Spokane United Methodist Homes, doing business as Rockwood Retirement Communities, has notified residents that a data security incident may have exposed their personal and protected health information. Senior living communities that hold this kind of sensitive data have a responsibility to protect it from unauthorized access.
Rockwood Retirement Communities’s Data Breach Investigation
Rockwood Retirement Communities, a Washington-based senior living company operated by Spokane United Methodist Homes, became aware of suspicious activity within its network on or around February 16, 2026. Following the discovery, Rockwood engaged forensic experts to investigate the scope and nature of the incident. That investigation determined that an unauthorized party may have acquired certain files stored on Rockwood’s network without authorization.
After completing a detailed review of the information contained in the affected files, Rockwood determined on July 27, 2026 that the exposed data varied by individual and may have included names, Social Security numbers, dates of birth, driver’s license or state identification numbers, passport numbers, financial account information, Medicaid or Medicare numbers, medical information, and health insurance information. Rockwood began notifying potentially affected individuals on August 20, 2026, the same day it posted a notice describing the incident to its website, and the breach was also reported to the Massachusetts Office of Consumer Affairs and Business Regulation on August 25, 2026.
Rockwood is committed to maintaining the trust of the residents and families it serves, and it has stated that the privacy and security of the information in its possession is a top priority. Nonetheless, the roughly five-month gap between the initial detection of suspicious activity in February and the company’s determination in late July of exactly what information had been exposed reflects the kind of prolonged forensic review that has become increasingly common with larger-scale network intrusions, even as it leaves affected individuals without clear information about their own exposure for an extended period.
Because Rockwood operates senior living communities, many of the individuals whose information may have been exposed are older adults who can be especially vulnerable to identity theft schemes, Medicare and Medicaid fraud, and other forms of exploitation that specifically target seniors. The combination of Social Security numbers, government-issued identification numbers, financial account details, and health insurance information named in Rockwood’s notice represents a particularly sensitive set of data, since it could allow a bad actor to open new financial accounts, file fraudulent insurance claims, or attempt to access existing accounts in a victim’s name.
Rockwood has offered complimentary single-bureau credit monitoring and identity theft protection services for 24 months to affected individuals through a partnership with Cyberscout, a TransUnion company, as well as proactive fraud assistance for anyone who has questions or believes they have become a victim of fraud connected to the incident. The company has stated it deeply regrets any worry or inconvenience the incident may have caused.
Attorneys are now investigating whether Rockwood Retirement Communities and Spokane United Methodist Homes maintained data security measures reasonably designed to protect the sensitive personal and medical information of the residents in their care, and whether the company’s response, including the roughly six-month period between detection and individual notification, satisfied its legal obligations under applicable state and federal breach notification laws.
Senior living operators like Rockwood are entrusted not only with residents’ day-to-day care but with a wide range of sensitive records built up over years of residency, including financial account details used for billing, government identification used for admission and benefits eligibility, and detailed medical histories. A breach affecting this combination of records can have consequences that extend well beyond a typical retailer or workplace data breach, since it touches nearly every aspect of a resident’s financial and medical identity at once.
When Did This Breach Occur?
Rockwood Retirement Communities became aware of suspicious activity in its network on or around February 16, 2026. Following an investigation with the assistance of forensic experts, the company determined on July 27, 2026 that certain files containing personal and health information had been acquired without authorization. Rockwood began sending notification letters to affected individuals and posted a notice to its website on August 20, 2026, and reported the incident to the Massachusetts Attorney General’s office on August 25, 2026.
What Information Was Breached?
According to Rockwood’s notice, the information exposed varied by individual and may have included names, Social Security numbers, dates of birth, driver’s license or state identification numbers, passport numbers, financial account information, Medicaid or Medicare numbers, medical information, and health insurance information.
What You Can Do
Rockwood Retirement Communities is offering affected individuals a complimentary 24-month membership in single-bureau credit monitoring and identity theft protection services through Cyberscout, a TransUnion company. To enroll, eligible individuals should visit the enrollment website listed in their notification letter and provide the unique activation code included. You should also consider placing a security freeze or fraud alert on your credit file with each of the three major credit bureaus, Equifax, Experian, and TransUnion, and regularly review your financial statements, Medicare or Medicaid statements, and explanation-of-benefits notices for anything unfamiliar. If you notice suspicious activity, report it to your financial institution, local law enforcement, and your state Attorney General’s office right away.
File a Data Breach Lawsuit Against Rockwood Retirement Communities
If you received a notice that your information was exposed in the Rockwood Retirement Communities data breach, you may have legal options. A class action lawsuit could hold Rockwood Retirement Communities and Spokane United Methodist Homes accountable for failing to adequately protect the sensitive information entrusted to them, and could result in compensation for those affected.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.