CommonSpirit Health Data Breach
CommonSpirit Health Network Server Breach Affects 623K Patients
What happened in the CommonSpirit Health data breach?
The CommonSpirit Health data breach was reported on December 1, 2022 and affected 623,774 individuals. The breach type was Hacking/IT Incident involving Network Server. This breach occurred in Illinois. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
CommonSpirit Health Breach Details
CommonSpirit Health Data Breach Report
Incident Overview
CommonSpirit Health, one of the largest nonprofit healthcare systems in the United States, experienced a significant data breach involving unauthorized access to its network servers. The breach was reported to the U.S. Department of Health and Human Services on December 1, 2022, affecting 623,774 individuals across its Illinois operations and potentially beyond. The incident involved a hacking or IT-related intrusion into CommonSpirit's network infrastructure, resulting in the potential exposure of sensitive patient health information and personal data maintained on compromised network servers.
Discovery and Response Timeline
CommonSpirit Health discovered the unauthorized access to its network servers through security monitoring systems and investigation protocols. Upon discovery, the organization initiated a comprehensive investigation to determine the scope of the breach, identify affected individuals, and assess what data may have been accessed or exfiltrated. The entity worked with cybersecurity experts and law enforcement to investigate the incident. Following HIPAA breach notification requirements, CommonSpirit began the process of notifying affected individuals, with the formal submission to HHS occurring on December 1, 2022. The organization also notified relevant state authorities in Illinois and other affected states, as required by state breach notification laws.
Technical Details of the Breach
The breach occurred on a network server, which typically indicates that attackers gained unauthorized access to CommonSpirit's internal network infrastructure rather than a single endpoint device. Network server compromises often result from vulnerabilities such as unpatched software, weak authentication credentials, phishing attacks targeting employees, or exploitation of known security weaknesses in network management systems. Once inside the network, threat actors may have been able to access multiple systems and databases containing patient information. The scale of the breach—affecting over 623,000 individuals—suggests the attackers had access to centralized systems or databases that store information across multiple facilities within the CommonSpirit Health system. The involvement of a business associate indicates that third-party vendors or contractors with access to CommonSpirit's systems may have also been implicated in the breach or had their systems compromised as an entry point.
Organizational Context
CommonSpirit Health is a major nonprofit healthcare system headquartered in Chicago, Illinois, operating hundreds of hospitals and healthcare facilities across multiple states. The organization provides comprehensive healthcare services including acute care, emergency services, primary care, specialty care, and other medical services. With operations spanning numerous states and serving millions of patients annually, CommonSpirit maintains extensive databases of patient health information, medical records, and personal data. The scale of the organization means that a single network compromise can potentially affect hundreds of thousands of patients across its service area. The involvement of business associates—such as billing companies, IT service providers, or other healthcare vendors—adds complexity to breach investigations and notification requirements, as these entities may also need to notify their own customers and regulatory bodies.
Patient Impact and Affected Information
The breach affected 623,774 individuals, primarily in Illinois but potentially extending to other states where CommonSpirit operates. These individuals may have had various types of protected health information (PHI) exposed through the compromised network servers. Depending on the systems accessed, exposed data likely includes names, addresses, dates of birth, Social Security numbers, insurance information, medical record numbers, and clinical information. The specific data elements exposed would depend on which databases and systems the attackers accessed during their time on the network. CommonSpirit Health was required under HIPAA regulations to notify all affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. Notifications were sent via mail and potentially through other channels, informing patients of the breach, the types of information potentially exposed, steps the organization was taking to address the incident, and recommended actions patients should take to protect themselves.
HIPAA Compliance and Industry Context
Under the Health Insurance Portability and Accountability Act (HIPAA), healthcare organizations must implement administrative, physical, and technical safeguards to protect patient information. When a breach of unsecured PHI occurs, covered entities and business associates must conduct a risk assessment to determine whether notification is required. If there is a low probability that PHI has been compromised, notification may not be necessary; however, given the scale of this breach and the nature of network server access, notification was clearly warranted. Network server breaches represent a significant category of healthcare data breaches, accounting for a substantial portion of incidents affecting large numbers of patients. According to HHS breach notification data, hacking and IT incidents consistently rank among the most common causes of large-scale healthcare breaches. The involvement of business associates in this breach highlights the importance of vendor management and third-party risk assessment in healthcare cybersecurity. Organizations must ensure that business associates maintain equivalent security standards and promptly notify the covered entity of any breaches affecting patient information.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the CommonSpirit Health Breach
Place a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) by contacting one bureau, which will notify the others. This alerts creditors to verify your identity before opening new accounts in your name.
Consider placing a credit freeze with all three credit bureaus to prevent unauthorized access to your credit report and make it more difficult for criminals to open accounts using your information. You can place a freeze for free under federal law.
Monitor your credit reports regularly for suspicious activity. You are entitled to one free credit report annually from each bureau at annualcreditreport.com. Consider using credit monitoring services that alert you to changes in your credit profile.
Review your medical records and explanation of benefits (EOB) statements from CommonSpirit Health and your insurance provider for unauthorized services or charges. Contact your healthcare provider immediately if you identify suspicious activity.
Monitor your financial accounts, including bank accounts and credit card statements, for unauthorized transactions. Set up account alerts with your financial institutions to notify you of unusual activity.
Be cautious of unsolicited communications claiming to be from CommonSpirit Health, your insurance company, or financial institutions. Verify any requests for personal information by contacting the organization directly using a phone number from an official source.
Consider enrolling in identity theft protection services if offered by CommonSpirit Health as part of their breach response. Many organizations provide complimentary credit monitoring and identity theft protection for affected individuals.
Change passwords for any online healthcare portals, insurance accounts, or financial accounts, using strong, unique passwords that are not reused across multiple sites.
Document all communications related to the breach, including notification letters and any identity theft or fraud incidents that occur, for potential future claims or disputes.
Report any suspected identity theft or fraud to the Federal Trade Commission (FTC) at IdentityTheft.gov and file a police report if necessary to establish an official record for disputing fraudulent accounts.
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Illinois Breaches
Search all breaches reported in Illinois
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuits