Healthcare provider · Hospital and healthcare services · Nonprofit health system · USA
Large nonprofit Catholic health system operating hospitals and clinics.
The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.
Ascension Healthcare patient data was compromised in the 2023 MOVEit Transfer software supply-chain attack carried out by the Cl0p ransomware group. The Cl0p group exploited a previously unknown zero-day vulnerability in Progress Software's MOVEit Transfer file-sharing platform around May 28-31, 2023, accessing data from hundreds of organizations worldwide that used MOVEit either directly or through vendors. The Ascension portion of the incident was indexed in late 2024 by breach-tracking services after disclosures continued to surface from various MOVEit-affected vendors handling Ascension patient data.\n\nThe breach affected approximately 261,000 Ascension patient records. Compromised fields included names, home addresses, phone numbers, Social Security numbers, and medical diagnosis information. Cl0p exploited the MOVEit zero-day to extract data from MOVEit Transfer servers operated by various organizations in the broader healthcare supply chain. Ascension itself was not the direct MOVEit operator; rather, patient data flowed through vendors that used MOVEit for secure file transfer.\n\nFor affected patients, the practical risk profile is severe and durable. The combination of name, address, Social Security number, and medical diagnosis is a strong base for synthetic identity fraud, fraudulent credit applications, and medical-themed scams that reference real diagnoses. Ascension patients should also note that they may have been affected by additional unrelated incidents at Ascension, including the May 2024 direct ransomware attack and the late 2024 Cleo-related vendor breach. Affected individuals should freeze credit at all three U.S. bureaus, monitor health-insurance and Medicare statements closely for unfamiliar charges, and treat unsolicited contact referencing Ascension, related hospitals, or insurance verification with caution. The combination of multiple back-to-back disclosures involving the same patient population makes Ascension patients an unusually attractive target for medical-fraud and identity-theft attempts.
Full threat analysis, exploitation vectors, and principal guidance below.
12 additional sections · verified field analysis · defensive doctrine
261K records analyzed
Ascension Healthcare, also known as Ascension Health, is one of the largest nonprofit Catholic health systems in the United States. Headquartered in St. Louis, Missouri, the organization operates approximately 142 hospitals across sixteen states and the District of Columbia, alongside a wide network of senior-living facilities, physician practices, and ambulatory care sites. Ascension employs more than 142,000 staff and reported total revenue of approximately \$28.3 billion in fiscal 2023. As a HIPAA-regulated health system at substantial scale, Ascension maintains comprehensive protected health information across hospital, ambulatory, and home-care operations, including patient identity, insurance, billing, diagnostic, treatment, and prescription records.
Large nonprofit health systems collect patient identity, contact, insurance, billing, scheduling, and clinical records across hospitals, clinics, and administrative systems.
The 2023 MOVEit-related disclosure was followed by two further major incidents at Ascension. In May 2024, Ascension was directly hit by a Black Basta ransomware attack that began when an employee downloaded a malicious file, ultimately affecting approximately 5.6 million patients and forcing extended outages of clinical systems across the network. The system reported a \$1.1 billion net loss for fiscal 2024 due in part to the attack. In April 2025, Ascension disclosed a separate incident at a former business partner involving the late-2024 Cl0p exploitation of Cleo file-transfer software, ultimately affecting approximately 437,000 additional patients. Multiple class-action lawsuits and a continuing federal Office for Civil Rights review remain active as of 2026.
Ascension faces substantial cumulative institutional exposure, with three major breach events disclosed between 2023 and 2025 affecting more than six million patients in total. Federal HIPAA notification obligations, an active Office for Civil Rights review, multistate attorney-general filings, and class-action litigation pipelines are all underway. The 2024 Black Basta attack imposed direct operational costs through extended clinical-system outages, contributing to the system's reported fiscal-year net loss of \$1.1 billion. Vendor-pathway and supply-chain risks have prompted ongoing review of Ascension's third-party governance functions. The reputational impact is national in scope given Ascension's scale and the public discussion of patient-care disruptions during the May 2024 outage.
• Identity theft and synthetic identity construction using government-issued IDs | • SIM swap attacks where phone numbers are present | • Doxxing risk from physical address exposure | • Medical identity fraud or insurance abuse using health data
A healthcare-linked breach: exposure ties a named individual to a provider relationship and, where clinical or insurance data is present, to conditions and treatment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.
Motivation: Financial extortion
A mature extortion group associated in public reporting with TA505 and FIN11-linked ecosystems. Cl0p is known for mass exploitation of managed file transfer products, including the 2023 MOVEit Transfer campaign exploiting CVE-2023-34362.
Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.
Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.
Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.
Request Consultation