Data breach
Ascension Healthcare
- Records
- 260,792
- Breach date
- 31 May 2023Estimated
- Added
- 4 December 2024
What was exposed
9 types of data · 1 puts you at serious risk
- Doctors' names1
- Names1
- Home addresses1
- Insurance providers1
- Employment1
- Employers1
- Medical diagnoses1
- Phone numbers1
- Social security numbers1
About this breach
The investigation team has indexed a breach listing tied to Ascension Healthcare, the St. Louis-based Catholic health system, with an estimated attack date of May 31, 2023. The team estimates that 260,792 records were exposed. According to the investigation, the breach is linked to the exploitation of a zero-day vulnerability in Progress Software's MOVEit Transfer file-sharing platform by the Cl0p ransomware group, a campaign that hit hundreds of organizations through a piece of software they used to move files securely. Rather than breaching Ascension's own systems directly, attackers targeted a vendor in its supply chain. Ascension posted a notice describing a security incident after a ransomware attack at Vertex, one of its vendors, resulted in leaked patient data. No ransomware group publicly claimed this specific listing in the indexed record.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Since May 27, 2023: The Cl0p ransomware group began exploiting a zero-day vulnerability in MOVEit Transfer, tracked as CVE-2023-34362, to steal data from organizations using the file-transfer software, according to Hackmageddon's cyber attack timeline.
June 6, 2023: Ascension posted a notice describing a security incident after learning that a ransomware cyberattack at Vertex, one of its vendors, had resulted in leaked patient data, according to Hackmageddon.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers, phone numbers, names, home addresses, medical diagnoses, insurance provider details, doctors' names, and employment or job information.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
The combination of medical diagnoses with names, addresses, and insurance details is attractive to identity thieves and fraudsters. Exposed Social Security numbers are the most serious concern because they can be used to open new lines of credit, file fraudulent tax returns, or commit medical identity fraud, where someone uses your identity to receive care or bill an insurer in your name. People whose medical and insurance details were exposed may also face targeted phishing or scams that impersonate doctors, insurers, or healthcare providers. Because the data surfaced through the MOVEit campaign, some of it may circulate in criminal markets or be used for extortion attempts.
What Is Ascension Healthcare Doing in Response?
In June 2023, Ascension posted a notice describing a security incident involving its vendor Vertex, whose ransomware attack had resulted in leaked patient data, according to Hackmageddon's timeline. Beyond that notice, our team did not locate detailed public statements from Ascension specifically addressing this listing as of September 25, 2026. If you believe you were affected, look for any notification you may have received from Ascension or its vendors and follow the guidance it contains.
What Should You Do If You Were Affected?
Check whether you received a breach notification from Ascension or a related vendor, and read it carefully for the specific data types involved.
Place a fraud alert or a security freeze on your credit files with the three major credit bureaus. A freeze is free and blocks most new accounts from being opened in your name.
Review your credit reports at annualcreditreport.com and dispute any accounts or activity you do not recognize.
Watch your insurance statements and explanation of benefits documents for medical services you did not receive, which can signal medical identity fraud.
Be cautious with unexpected calls, texts, or emails that reference your health care, insurance, or doctors. Do not share your Social Security number or insurance details in response to unsolicited contact.
Consider strong, unique passwords and two-factor authentication on financial and healthcare accounts, especially if any of your other information has appeared in previous breaches.
