MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedRansom DemandedPHIHEALTH_BASICFINANCIAL_ACCOUNTIDENTITY_GOVERNMENTIDENTITY_BASICCriticalContained
Ascension Health Alliance
bd_eef1dcc9991ab11d · schema v1 · pii pii-v1
Full breach record for Ascension Health Alliance →Ascension Health filed a supplemental security breach notification with the Maryland Office of the Attorney General on February 3, 2025, supplementing a December 19, 2024 filing. The incident involved a ransomware attack detected on May 8, 2024, affecting approximately 5.47 million individuals nationwide, including 22,293 Maryland residents. Exfiltrated data included PHI, financial account numbers, government IDs, and PII. Ascension engaged cybersecurity experts, notified the FBI and CISA, and provided 24 months of credit monitoring and ID theft recovery services.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5,466,931 affectedView incident
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376048.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 17, 2025
- Raw hash
- da011f954af9329443f1b2008b6253e0dc4b5cd917e786cabfeba3ff70299823
Reporting entity
- Name
- Ascension Health Alliancenorm: ascension health alliance
- Domain
- ascension.org
Victim entity
- Name
- Ascension Health Alliancenorm: ascension health alliance
- Domain
- ascension.org
Incident
- Discovered
- May 8, 2024
- Materiality determined
- —
- Notification sent
- Dec 19, 2024
- Affected individuals
- 5,466,931
- Data types
- PHIHEALTH_BASICFINANCIAL_ACCOUNTIDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- reported the incident to law enforcement and government partners, including the FBI and the Cybersecurity and Infrastructure Agency (CISA)
Compliance
- Time to disclose
- 20 months(588 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.