Rockwood Retirement Communities (Spokane United Methodist Homes) Data Breach Notice (Washington Attorney General): What Was Exposed & What To Do
Rockwood Retirement Communities (Spokane United Methodist Homes) disclosed on August 20, 2026, that a data breach exposing the personal information of 7,136 individuals occurred on or around February 15, 2026. If you believe you may have been affected, review the notice posted by the organization or the Washington Attorney General and take the recommended steps to protect your identity and accounts.
In February 2026, personal information belonging to thousands of people connected to Rockwood Retirement Communities was exposed in a cybersecurity incident. A notice filed with the Washington State Attorney General on August 20, 2026, states that 7,136 individuals were affected and that the data involved included names, Social Security numbers, driver’s license or Washington ID card numbers, financial and banking details, full dates of birth, passport numbers, health insurance policy or ID numbers, and medical information. For residents, former residents, family members, and staff whose records may have been involved, the practical stakes are concrete: the combination of identity documents, financial data, and health information can be used for identity theft, fraudulent accounts, or medical-related scams long after the initial event.
The disclosure itself is the public record of what the organization reported. It places the incident on February 15, 2026, and confirms the categories of data listed above. Beyond those points, public detail remains limited to what appears in the Attorney General filing.
Inside the incident
According to the notice reported to the Washington State Attorney General on August 20, 2026, Rockwood Retirement Communities (also identified as Spokane United Methodist Homes) experienced a data breach on February 15, 2026. The filing states that 7,136 people were affected. The notice lists the exposed information as name, Social Security number, driver’s license or Washington ID card number, financial and banking information, full date of birth, passport number, health insurance policy or ID number, and medical information.
The public filing does not describe the technical method of intrusion, the systems involved, how long unauthorized access lasted, or whether data was exfiltrated, encrypted, or otherwise manipulated. It also does not name any threat actor or provide a narrative of discovery and containment. Those elements are undisclosed in the available notice. What is established is the reported date of the incident, the number of people notified as affected, and the categories of personal data the organization stated were exposed.
How a breach like this happens
Incidents that expose resident or patient-related records at senior-living and healthcare-adjacent organizations typically begin with unauthorized access to systems that store administrative, billing, or clinical data. Common pathways in the broader sector include compromised credentials, phishing that leads to account takeover, exploitation of unpatched remote-access software, or malware that moves laterally once inside a network. Once access is obtained, attackers may copy databases, document stores, or backup files that contain identity and health information.
In many cases the organization only learns of the event weeks or months later—through unusual system behavior, a ransom note, or notification from a third party. Investigation then focuses on determining which records were touched and who must be notified under state law. None of these general patterns is confirmed as the cause of the Rockwood incident; they are background on how breaches of this type often unfold when detailed technical findings are not made public.
Who is Rockwood Retirement Communities (Spokane United Methodist Homes)?
Rockwood Retirement Communities, operating in connection with Spokane United Methodist Homes, is a senior-living organization based in the Spokane, Washington area. Organizations of this kind provide independent living, assisted living, memory care, or related residential and support services for older adults. They routinely maintain detailed files on residents and sometimes on family contacts and employees—files that can include government identifiers, payment and banking information, insurance coverage, and medical or care-related notes.
A breach at such an organization is consequential because the population it serves often holds long-term relationships with the provider and may have extensive medical and financial histories on file. The sensitivity of that data, combined with the age and life circumstances of many residents, raises the real-world impact of any confirmed exposure.
The information in question
The Washington Attorney General filing explicitly names the following categories as exposed: name, Social Security number, driver’s license or Washington ID card number, financial and banking information, full date of birth, passport number, health insurance policy or ID number, and medical information. These are the data types the organization reported; no further breakdown of which individuals received which combination of fields is provided in the public notice.
Organizations in the senior-living sector typically hold precisely these kinds of records in order to manage admissions, billing, insurance claims, and care. The filing confirms that these categories were among the information exposed in this incident. It does not, however, detail the volume of each data type per person or whether every affected individual had every field present.
Why it matters
When Social Security numbers, government ID numbers, passport data, dates of birth, and financial details appear together, the risk of identity theft and new-account fraud increases. Medical information and health-insurance identifiers can support medical identity theft or targeted phishing that impersonates insurers or providers. For older adults and their families, recovering from such misuse can be time-consuming and stressful, involving credit freezes, dispute processes, and ongoing monitoring.
For the organization, a breach of this scale triggers legal notification duties, potential regulatory scrutiny, and the operational cost of investigation and remediation. The filing establishes that thousands of people were placed in the notification population; the long-term consequences for those individuals depend on whether the exposed data is later misused—an outcome that cannot be predicted from the notice alone.
What to do if you're exposed
If you believe you may be among the 7,136 people affected, begin by reading any official notice you received from Rockwood Retirement Communities for the specific data elements tied to your record and any support the organization is offering. Place a fraud alert or credit freeze with the major credit bureaus, and monitor bank, credit-card, and insurance statements for unfamiliar activity. Consider requesting a free annual credit report and reviewing Explanation of Benefits statements from health insurers for services you did not receive. Keep records of any correspondence related to the incident.
You can also run a free exposure scan of your email address to check whether your information has already appeared in known breach datasets. That step does not replace official notices or credit monitoring, but it can help you understand whether the same email has surfaced elsewhere and decide what additional precautions to take.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Golden Opportunities And Local Support, LLC Data Breach Notice (Washington Attorney General)Aesto, LLC (Grant County Public Hospital District #2) Data Breach Notice (Washington Attorney General)The Moody Bible Institute of Chicago Data Breach Notice (Washington Attorney General)Wilmer Cutler Pickering Hale and Dorr LLP Data Breach Notice (Washington Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.