Ascension Healthcare, one of the largest nonprofit healthcare organizations in the US, is informing patients that their data was compromised in a cyberattack last year.
Ascension, a private Catholic healthcare system, is one of the largest of its kind with 142,000 employees, 142 hospitals, and 40 senior living facilities operating in 19 states and the District of Columbia as of 2021.
The organization is telling patients that hackers likely stole their medical and personal data in a 2024 cyberattack on one of Ascension’s business partners.
“On December 5, 2024, we learned that Ascension patient information may have been involved in a potential security incident,” the letter (PDF) informs patients. “We immediately initiated an investigation to determine whether and how a security incident occurred.”
“Our investigation determined on January 21, 2025, that Ascension inadvertently disclosed information to a former business partner, and some of this information was likely stolen from them due to a vulnerability in third-party software used by the former business partner,” the letter continues. “We have since reviewed our processes and are working to implement enhanced measures to prevent similar incidents from occurring in the future.”
Investigators determined that the breach involved both personal and health information, including:
- Name, address, phone number(s), email address, date of birth, race, gender, and Social Security numbers (SSN).
- Clinical information related to an inpatient visit, such as place of service, physician name, admission and discharge dates, diagnosis and billing codes, medical record number, and insurance company name.
Ascension notes that the exact type of information involved depends on the individual.
The healthcare organization offers affected customers two years of complimentary identity monitoring services, including credit monitoring, fraud consultation, and identity theft restoration.
“We encourage you to remain vigilant against incidents of identity theft and fraud, review your account statements, and monitor your credit reports for suspicious activity,” the nonprofit says.
As highlighted by The Register, this incident marks the second time in a year that Ascension is forced to respond to cybercriminal actions. In May 2024, ransomware actors claimed an attack on the healthcare system, prompting cybersecurity agencies to issue warnings to the public.
Most organizations are transparent and quick to inform customers about a data breach, but others may not react quickly or decisively. Bitdefender Digital Identity Protection lets you know if your data has been caught up in a breach, compromised, or leaked online, as well as what risks you face and how to protect yourself.
Data stolen in breaches fuels socially engineered scams and fraud. Whenever you see a suspicious text, phone call, or social media interaction, Bitdefender recommends using Scamio, our free, scam-fighting AI bot. You can share with Scamio the exact thing you want to check, such as a screenshot, link, or QR code – or simply describe the situation in your own words. Scamio lets you know in seconds if it’s a sham.
Consider using a security solution on all your personal devices for peace of mind.
You may also want to read:
US Clinical Lab Tells 1.6 Million Customers to 'Protect' Their Data Following Cyberattack
‘Termite’ Claims Attack on Australian IVF Clinic Genea
New Jersey Neurology Practice Fined $25,000 over Ransomware Incident
tags
Filip has 15 years of experience in technology journalism. In recent years, he has turned his focus to cybersecurity in his role as Information Security Analyst at Bitdefender.
View all postsApril 03, 2025
March 12, 2025
February 20, 2025
February 11, 2025