Skip to content

MultiCare Health System

Disclosed Jan 26, 20179 years ago1,249 affectedConfirmed

Official notice

MultiCare Health System, the covered entity (CE), reported that due to a phishing attack a hacker gained access to an employee’s email access credentials for approximately 3 days. The breach affected the protected health information (PHI) of 1,249 individuals and included names, dates of birth, dates of service, diagnoses, medical record numbers, and descriptions of treatment. The CE provided breach notification to HHS, affected individuals and the media. Following the breach, the CE updated its policies and procedures addressing phishing emails, implemented technical security safeguards to reduce the risk of malware infection and hacking, and retrained all employees on its updated policies and procedures. OCR provided the CE with comprehensive technical assistance regarding its obligations under the Security Rule to conduct a thorough security risk analysis and implement a corresponding risk management/mitigation plan. OCR also provided an explanation of the requirements of the Security Rule for the CE to use in future compliance efforts. OCR obtained documented assurances that the CE implemented the corrective actions listed above.

What is known

People affected1,249 (as reported to HHS)
DisclosedJan 26, 2017
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalJan 26, 20171,249

Other breaches at MultiCare Health System

BreachAffected
Disclosed Jul 25, 2022Jul 25, 20224 years agoRansomware24K
Disclosed Aug 21, 2020Aug 21, 20206 years agoRansomware179K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about MultiCare Health System

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.