Cyber Incident Victim: MicroCode Software Services Inc.
Timeline
Summary
MicroCode Software Services Inc., an IT vendor of CommonSpirit Health, disclosed a data breach linked to a ransomware attack on a database it hosted and supported for tracking medical malpractice insurance records. The breach was reported to the Washington Attorney General, identifying 4,096 Washington residents as affected. Investigators determined that unauthorized access had occurred over a period prior to discovery, and the company later found that names and dates of birth were compromised while Social Security numbers and financial data were not affected. The company engaged Kroll to operate a call center for impacted individuals and provided guidance on credit alerts and freezes. The notification letter listed the types of information involved, including names, dates of birth, addresses, government IDs, medical details, and financial information.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
MicroCode Software Services Inc., an IT vendor of CommonSpirit Health, disclosed a data breach linked to a ransomware attack. The company hosted and supported a database that CommonSpirit Health used to track medical malpractice insurance records. On April 14, 2026, MicroCode experienced a ransomware event involving the system hosting the CommonSpirit Health database. Forensic investigation found that unauthorized access occurred between January 19, 2026, and April 14, 2026. MicroCode determined on July 1, 2026, that personal information, including names and dates of birth, was compromised. The breach was disclosed to the Washington Attorney General on July 30, 2026, with 4,096 Washington residents identified as affected.

The notification letter indicated that affected information types include names, Social Security Numbers, dates of birth, addresses, government IDs, medical info, and financial info. Earlier in the article it was stated that Social Security numbers, financial data, and other sensitive information were not affected. MicroCode retained Kroll to manage a call center for affected individuals, providing the phone number 844-958-8933, available Monday through Friday from 8 AM to 5:30 PM CT. The notification letter also included resources for credit alerts and freezes.
The breach was linked to a ransomware attack on the system supporting the CommonSpirit Health medical malpractice insurance records database. No further details about the ransomware variant or attacker identity were provided in the source. The company’s actions focused on notification, call center support, and providing guidance on credit protections.
