2026 Ascent Asheville SNFs — vendor credential breach Nov 25–28 2025; ~3,993 residents (OCR)
Data compromised
Resident names, DOB, addresses, email, driver’s license, SSN, patient account numbers, diagnosis and care-related health information (elements varied)
Technical writeup
Verified facility/HHS notices covered by DataBreaches.net August 24, 2026. Three Ascent Healthcare Management–affiliated Asheville, NC skilled nursing operators — Bear Mountain Health and Rehabilitation, Elevate Health & Rehabilitation, and Swannanoa Valley Health and Rehabilitation — notified residents that a threat actor logged into systems between November 25 and 28, 2025 and acquired files held by a trusted vendor. Massachusetts AG materials add that the vendor was compromised using credentials stolen from another trusted vendor. HHS OCR tallies cited: Bear Mountain 1,397; Elevate 1,551; Swannanoa 1,045 (sum 3,993). Notices claim “credible evidence” stolen files were permanently deleted and not published — DataBreaches.net questions that assurance. Facility-specific census sum used for recordsAffected; companyConfirmed true for the notifications.
Root cause
Threat actor used stolen credentials of a trusted vendor (and allegedly a second vendor) to access resident files Nov 25–28, 2025; facility notices Jul 31, 2026
References
- https://databreaches.net/2026/08/24/ascent-skilled-nursing-facilities-assure-breach-victims-of-credible-evidence-stolen-data-was-deleted/
- https://bearmountainnhr.com/wp-content/uploads/2026/07/Bear-Mountain-Notice-of-Data-Incident.pdf
- https://www.mass.gov/doc/2026-1326-asheville-victoria-nc-opco-llc-dba-elevate-health-rehabilitation/download