Skip to content

PROVAIL

Disclosed Aug 8, 20251 year ago4,908 affectedConfirmed

Official notice

PROVAIL, the covered entity (CE), reported unauthorized access to its network containing the protected health information (PHI) of 4,908 individuals. The PHI involved included clinical, demographic, and financial information. The CE notified HHS and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services to the affected individuals, implemented additional administrative, technical, and security safeguards, and retrained workforce members to better protect its PHI.

What is known

People affected4,908 (as reported to HHS)
DisclosedAug 8, 2025
DiscoveredJun 8, 2025
HappenedJun 7, 2025
AttackRansomware
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
Washington Attorney General breach notice: PROVAILatg.wa.gov · Official notice
HHS OCR breach report (archive, resolved): PROVAIL (Healthcare Provider, WA)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalAug 8, 20254,908
Washington AGresidents of WAJan 164,391
History of this record
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 4908 · backfill source
  • 2026-09-25 · disclosed: 2026-01-16 to 2025-08-08 · backfill source
  • 2026-09-25 · summary: empty to PROVAIL, the covered entity (CE), reported unauthorized access to its network containing the protected health information (PHI) of 4,908 individuals. The PHI involved included clinical, demographic, and financial information. The CE notifie · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Washington AG), confirmed by Washington AG. Record counts are as reported. Not legal advice.

Everything about PROVAIL

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.