Ascension, one of America’s largest private healthcare networks with 142 hospitals nationwide and over 142,000 employees, is alerting patients about a significant data breach that occurred in December 2024. The breach, which compromised personal and health information, stemmed from a vulnerability in third-party software used by a former business partner.
## Breach Details
According to notifications sent to affected individuals, Ascension discovered on December 5, 2024, that patient information may have been compromised. Their investigation, completed on January 21, 2025, revealed that Ascension had inadvertently shared information with a former business partner, from which data was subsequently stolen.
The exposed information includes:
– Personal data: names, addresses, phone numbers, email addresses, dates of birth, race, gender, and Social Security numbers
– Health information: physician names, admission and discharge dates, diagnosis codes, billing codes, medical record numbers, and insurance details
## Scope and Response
While Ascension has not publicly disclosed the total number of affected patients, a filing with Massachusetts’ Office of the Attorney General indicated that 96 Massachusetts residents had their medical records and Social Security numbers exposed.
The healthcare provider is offering affected individuals two years of free identity monitoring services, including credit monitoring, fraud consultation, and identity theft restoration.
The timing suggests this breach may be connected to a series of Clop ransomware attacks that exploited a zero-day vulnerability in Cleo secure file transfer software.
This incident follows a more extensive breach in May 2024, when a Black Basta ransomware attack compromised data of nearly 5.6 million Ascension patients and employees after an employee downloaded a malicious file.
