Ascension Healthcare 2023 Data Breach

Ascension Health Nonprofit Hospital System Breach (2023): Patient Medical Diagnoses & SSN Exposed

Healthcare provider · Hospital and healthcare services · Nonprofit health system · USA

Ascension Health Nonprofit Hospital System Breach (2023): Patient Medical Diagnoses & SSN Exposed

Large nonprofit Catholic health system operating hospitals and clinics.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
75/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
261KRecords
2023Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
PHI / MedicalMedical Diagnosis
AddressPhysical address
Classification Tags
Cl0p / CL0PRansomware / ExtortionHealthcareMedicalPatients2023

Breach Summary

Ascension Healthcare patient data was compromised in the 2023 MOVEit Transfer software supply-chain attack carried out by the Cl0p ransomware group. The Cl0p group exploited a previously unknown zero-day vulnerability in Progress Software's MOVEit Transfer file-sharing platform around May 28-31, 2023, accessing data from hundreds of organizations worldwide that used MOVEit either directly or through vendors. The Ascension portion of the incident was indexed in late 2024 by breach-tracking services after disclosures continued to surface from various MOVEit-affected vendors handling Ascension patient data.\n\nThe breach affected approximately 261,000 Ascension patient records. Compromised fields included names, home addresses, phone numbers, Social Security numbers, and medical diagnosis information. Cl0p exploited the MOVEit zero-day to extract data from MOVEit Transfer servers operated by various organizations in the broader healthcare supply chain. Ascension itself was not the direct MOVEit operator; rather, patient data flowed through vendors that used MOVEit for secure file transfer.\n\nFor affected patients, the practical risk profile is severe and durable. The combination of name, address, Social Security number, and medical diagnosis is a strong base for synthetic identity fraud, fraudulent credit applications, and medical-themed scams that reference real diagnoses. Ascension patients should also note that they may have been affected by additional unrelated incidents at Ascension, including the May 2024 direct ransomware attack and the late 2024 Cleo-related vendor breach. Affected individuals should freeze credit at all three U.S. bureaus, monitor health-insurance and Medicare statements closely for unfamiliar charges, and treat unsolicited contact referencing Ascension, related hospitals, or insurance verification with caution. The combination of multiple back-to-back disclosures involving the same patient population makes Ascension patients an unusually attractive target for medical-fraud and identity-theft attempts.

Full threat analysis, exploitation vectors, and principal guidance below.

12 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

261K records analyzed

About Ascension Healthcare

Ascension Healthcare, also known as Ascension Health, is one of the largest nonprofit Catholic health systems in the United States. Headquartered in St. Louis, Missouri, the organization operates approximately 142 hospitals across sixteen states and the District of Columbia, alongside a wide network of senior-living facilities, physician practices, and ambulatory care sites. Ascension employs more than 142,000 staff and reported total revenue of approximately \$28.3 billion in fiscal 2023. As a HIPAA-regulated health system at substantial scale, Ascension maintains comprehensive protected health information across hospital, ambulatory, and home-care operations, including patient identity, insurance, billing, diagnostic, treatment, and prescription records.

Why They Hold Your Data

Large nonprofit health systems collect patient identity, contact, insurance, billing, scheduling, and clinical records across hospitals, clinics, and administrative systems.

Recent Developments

The 2023 MOVEit-related disclosure was followed by two further major incidents at Ascension. In May 2024, Ascension was directly hit by a Black Basta ransomware attack that began when an employee downloaded a malicious file, ultimately affecting approximately 5.6 million patients and forcing extended outages of clinical systems across the network. The system reported a \$1.1 billion net loss for fiscal 2024 due in part to the attack. In April 2025, Ascension disclosed a separate incident at a former business partner involving the late-2024 Cl0p exploitation of Cleo file-transfer software, ultimately affecting approximately 437,000 additional patients. Multiple class-action lawsuits and a continuing federal Office for Civil Rights review remain active as of 2026.

Data Points Exposed

5 verified field types
Full Name
Medical Diagnosis Critical
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

Ascension faces substantial cumulative institutional exposure, with three major breach events disclosed between 2023 and 2025 affecting more than six million patients in total. Federal HIPAA notification obligations, an active Office for Civil Rights review, multistate attorney-general filings, and class-action litigation pipelines are all underway. The 2024 Black Basta attack imposed direct operational costs through extended clinical-system outages, contributing to the system's reported fiscal-year net loss of \$1.1 billion. Vendor-pathway and supply-chain risks have prompted ongoing review of Ascension's third-party governance functions. The reputational impact is national in scope given Ascension's scale and the public discussion of patient-care disruptions during the May 2024 outage.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using government-issued IDs | • SIM swap attacks where phone numbers are present | • Doxxing risk from physical address exposure | • Medical identity fraud or insurance abuse using health data

Principal Risk Advisory

What this means for a principal

A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Watch for medical-benefit fraud and health-themed phishing that references real provider relationships.
  4. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  5. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
C/
Threat Actor: Cl0p / CL0PConfidence: High
Ransomware and mass exploitation group

Motivation: Financial extortion
A mature extortion group associated in public reporting with TA505 and FIN11-linked ecosystems. Cl0p is known for mass exploitation of managed file transfer products, including the 2023 MOVEit Transfer campaign exploiting CVE-2023-34362.

Read the full threat-actor profile →
This breach is linked to the MOVEit / Cl0p (2023) campaign (2023 related breaches tracked by ObscureIQ). See the full campaign analysis →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation