Microcode, Inc. Data Breach Exposes Patient Health and Personal Information

Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: July 2026

What Happened in the Microcode, Inc. Data Breach?

Microcode, Inc., a technology vendor tied to CommonSpirit Health, recently filed a formal data breach notification with the Washington State Attorney General. This filing confirms that unauthorized parties may have gained access to sensitive personal and health information tied to patients connected to CommonSpirit Health’s network. The Microcode data breach notification is the primary public record currently available about this incident.

According to the notification, Microcode discovered that data within its systems had been compromised. As a result, the company began a formal review process to determine the scope of the exposure. However, the notification does not specify the exact method attackers used to gain access, nor does it detail a precise timeline of when the intrusion first began.

Because Microcode works as a service provider for CommonSpirit Health, the breach highlights a growing risk in healthcare: vendors and third-party technology partners often hold the same sensitive data as the hospital systems they support. When one of these vendors suffers a breach, patients from the partnered health system can be affected too. Microcode’s investigation into the full scope of this incident appears to still be ongoing.

Following discovery, Microcode took steps to investigate the incident and notify regulators. This regulatory filing with Washington’s Attorney General is a required step under state breach notification laws. In addition, affected individuals are expected to receive direct notice describing what specific information of theirs may have been involved.

Who was affected?

The individuals affected by this breach appear to be patients whose information was processed or stored through Microcode’s systems on behalf of CommonSpirit Health. Because CommonSpirit Health operates a large network of hospitals and clinics, the population potentially affected could span multiple states. However, the notification filed with Washington’s Attorney General does not provide a specific total count of affected individuals.

At this time, the exact number of impacted patients has not been publicly disclosed. As a result, individuals who have received care through CommonSpirit Health facilities or affiliated providers should watch for a direct notification letter. Because healthcare data often includes information about minors, elderly patients, and other vulnerable groups, the population affected may include people who need extra help protecting their identities.

What Information Was Potentially Exposed?

Data breach notifications involving healthcare vendors like Microcode typically involve highly sensitive categories of personal and medical information. While the notification confirms that a breach occurred, it does not provide an exhaustive public list of every data element compromised for each individual. Based on the nature of the breach and the type of vendor involved, the following categories of information are commonly at risk in incidents like this one.

  • Full names
  • Dates of birth
  • Medical record numbers
  • Treatment or diagnosis information
  • Health insurance details
  • Social Security numbers
  • Patient account or billing information

If Social Security numbers or health insurance details were exposed, affected patients could face a heightened risk of identity theft. Criminals often use stolen Social Security numbers to open new credit lines, file fraudulent tax returns, or apply for loans in someone else’s name. This type of fraud can take months to detect and even longer to fully resolve.

In addition, exposed medical information creates the risk of medical identity theft. This occurs when someone uses stolen health data to receive treatment, obtain prescriptions, or submit fraudulent insurance claims under another person’s name. Medical identity theft can be especially harmful because it may corrupt a victim’s actual medical records, potentially leading to incorrect treatment decisions down the line.

What is the company doing?

In response to the breach, Microcode launched an investigation to determine which systems were compromised and what data was involved. The company also filed the required breach notification with Washington’s Attorney General, a step meant to keep regulators informed and to trigger consumer protection obligations under state law.

Beyond the regulatory filing, Microcode is expected to notify affected individuals directly. This notice should include specific guidance about the types of information involved in each person’s case. Because Microcode works closely with CommonSpirit Health, the two organizations may coordinate on remediation efforts, including any credit monitoring or identity protection services offered to affected patients.

What Should Affected Individuals Do?

Monitor Your Credit Reports Regularly

Affected individuals should check their credit reports for unfamiliar accounts or inquiries. You can request free credit reports from each of the three major credit bureaus through AnnualCreditReport.com. Reviewing these reports regularly helps you catch fraudulent activity early, before it causes lasting financial damage.

Because identity thieves sometimes wait months before using stolen data, ongoing vigilance matters more than a single check. Consider spacing out your free reports throughout the year so you have continuous visibility. If you notice anything suspicious, report it to the credit bureau immediately.

Consider a Fraud Alert or Credit Freeze

Since Social Security numbers may have been involved in this breach, placing a fraud alert or credit freeze is a strong protective step. A fraud alert requires creditors to verify your identity before opening new accounts in your name. A credit freeze goes further by blocking access to your credit file entirely.

To set up either protection, contact one of the three major credit bureaus directly, as they are required to notify the others. This process is free and can be reversed later if you need to apply for credit. Taking this step now can prevent significant headaches later.

Watch for Medical Identity Theft

Because health information may have been exposed, affected patients should carefully review any insurance statements or medical bills for unfamiliar charges. Request a copy of your medical records periodically to check for treatments or diagnoses you don’t recognize. This can help you catch fraudulent use of your health identity early.

If you spot anything unusual, contact your healthcare provider and insurance company right away. In addition, you may want to request an accounting of disclosures from CommonSpirit Health to see who has accessed your records. Acting quickly can limit the damage caused by medical identity theft.

Stay Alert for Phishing Attempts

After a healthcare data breach, scammers often send phishing emails or texts pretending to be from the breached company. These messages may ask you to click a link or share personal details to


More Information

Official data breach notification from Washington State Attorney General

Related Data Breaches

View the full list of tracked data breaches →