INSIGHTS

Mt. Spokane Pediatrics Breach Highlights Growing Need for Secure Managed IT Services in Spokane, Washington

Mt-spokane-ped-data-breach (1)

A ransomware attack affecting nearly 30,000 accounts at Mt. Spokane Pediatrics is drawing attention to a growing concern for Spokane businesses and health care organizations: cyberattacks are becoming easier to launch, harder to identify and increasingly amplified by artificial intelligence.

Mt. Spokane Pediatrics recently notified patients and other account holders that an unauthorized party accessed its network around January 1, 2026. The incident potentially exposed sensitive personal and medical information connected to approximately 29,410 accounts.

Information that may have been compromised included full names, Social Security numbers, health insurance information and medical information.

The clinic said it immediately worked to contain the incident and brought in outside cybersecurity professionals to investigate. By January 3, ransomware group LockBit 5.0 had claimed responsibility for the attack.

Forensic investigators later determined that files taken during the incident contained patient information. Mt. Spokane Pediatrics subsequently reported the breach to the Washington State Attorney General’s Office.

AI Is Changing the Cybersecurity Risk for Spokane Businesses

The Mt. Spokane Pediatrics incident comes as organizations face a rapidly changing cybersecurity environment.

Artificial intelligence is creating new opportunities for businesses, but the same technology is also giving cybercriminals tools that can make attacks faster and more convincing.

Attackers can use AI to help create realistic phishing emails, impersonate executives or employees, automate reconnaissance and analyze potential targets more efficiently. The technology can also make it easier to create highly personalized attacks using information collected from company websites, social media accounts and other public sources.

For businesses, this means traditional warning signs can become less reliable.

A phishing email may no longer contain obvious spelling mistakes or awkward language. A fraudulent message can closely imitate the writing style of a company executive. Voice and video cloning technologies can also make impersonation attempts more difficult for employees to recognize.

AI does not necessarily create entirely new forms of cybercrime. Instead, it can make many existing attacks easier to execute at a larger scale.

That creates particular concerns for industries such as health care, financial services and professional services, where organizations maintain large quantities of confidential customer or patient information.

Spokane IT Provider Warns Businesses About AI-Driven Threats

Josh Smith, owner of BCA, an information technology (IT) service provider in Spokane, said businesses need to account for the ways AI is changing cybersecurity threats.

“AI is allowing attackers to do things faster and with a level of sophistication we didn’t see a few years ago,” Smith said. “They can research a company, identify employees and create a very convincing phishing email in a matter of minutes. It doesn’t necessarily change what the attack is, but it can make that attack much harder for the average employee to recognize.”

Smith said one of the challenges for businesses is that attackers can increasingly use AI to make fraudulent communications appear legitimate.

“We used to tell people to look for bad grammar, strange wording or an email that just didn’t sound like the person sending it,” Smith said. “AI is taking a lot of those warning signs away. An attacker can make an email sound like your CEO, your accounting manager or one of your vendors. That means employees have to be much more cautious about what they click and especially about requests involving passwords, money or sensitive information.”

The increased availability of AI tools also means cyber threats are no longer limited to highly sophisticated attackers. Technology that can automate research, generate convincing messages and assist with technical tasks can lower the barrier to launching certain types of attacks.

For local businesses, Smith said cybersecurity strategies increasingly need to combine technology with employee education and clearly defined security procedures.

“There isn’t one product you can buy that suddenly makes your business secure,” Smith said. “Businesses need layers. Multifactor authentication, email protection, endpoint security, backups and monitoring are important, but employees also need to know what an attack looks like and what to do when something doesn’t seem right. With AI making scams more believable, having a process to independently verify unusual requests is becoming extremely important.”

Businesses may need to place greater emphasis on measures such as multifactor authentication, employee cybersecurity training, email security, network monitoring, data backups and procedures for independently verifying unusual financial or account requests.

Mt. Spokane Pediatrics Says No Fraud Has Been Reported

Mt. Spokane Pediatrics said it has not received any reports indicating that information compromised in the incident has been used for identity theft or other fraudulent activity.

People who may have been affected were notified through U.S. mail and provided with information about steps they could take to protect their personal information.

The clinic also offered complimentary credit monitoring to notified individuals whose Social Security numbers may have been involved.

“On or about January 1, 2026, Mt. Spokane Pediatrics experienced a data security incident, where an unauthorized party accessed certain systems in our network environment. Upon learning of this issue, we contained the threat and immediately commenced a prompt and thorough investigation,” Practice Administrator Daniel Oneill said.

Mt. Spokane Pediatrics said its investigation has concluded and it does not currently anticipate releasing additional updates.

“The privacy and security of the information provided to Mt. Spokane Pediatrics is of the utmost importance to us and we will continue to take significant measures to protect that information,” Oneill said.

Ransomware Remains a Major Washington Cybersecurity Concern

The attack is part of a larger cybersecurity problem affecting organizations throughout Washington.

The Washington Attorney General’s 2025 data breach report found that the number of people affected by reported breaches exceeded the state’s population for the second consecutive year.

Ransomware was the leading type of data exposure identified in the report, and three of Washington’s five largest reported breaches involved health care organizations.

As businesses adopt more AI-powered technology themselves, they are simultaneously facing attackers who have access to increasingly capable tools.

For Spokane organizations, incidents such as the Mt. Spokane Pediatrics breach demonstrate that cybersecurity is becoming more than an IT issue. Protecting company systems, employee accounts and sensitive customer information is increasingly a core business risk management responsibility.

Related Posts