Ascension
Disclosed Dec 19, 20241 year ago437,329 affectedConfirmed
Ascension patient data stolen from former business partner
Ascension said patient data it inadvertently disclosed to a former business partner was likely stolen in December 2024 through a flaw in third-party software; it reported 437,329 affected patients to HHS.
What is known
| People affected | 437,329 (as reported by the organization) |
|---|---|
| Disclosed | Dec 19, 2024 |
| Discovered | May 8, 2024 |
| Happened | Feb 29, 2024 |
| Attack | Vendor breach |
| Data exposed | Names, Government IDs, Health, Insurance, Credentials and tokens, Biometrics, Addresses, Phone numbers, Emails, Dates of birth, Social Security numbers |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Notice letter filed with the Delaware DOJ: Ascensionattorneygeneral.delaware.gov · Official notice | Official notice |
| Ascension discloses new data breach after third-party hacking incidentbleepingcomputer.com · News | News |
| Ascension says recent data breach affects over 430,000 patientsbleepingcomputer.com · News | News |
| April 2025 Healthcare Data Breach Reporthipaajournal.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Delaware DOJresidents of DE | Dec 19, 2024 | 606 |
| Researchtotal | Apr 29, 2025 | 437,329 |
Other breaches at Ascension
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Black Basta ransomware attack on Ascension exposes data of 5.6 million peopleMay 8, 20242 years agoRansomwareUnverified | May 8, 20242 years ago | Ransomware | Healthcare | Unverified | 5.6M |
History of this record
- 2026-09-25 · sector: other to health · seed source
- 2026-09-25 · attack: unknown to third-party · seed source
- 2026-09-25 · data_types: ["names","government-id","health","insurance","credentials","biometrics"] to ["names","government-id","health","insurance","credentials","biometrics","addresses","phone","emails","dob","ssn"] · seed source
- 2026-09-25 · records: 5599699 to 437329 · seed source
- 2026-09-25 · summary: empty to Ascension said patient data it inadvertently disclosed to a former business partner was likely stolen in December 2024 through a flaw in third-party software; it reported 437,329 affected patients to HHS. · seed source
- 2026-09-25 · title: empty to Ascension patient data stolen from former business partner · seed source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Delaware DOJ), confirmed by Delaware DOJ. Record counts are as reported. Not legal advice.