Massive Data Breach at Ascension Exposes 430,000+ Patient Records

Ascension, one of the largest private healthcare providers in the U.S., has confirmed a significant data breach affecting 437,329 patients, linked to a former business partner’s software vulnerability. This marks yet another serious blow to the healthcare sector’s cybersecurity posture, coming less than a year after Ascension's systems were crippled by ransomware.
- The breach originated from a December 2024 vulnerability in third-party software used by a former business partner.
- Ascension confirmed the incident impacted patient health records, billing codes, insurance info, and sensitive personal data including SSNs.
- Affected information includes:
- Patient names, dates of birth, race, gender
- Addresses, phone numbers, email addresses
- Medical record numbers, diagnosis details, admission/discharge dates
- Insurance provider details, Social Security numbers - The breach was discovered in January 2025, but notifications began rolling out in April.
- A total of 437,329 individuals are confirmed impacted in the latest HHS filing.
- Ascension is offering two years of free identity and credit monitoring services to those affected.
- The breach aligns with a pattern of Clop ransomware attacks that exploited zero-day vulnerabilities in Cleo secure file transfer software.
- This comes after a May 2024 Black Basta ransomware attack that disrupted hospital operations and exposed 5.6 million records.
The Ascension breach underscores the escalating risks tied to third-party vendors and legacy systems within healthcare. At Net Protector Cyber Security, we continue to stress the importance of zero-trust architectures, regular third-party risk assessments, and proactive vulnerability patching to protect patient data. As cybercriminals expand their tactics, so must our defenses.
Secure every link in your chain — because attackers only need one.
- Other (42)
- Ransomware (144)
- Events and News (27)
- Features (45)
- Security (468)
- Tips (79)
- Google (23)
- Achievements (11)
- Products (34)
- Activation (7)
- Dealers (1)
- Bank Phishing (44)
- Malware Alerts (215)
- Cyber Attack (263)
- Data Backup (11)
- Data Breach (99)
- Phishing (156)
- Securty Tips (1)
- Browser Hijack (18)
- Adware (15)
- Email And Password (69)
- Android Security (71)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (71)
- Hacking (57)
- Social Media (8)
- vulnerability (57)
- Hacker (31)
- Spyware (9)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (5)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (7)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (11)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (2)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (11)
- Impersonation phishing (1)
- DDoS (6)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)