← Ascension Health

2024 Ascension — 437K patients via former partner Cleo file-transfer zero-day

2024 437.3K records affected Share on X

Data compromised

PHI (inpatient visits, diagnoses, billing codes, MRNs), plus names, addresses, phones, emails, DOB, race, gender, SSNs

Technical writeup

Ascension disclosed that patient information was likely stolen from a former business partner after Ascension inadvertently shared data with that partner, whose systems were hit via a vulnerability in third-party Cleo secure file transfer software tied to widespread Clop data-theft attacks. Ascension learned of the incident on December 5, 2024; investigation concluded January 21, 2025 that partner-held Ascension data was likely exfiltrated. HHS OCR filing published in May 2025 listed 437,329 affected individuals—distinct from Ascension’s separate May 2024 Black Basta ransomware incident affecting roughly 5.6 million patients and employees.

Root cause

Data theft at former business partner exploiting Cleo secure file transfer zero-day (Clop campaign)

References