Ascension, one of many largest non-public healthcare programs in america, has revealed that the private and healthcare data of over 430,000 sufferers was uncovered in an information breach disclosed final month.
As Ascension revealed in breach notification letters despatched to affected people in April, their data was stolen in an information theft assault that impacted a former enterprise associate in December.
Relying on the impacted affected person, the attackers might entry private well being data associated to inpatient visits, together with the doctor’s identify, admission and discharge dates, analysis and billing codes, medical document quantity, and insurance coverage firm identify. They might additionally achieve entry to non-public data, together with identify, deal with, cellphone quantity(s), e mail deal with, date of delivery, race, gender, and Social Safety numbers (SSNs).
“On December 5, 2024, we discovered that Ascension affected person data might have been concerned in a possible safety incident. We instantly initiated an investigation to find out whether or not and the way a safety incident occurred,” Ascension stated.
“Our investigation decided on January 21, 2025, that Ascension inadvertently disclosed data to a former enterprise associate, and a few of this data was doubtless stolen from them as a consequence of a vulnerability in third-party software program utilized by the previous enterprise associate.”
Whereas Ascension did not reveal the overall variety of affected people on the time, an April 29 submitting stated that the incident impacted 114,692 people in Texas, and the corporate additionally informed Massachusetts’ Workplace of the Lawyer Common that 96 residents had their medical information and SSNs uncovered within the incident.
Nonetheless, the healthcare large additionally disclosed in an April 28 submitting with the U.S. Division of Well being & Human Providers (HHS) that wasn’t revealed till at the moment that the information breach affected 437,329 people.

Ascension gives two years of free id monitoring providers to these impacted by this incident, together with credit score monitoring, fraud session, and id theft restoration.
Though Ascension did not share any particulars relating to the breach affecting its former enterprise associate, the timeline of the breach implies that the assault was a part of widespread Clop ransomware information theft assaults that exploited a zero-day flaw in Cleo safe file switch software program.
Final 12 months, Ascension notified nearly 5.6 million sufferers and workers that their private, monetary, insurance coverage, and well being data had been stolen in a Could 2024 Black Basta ransomware assault.
After the incident, the healthcare group revealed that the ransomware breach resulted from an worker downloading a malicious file onto an organization system.
Following the Could 2024 assault, workers had been pressured to maintain observe of procedures and medicines on paper, as sufferers’ digital information could not be accessed. Ascension additionally needed to pause some non-emergent elective procedures, checks, and appointments and redirect emergency medical providers to unaffected healthcare items to stop triage delays.
Ascension has over 142,000 workers, operates 142 hospitals and 40 senior care amenities acoss North America, and reported revenues of $28.3 billion in 2023.