Massive Data Breach at Ascension Exposes 430,000+ Patient Records

Ascension, one of the largest private healthcare providers in the U.S., has confirmed a significant data breach affecting 437,329 patients, linked to a former business partner’s software vulnerability. This marks yet another serious blow to the healthcare sector’s cybersecurity posture, coming less than a year after Ascension's systems were crippled by ransomware.
- The breach originated from a December 2024 vulnerability in third-party software used by a former business partner.
- Ascension confirmed the incident impacted patient health records, billing codes, insurance info, and sensitive personal data including SSNs.
- Affected information includes:
- Patient names, dates of birth, race, gender
- Addresses, phone numbers, email addresses
- Medical record numbers, diagnosis details, admission/discharge dates
- Insurance provider details, Social Security numbers - The breach was discovered in January 2025, but notifications began rolling out in April.
- A total of 437,329 individuals are confirmed impacted in the latest HHS filing.
- Ascension is offering two years of free identity and credit monitoring services to those affected.
- The breach aligns with a pattern of Clop ransomware attacks that exploited zero-day vulnerabilities in Cleo secure file transfer software.
- This comes after a May 2024 Black Basta ransomware attack that disrupted hospital operations and exposed 5.6 million records.
The Ascension breach underscores the escalating risks tied to third-party vendors and legacy systems within healthcare. At Net Protector Cyber Security, we continue to stress the importance of zero-trust architectures, regular third-party risk assessments, and proactive vulnerability patching to protect patient data. As cybercriminals expand their tactics, so must our defenses.
Secure every link in your chain — because attackers only need one.
- Other (43)
- Ransomware (153)
- Events and News (27)
- Features (45)
- Security (484)
- Tips (79)
- Google (28)
- Achievements (11)
- Products (35)
- Activation (7)
- Dealers (1)
- Bank Phishing (50)
- Malware Alerts (230)
- Cyber Attack (295)
- Data Backup (13)
- Data Breach (125)
- Phishing (164)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (70)
- Android Security (76)
- Knoweldgebase (38)
- Botnet (17)
- Updates (4)
- Alert (71)
- Hacking (70)
- Social Media (8)
- vulnerability (71)
- Hacker (38)
- Spyware (12)
- Windows (8)
- Microsoft (24)
- Uber (1)
- YouTube (1)
- Trojan (4)
- Website hacks (10)
- Paytm (1)
- Credit card scam (2)
- Telegram (3)
- RAT (8)
- Bug (3)
- Twitter (2)
- Facebook (8)
- Banking Trojan (9)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (2)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (5)
- Occasion (3)
- firewall (3)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (37)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)
- Fraud Protector (25)