{"id":14565,"date":"2026-05-09T17:44:05","date_gmt":"2026-05-09T17:44:05","guid":{"rendered":"https:\/\/russellandhill.com\/blog\/"},"modified":"2026-05-10T17:57:27","modified_gmt":"2026-05-10T17:57:27","slug":"mt-spokane-pediatrics-data-breach","status":"publish","type":"post","link":"https:\/\/russellandhill.com\/es\/blog\/mt-spokane-pediatrics-data-breach\/","title":{"rendered":"Mt. Spokane Pediatrics Data Breach: What the 29,410 Affected Patients Should Know"},"content":{"rendered":"<p>If you got a letter from Mt. Spokane Pediatrics dated around April 30, 2026, your name was on a list of 29,410 patients whose information was taken in a January ransomware attack. For many on that list, the affected patient is a child. The practical steps below matter more than the letter does \u2014 and most of them are free.<\/p>\n<h2>What happened<\/h2>\n<p>The Mt. Spokane Pediatrics data breach began on or around January 1, 2026, when an unauthorized party broke into the clinic&#8217;s network and removed files. The clinic says it caught the intrusion, contained it, and brought in outside forensic investigators. Two days later, a ransomware group operating under the LockBit 5.0 name claimed responsibility.<\/p>\n<p>The forensic investigation took most of the next four months. On April 22, 2026, investigators confirmed what was in the stolen files. The clinic began mailing notices to affected patients on April 30 and reported the breach to the Washington Attorney General.<\/p>\n<h2>What was in the files<\/h2>\n<p><strong>Per the clinic&#8217;s notice, the stolen files contained some combination of the following for each affected patient:<\/strong><\/p>\n<ul>\n<li>Full name and date of birth<\/li>\n<li>Social Security number<\/li>\n<li>Health insurance information and health plan beneficiary number<\/li>\n<li>Medical treatment and diagnostic information<\/li>\n<li>Medical record number or patient number<\/li>\n<li>Dates of service<\/li>\n<\/ul>\n<p>Not every notified person had every category exposed. Patients whose Social Security numbers were among the stolen data are being offered free credit monitoring through the clinic.<\/p>\n<p>The clinic says it has no evidence of fraud tied to the incident as of the notification date. That&#8217;s a snapshot, not a guarantee. Stolen healthcare records often surface on dark-web marketplaces months or years after the breach itself, which is why the practical response matters even if nothing has happened yet.<\/p>\n<h2>Why pediatric breaches are worse than most<\/h2>\n<p>A child&#8217;s Social Security number is, from a thief&#8217;s perspective, cleaner than an adult&#8217;s. Kids don&#8217;t check their credit. Most parents don&#8217;t either, on a child&#8217;s behalf. A stolen child SSN can sit unused for ten or fifteen years and surface as a fraudulent credit account, an apartment lease, or a tax return that has to be untangled before the child can buy a car or apply for student aid.<\/p>\n<p>That&#8217;s the practical reason this breach hits harder than a typical adult-data exposure of the same size. A meaningful share of the 29,410 affected here are minors, and the harm \u2014 if it materializes \u2014 won&#8217;t show up for years.<\/p>\n<h2>What to do this week<\/h2>\n<p>Freeze your child&#8217;s credit at all three bureaus. <a href=\"https:\/\/consumer.ftc.gov\/articles\/what-know-about-credit-freezes-and-fraud-alerts\" target=\"_blank\" rel=\"noopener\">Equifax, Experian, and TransUnion<\/a> will each let a parent place a security freeze on a minor&#8217;s file. It&#8217;s free. Do this even if you take no other step. A freeze blocks new accounts from being opened in the child&#8217;s name and is the single most effective protection against the long-tail risk of pediatric SSN theft.<\/p>\n<p>Enroll in the credit monitoring the clinic offered. It&#8217;s free for affected individuals. Use the activation code in your letter. The clinic&#8217;s response line is 1-833-289-5228 if you misplaced the code or have questions about your specific exposure.Pull a credit report on your child directly from each bureau. Children should not have a credit file at all. If a report comes back showing one exists, that&#8217;s a flag worth investigating. The <a href=\"https:\/\/www.idtheftcenter.org\/identity-theft-victim-assistance\/child-identity-theft\/\" target=\"_blank\" rel=\"noopener\">Identity Theft Resource Center<\/a> has step-by-step instructions for minor credit checks.<\/p>\n<p>Watch your insurance EOBs and tax filings. Medical identity theft shows up as treatment you didn&#8217;t receive billed to your plan. Tax-related identity theft shows up as a rejected return because someone filed first using the affected SSN. Both can trace back to a healthcare breach.<\/p>\n<p>Save the notice letter. It&#8217;s your proof you were among the affected and it&#8217;s what triggers your standing if anything later requires legal action.<\/p>\n<h2>The Washington context<\/h2>\n<p>The Washington Attorney General&#8217;s 2025 data breach report flagged a pattern that put Mt. Spokane Pediatrics squarely inside the trend before its own breach happened. Breach notifications in the state exceeded Washington&#8217;s population for the second year running. Ransomware was the leading attack type. Three of the top five breaches involved healthcare entities.<\/p>\n<p>Washington&#8217;s data breach notification law, RCW 19.255, requires entities holding personal information to notify affected residents and the attorney general when more than 500 Washingtonians are involved. Mt. Spokane Pediatrics appears to have followed the notice requirement on its face. Whether the underlying security practices met the legal standard of reasonableness is a separate question, and one that often gets sorted out only after litigation forces the question.<\/p>\n<h2>What kind of legal exposure these breaches create<\/h2>\n<p>Affected patients sometimes have claims under several Washington and federal theories. <a href=\"https:\/\/app.leg.wa.gov\/rcw\/default.aspx?cite=19.86\" target=\"_blank\" rel=\"noopener\">The Washington Consumer Protection Act (RCW 19.86)<\/a> reaches unfair or deceptive practices, and inadequate data security has been litigated under that statute. Common-law negligence applies where a covered entity failed to maintain reasonable safeguards. HIPAA itself doesn&#8217;t create a private right of action, but its standards are often used as evidence of the duty of care in state-law claims.<\/p>\n<p>Class actions in healthcare data breach cases have become routine over the past several years. They typically resolve with settlements that include extended credit monitoring, identity-restoration services, and cash payments tied to documented out-of-pocket losses. Recoveries vary widely depending on the size of the breach, the sensitivity of the data, and whether plaintiffs can show actual misuse.<\/p>\n<p>Damages generally fall into two categories. Actual out-of-pocket losses cover things like fraudulent charges, the time cost of restoring identity, and any monitoring you have to pay for beyond what the breached entity provided. Statutory or contract-based recovery is available where state law allows.<\/p>\n<h2>When it&#8217;s worth talking to a lawyer<\/h2>\n<p>You don&#8217;t need an attorney to freeze a credit file or sign up for monitoring. Do those things first regardless.<br \/>\n<strong>A short consultation makes sense if any of these apply:<\/strong><\/p>\n<ul>\n<li>You&#8217;ve already noticed unauthorized accounts, charges, tax filings, or medical claims tied to an affected SSN<\/li>\n<li>A child&#8217;s information was exposed and you want to understand long-term protections beyond the standard monitoring window<\/li>\n<li>You want to know whether a class action has been filed, whether you&#8217;d be in the class, and how class settlements affect your individual rights<\/li>\n<li>You&#8217;ve spent meaningful time or money responding to the breach already<\/li>\n<\/ul>\n<p>Most consumer-protection and data-breach cases are handled on contingency, meaning no fee unless there&#8217;s a recovery. A first call costs nothing.<\/p>\n<p>If you want a Washington firm to talk it through, Russell &amp; Hill takes consultations from anyone affected by the Mt. Spokane Pediatrics breach. Call us, or use the<a href=\"https:\/\/russellandhill.com\/es\/contact\/\"> formulario de contacto<\/a> on this page, and we&#8217;ll walk through your specific situation.<\/p>","protected":false},"excerpt":{"rendered":"<p>If you got a letter from Mt. Spokane Pediatrics dated around April 30, 2026, your name was on a list of 29,410 patients whose information was taken in a January ransomware attack. For many on that list, the affected patient is a child. The practical steps below matter more than the letter does \u2014 and<\/p>","protected":false},"author":16,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[296],"tags":[],"class_list":["post-14565","post","type-post","status-publish","format-standard","hentry","category-class-actions"],"acf":[],"_links":{"self":[{"href":"https:\/\/russellandhill.com\/es\/wp-json\/wp\/v2\/posts\/14565","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/russellandhill.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/russellandhill.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/russellandhill.com\/es\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/russellandhill.com\/es\/wp-json\/wp\/v2\/comments?post=14565"}],"version-history":[{"count":2,"href":"https:\/\/russellandhill.com\/es\/wp-json\/wp\/v2\/posts\/14565\/revisions"}],"predecessor-version":[{"id":14568,"href":"https:\/\/russellandhill.com\/es\/wp-json\/wp\/v2\/posts\/14565\/revisions\/14568"}],"wp:attachment":[{"href":"https:\/\/russellandhill.com\/es\/wp-json\/wp\/v2\/media?parent=14565"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/russellandhill.com\/es\/wp-json\/wp\/v2\/categories?post=14565"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/russellandhill.com\/es\/wp-json\/wp\/v2\/tags?post=14565"}],"curies":[{"name":"gracias","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}