[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1mmymmaftpegl":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":39,"seoTitle":40,"seoTitleEn":41,"seoDescription":40,"seoDescriptionEn":42,"logoUrl":43,"isVerified":4,"isSensitive":4,"isSpamList":44,"isMalware":44,"company":45},"6a706706d5dd2ff3e909ebbf","AscensionFormerBusinessPartner2024","Ascension 2024 Data Breach","ascension-former-business-partner-2024","ascension.org","2024-12-05T00:00:00.000Z","2026-08-03T10:01:41.446Z","2026-08-03T10:06:33.779Z","HHS OCR and Ascension regulatory notice","https:\u002F\u002Fwww.mass.gov\u002Fdoc\u002F2025-738-ascension-health\u002Fdownload",[15,17,18],"https:\u002F\u002Focrportal.hhs.gov\u002Focr\u002Fbreach\u002Fbreach_report.jsf","https:\u002F\u002Fwww.hipaajournal.com\u002Fascension-data-breach-former-business-partner\u002F",437329,"known",null,"people","High",[25,26,27,28,29,30,31,32,33,34,35,36,37,38],"Names","Physical addresses","Phone numbers","Email addresses","Dates of birth","Ethnicities","Genders","Social security numbers","Medical record numbers","Provider names","Diagnoses","Treatment information","Health insurance information","Medical information","\u003Cp>\u003Cstrong>The 2024 Ascension former-business-partner data breach\u003C\u002Fstrong> was a separate incident in which Ascension patient information may have been obtained through a vulnerability in third-party software used by a former business partner. Ascension learned of the incident on December 5, 2024.\u003C\u002Fp>\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights records the event as a Hacking\u002FIT Incident affecting 437,329 people. It should not be confused with the May 2024 ransomware attack that affected Ascension's own systems and involved millions of people.\u003C\u002Fp>\u003Ch2>How was the Ascension incident confirmed?\u003C\u002Fh2>\u003Cp>Ascension's regulatory notice says patient information was inadvertently disclosed to a former business partner and was likely stolen because of a vulnerability in third-party software used by that partner. The investigation reached this conclusion on January 21, 2025.\u003C\u002Fp>\u003Cp>The HHS OCR entry connects Ascension Health, the total of 437,329 people, and the April 28, 2025 report date in one event. Independent healthcare-security reporting corroborates the timeline, affected fields, and the fact that Ascension's own systems were not affected.\u003C\u002Fp>\u003Ch2>How did the incident happen?\u003C\u002Fh2>\u003Cp>Ascension determined that it had inadvertently disclosed certain patient information to the former business partner. An unauthorized person exploited a vulnerability in third-party software used by the partner and likely obtained the data.\u003C\u002Fp>\u003Cp>The public notice does not identify the former partner, name the vulnerable product, state when unauthorized access began, or identify the responsible actor. Ascension specifically says its own network and systems were not breached in this incident.\u003C\u002Fp>\u003Ch2>What information may have been involved?\u003C\u002Fh2>\u003Cp>Depending on the person, the information may have included names, addresses, phone numbers, email addresses, dates of birth, race, gender, and Social Security numbers. The disclosed categories did not necessarily apply to every affected person.\u003C\u002Fp>\u003Cp>Clinical fields may have included places of service, physician names, admission and discharge dates, diagnosis and billing codes, medical record numbers, and insurance company names. Passwords, payment cards, and bank-account information are not included because the official notice does not identify them.\u003C\u002Fp>\u003Ch2>What risks do these data types create?\u003C\u002Fh2>\u003Cp>A Social Security number combined with contact and birth information can increase the risk of identity theft, fraudulent account applications, and targeted scams. Because many of these details do not change, monitoring may be appropriate over a longer period.\u003C\u002Fp>\u003Cp>Someone who knows a real hospital visit, physician, diagnosis, or insurance detail may create a convincing message claiming to represent Ascension, a clinic, or an insurer. Accurate medical details do not prove that the sender is authorized.\u003C\u002Fp>\u003Ch2>How did Ascension respond?\u003C\u002Fh2>\u003Cp>After learning of the incident, Ascension opened an investigation, reviewed its information-sharing processes, and said it was working to implement additional safeguards. Written notices were sent to affected individuals.\u003C\u002Fp>\u003Cp>The organization offered eligible recipients two years of credit monitoring, fraud consultation, and identity-theft restoration services. The public notice does not say that misuse tied to the incident was definitively identified.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients should regularly review credit reports, new-account inquiries, health-insurance explanations, and medical bills for services or activity they do not recognize. Suspicious records should be reported promptly to the relevant organizations.\u003C\u002Fp>\u003Cp>Do not provide a Social Security number, password, payment detail, or verification code in response to an unexpected message claiming to come from Ascension, a physician, or an insurer. Verify the request through an official channel located independently rather than a link or number in the message.\u003C\u002Fp>","","Ascension 2024 Partner Data Breach (437.3 Thousand People Affected)","The Ascension former-business-partner data breach may have exposed identity and health information belonging to 437,329 people.","\u002Fuploads\u002Flogo\u002Fascension-official.svg",false,{"name":46,"sector":47,"country":48,"website":49,"websiteArchiveUrl":40,"websiteStatus":40,"websiteCheckedAt":21},"Ascension Health","Healthcare","United States","https:\u002F\u002Fwww.ascension.org\u002F"]