Ascension, one of the largest private healthcare systems in the United States, is notifying patients that their personal and health information was stolen in a December 2024 data theft attack, which affected a former business partner. The health network operates 142 hospitals nationwide, has over 142,000 employees, and has reported a total revenue of $28.3 billion in 2023. "On December 5, 2024, we learned that Ascension patient information may have been involved in a potential security incident. We immediately initiated an investigation to determine whether and how a security incident occurred," Ascension says in data breach notifications sent to affected individuals. "Our investigation determined on January 21, 2025, that Ascension inadvertently disclosed information to a former business partner, and some of this information was likely stolen from them due to a vulnerability in third-party software used by the former business partner." Depending on the impacted patient, the attackers gained access to a combination of personal information, including name, address, phone number(s), email address, date of birth, race, gender, and Social Security numbers (SSNs). They could also access personal health information related to inpatient visits, including the physician's name, admission and discharge dates, diagnosis and billing codes, medical record number, and insurance company name. Even though the breach notifications didn't include any information regarding the total number of...
Ascension discloses new data breach after third-party hacking incident
BleepingComputer
·Sergiu Gatlan
·Published Apr 30, 2025
·Updated
Affected Software
1 affected component
Cleo Secure File Transfer
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a data breach disclosed by Ascension involving stolen personal and health information due to a security incident linked to a former business partner.
2
What security implications are discussed in the article?
The article highlights the risks posed to patient privacy and data security stemming from third-party vendor vulnerabilities.
3
What products or software are affected by this data breach?
The breach involves the Cleo Secure File Transfer software, which was used by the affected former business partner.
4
Who is Ascension and how does this breach impact them?
Ascension is one of the largest private healthcare systems in the U.S., and the breach can damage their reputation and erode patient trust.
5
When did the data breach incident occur?
The data theft attack occurred in December 2024.