MalwareRansomwareData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedPHIHEALTH_BASICFINANCIAL_ACCOUNTIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
Ascension Health Alliance
bd_afc6dca482d6c28a · schema v1 · pii pii-v1
Full breach record for Ascension Health Alliance →Ascension Health experienced a ransomware attack resulting in unauthorized access to patient and associate data. The breach occurred between February 29 and June 11, 2024, and was detected on May 8, 2024. A cybercriminal exfiltrated files containing names, medical records, payment info, insurance IDs, and government IDs. Ascension engaged cybersecurity experts, notified law enforcement, and offered identity protection services.
California clockDiscovered May 8, 2024 → Notified Dec 19, 2024225d ✗ CA 60-day late32 weeks discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_02c1dec26ae275caMontana State AGfiled 2024-12-19Candidate
- bd_87337b5050c1dc47Oregon State AGfiled 2024-12-19Verified
- bd_ffe2ffef268362d8Washington State AGfiled 2024-12-19Verified
- bd_ffefbbb101b0be3fMaine State AGfiled 2024-12-19Verified
Show 3 more filings ↓Show fewer ↑up to 46d gap
- bd_11a18f6c51cd9cedDelaware State AGfiled 2025-01-16(28d gap)Verified by operator
- bd_8febdcacf791a205California State AGfiled 2025-02-03(46d gap)Verified
- bd_a6331b2f68fc294dOregon State AGfiled 2025-02-03(46d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-596447
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2024
- Raw hash
- 01579dc82a33975e44a6f0129254b9e33e47c5a02b7412ef53a5e00586592c44
Reporting entity
- Name
- Ascension Health Alliancenorm: ascension health alliance
- Domain
- ascension.org
Victim entity
- Name
- Ascension Health Alliancenorm: ascension health alliance
- Domain
- ascension.org
Incident
- Discovered
- May 8, 2024
- Materiality determined
- —
- Notification sent
- Dec 19, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICFINANCIAL_ACCOUNTIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified government regulators
Compliance
- Time to disclose
- 32 weeks(225 days from discovery to filing)
- Compliance flags
- CA 60-day late · 225d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: May 8, 2024→ Notified: Dec 19, 2024225d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.