Rockwood Retirement Communities, also known as Spokane United Methodist Homes, disclosed a data breach in an August 2026 filing with Washington regulators, confirming that residents’ and employees’ personal information may have been exposed. The exact number of affected people has not been disclosed. Anyone notified should immediately review their credit reports and consider a credit freeze.
| Company | Rockwood Retirement Communities (Spokane United Methodist Homes) |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Full Names, Social Security Numbers, Dates of Birth, Financial Account Information, Health or Medical Information, Government-Issued Identification Numbers |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unauthorized Access |
| Regulators Notified | Washington State Attorney General |
What Happened in the Rockwood Retirement Communities Data Breach?
Rockwood Retirement Communities, also operating as Spokane United Methodist Homes, recently disclosed a data breach affecting people connected to its senior living community. The organization filed a formal notification with state regulators in August 2026. This filing confirmed that unauthorized parties had accessed sensitive personal information.
According to the notification, the incident involved unauthorized access to systems or files containing personal data. The exact discovery date has not been publicly disclosed. However, the organization determined that certain files were accessed without permission before taking action to secure its network.
Once the organization became aware of the issue, it began an internal review to understand the scope of the exposure. As a result, Rockwood Retirement Communities worked to determine which individuals had information involved. This process ultimately led to formal notification of affected people and regulators.
Because senior care organizations often store years of resident and employee records, breaches like this one can involve a wide range of sensitive details. The investigation into how the breach occurred and what specific data was involved appears to have informed the notification process. Additional facts about the intrusion method have not been made public.
Who was affected?
The breach may affect current and former residents of Rockwood Retirement Communities, along with employees whose personal records were stored on the organization’s systems. Because the facility provides senior living and long-term care services, many affected individuals are likely older adults. This population can be especially vulnerable to identity theft and financial scams.
The exact number of people affected has not been publicly disclosed. In addition, it is not yet clear whether the breach affected only Washington residents or a broader geographic group. Family members or authorized representatives handling a resident’s affairs could also be indirectly affected if their information was stored alongside a resident’s records.
Because retirement communities often maintain detailed health and financial files, both current and former staff members could also be included. This means the breach’s impact may extend beyond just residents. Anyone who received a notification letter from Rockwood Retirement Communities should assume their information was part of the exposed data.
What Information Was Potentially Exposed?
The notification filed with regulators indicates that personal information was accessed without authorization. While the full scope of exposed data categories has not been itemized publicly in detail, breach notifications of this type typically involve several forms of sensitive identifying information.
- Full names
- Social Security numbers
- Dates of birth
- Financial account information
- Health or medical information
- Government-issued identification numbers
If Social Security numbers were involved, affected individuals face a heightened risk of identity theft. Criminals can use this data to open new credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. This type of fraud can take months to detect and even longer to resolve.
Similarly, if health or financial information was exposed, affected individuals could face medical identity theft or unauthorized account access. For older residents, this risk is especially serious. Scammers frequently target seniors with convincing phone or mail scams that reference real personal details stolen in breaches like this one.
What is the company doing?
In response to the breach, Rockwood Retirement Communities took steps to investigate the incident and secure its systems. The organization also notified affected individuals directly, as required under state breach notification laws. This notification explained what data may have been involved and what recipients should do next.
Additionally, the organization filed formal notice with the Washington State Attorney General. This filing is a required step under Washington’s data breach notification law when a certain number of residents are affected. It also provides regulators with details about the scope and nature of the incident.
Going forward, Rockwood Retirement Communities likely reviewed its internal security practices to prevent similar incidents. Many organizations facing breaches of this kind also work with cybersecurity specialists. This helps confirm that unauthorized access has been fully contained and that vulnerabilities are addressed.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should request a copy of their credit report and review it closely. Look for unfamiliar accounts, inquiries, or changes that you did not authorize. Catching suspicious activity early can prevent further financial damage.
You can request free credit reports from each of the three major credit bureaus. Because errors or fraud can appear months after a breach, it helps to check your reports periodically rather than just once. If you notice anything unusual, report it to the credit bureau immediately.
Consider a Credit Freeze or Fraud Alert
If your Social Security number was exposed, placing a credit freeze with each credit bureau is one of the strongest protective steps available. A freeze blocks new creditors from accessing your credit file, which makes it much harder for identity thieves to open accounts in your name.
Alternatively, a fraud alert requires lenders to verify your identity before extending credit. This option is faster to set up and still offers meaningful protection. Either way, acting quickly reduces the window of opportunity for criminals to misuse your information.
Watch for Phishing and Scam Attempts
After a breach, scammers often follow up with phishing emails, texts, or phone calls designed to look official. Because your name and other details may already be compromised, these messages can seem convincing. Never click links or share personal information in response to unsolicited messages.
Instead, verify any communication by contacting the organization directly using a known phone number or website. This is especially important for older residents, who are frequently targeted with scams referencing real breach details. When in doubt, treat unexpected requests for personal information with caution.
Protect Health Information and Insurance Accounts
If medical or health information was exposed, review your insurance statements and medical records for unfamiliar claims or services. Medical identity theft can lead to incorrect information appearing in your health records, which may affect future care.
As a result, it is wise to request an itemized list of services from your health insurer periodically. If you spot a claim you don’t recognize, report it right away. Acting promptly can help prevent long-term complications with your medical history or insurance coverage.
Seek Legal Guidance if You Were Affected
Because breaches involving sensitive personal data can lead to real financial harm, affected individuals may want to speak with a data breach attorney. An attorney can help evaluate whether you qualify for compensation through a class action or individual claim.
Many attorneys offer free consultations, so there is little downside to asking questions. This is especially useful if you have already experienced fraud or unauthorized account activity following the breach. Getting legal advice early can help preserve your options and protect your rights.
More Information
Official data breach notification report (PDF) from Washington State Attorney General
