← Blog

Ascension Health Data Breaches: Full Timeline Through 2026

Share on X

People search Ascension Health data breach timeline because regulated data and trust are existential—one incident triggers class actions and regulator exams. BreachHistory indexes 2 Ascension Health-linked incidents, with headline counts up to 5.6M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why Ascension Health breach history matters

Ascension Health operates in Healthcare (United States). Across indexed rows, recurring themes include ransomware and extortion, third-party and supply-chain exposure, zero-day exploitation and malware. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2024 — 437K patients via former partner Cleo file-transfer zero-day

Cataloged incident. Ascension disclosed that patient information was likely stolen from a former business partner after Ascension inadvertently shared data with that partner, whose systems were hit via a vulnerability in third-party Cleo secure file transfer software tied to widespread Clop data-theft attacks. Ascension learned of the incident on December 5, 2024; investigation concluded January 21, 2025 that partner-held Ascension data was likely exfiltrated. HHS OCR filing published in May 2025 listed 437,329 affected individuals—di Exposed categories include PHI (inpatient visits, diagnoses, billing codes, MRNs), plus names, addresses, phones, emails, DOB, race, gender, SSNs. BreachHistory cites approximately 437K+ affected records in this row. See the ascension-third-party-cleo2024 and canonical BreachHistory entry.

2024 — Black Basta ransomware; 5.6M patients and employees

Cataloged incident. Ascension, one of the largest U.S. Catholic healthcare systems, suffered a May 2024 Black Basta ransomware attack that disrupted electronic health records nationwide—forcing paper charting, pausing elective procedures, and redirecting ambulances from affected facilities. The organization later notified almost 5.6 million patients and employees that personal, financial, insurance, and health information was stolen. This incident is separate from Ascension’s December 2024 third-party Cleo partner breach affecting 437 Exposed categories include Personal, financial, insurance, and health information for patients and employees. BreachHistory cites approximately 5.6M+ affected records in this row. See the ascension-black-basta2024 and canonical BreachHistory entry.

Patterns and analysis

  • Ransomware and extortion — appears across multiple Ascension Health catalog entries; prioritize controls that address this class of failure.
  • Third-party and supply-chain exposure — appears across multiple Ascension Health catalog entries; prioritize controls that address this class of failure.
  • Zero-day exploitation and malware — appears across multiple Ascension Health catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Watch for medical-ID theft and billing fraud after health-data incidents.
  5. Step 5: Bookmark the Ascension Health company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/ascension · Latest: ascension-third-party-cleo2024.

Sources: BreachHistory catalog (2 rows for Ascension Health), company and regulator disclosures cited in individual breach records.