely. Both options are free and can be requested directly through the credit bureaus.

For patients concerned about long-term exposure, a credit freeze generally offers stronger protection than a fraud alert alone. Although a freeze requires temporarily lifting it before applying for new credit, this small inconvenience is often worth the added security. As a result, many privacy experts recommend freezes for anyone affected by a healthcare data breach.

Watch for Medical Fraud and Insurance Misuse

Because health insurance details may have been exposed, patients should carefully review any statements from their insurance provider. This includes checking explanation-of-benefits notices for unfamiliar procedures, providers, or charges. If something looks wrong, contacting the insurer immediately can help prevent further fraudulent use.

Patients should also request a copy of their medical records periodically to confirm accuracy. This matters because inaccurate records caused by medical identity theft can affect future treatment decisions. Catching errors early gives patients the best chance to correct their files before problems escalate.

Stay Alert for Phishing Attempts

Following any healthcare data breach, scammers often use stolen information to craft convincing phishing emails or phone calls. These messages may reference real details from a patient’s history to appear legitimate. Therefore, individuals should treat unexpected messages requesting personal information with strong suspicion.

Instead of clicking links or providing information over the phone, patients should verify requests by contacting the provider directly using a known number. This simple habit can prevent scammers from successfully impersonating a trusted healthcare organization. Because phishing attempts often increase after a breach becomes public, this vigilance should continue for months, not just days.

Consult a Data Breach Attorney

Patients concerned about how this breach may affect them can benefit from speaking with an attorney who focuses on data breach cases. A knowledgeable attorney can help determine whether compensation may be available and explain realistic next steps. Many offer free initial consultations, so there is little downside to asking questions.

Because deadlines for legal claims vary by state and case type, acting sooner rather than later is generally wise. Waiting too long could limit available options if a claim becomes appropriate. A free case evaluation can clarify what rights an affected patient may have.



More Information

Official data breach notification from Washington State Attorney General

Related Data Breaches