Skip to main content
Breach Signal

Breach report

Healthcare

Ascension

Ascension: Health data of 5.6 million stolen in ransomware attack

A ransomware attack blamed on the Black Basta gang forced Ascension's 140 hospitals onto paper records for weeks and exposed medical, financial and identity data belonging to about 5.6 million people.

Reported by BleepingComputer

Records exposed

5.6M

About 5.6 million patients and employees

Scale vs. largest on file

When
2024
How they got in
Ransomware (Black Basta) after an employee downloaded a malicious file
Sector
Healthcare

On May 8, 2024, Ascension, one of the largest private health systems in the United States, detected a cyberattack that quickly knocked out critical systems across its network of roughly 140 hospitals. Electronic health records, patient portals, phone systems and tools used to order tests and medications went offline, and some facilities diverted ambulances. Clinicians reverted to paper charts and manual processes for about a month while the organization restored systems. Because Ascension operates in about 19 states and the District of Columbia, the outage affected hospitals from Michigan and Wisconsin to Texas and Florida.

Ascension later said the attack began when an employee downloaded a file they mistakenly believed to be legitimate, which it described as an honest mistake. Reporting by CNN and others linked the intrusion to the Black Basta ransomware group, though the gang did not publicly claim it. The attackers stole data from a limited number of file servers before deploying ransomware.

In December 2024, Ascension began notifying about 5.6 million people that their information was taken. Depending on the individual, the stolen files included medical record numbers, dates of service, lab test types, diagnoses and procedure codes, insurance details, payment information such as card or bank numbers, and government identifiers including Social Security, driver's license and passport numbers. The organization offered two years of free identity protection and monitoring.

The disruption drew concern from clinicians and patient safety advocates, with nurses reporting delays in lab results and medication errors during the outage. Ascension faced multiple class-action lawsuits over the data theft, and the attack contributed to financial losses at the Catholic nonprofit system in 2024. It came just months after the Change Healthcare attack, reinforcing warnings from federal officials that ransomware against hospitals had become a direct threat to patient care rather than just a data privacy issue.

The case highlights two lessons that repeat across healthcare. First, a single user's click can still cascade into a system-wide outage when networks are not segmented. Second, health systems hold a mix of medical, financial and identity data on both patients and staff, so one intrusion can create lasting fraud risk for millions of people who simply sought care.

More from the wire

More in Healthcare.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.