MalwareHealthcareHealthcareRansomwareCapture Stored DataRansom DemandedData ExfiltratedData EncryptedCustomer Data InvolvedEmployee Data InvolvedTargetedPIIPHIPCIFINANCIALIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Ascension Health Alliance
bd_ffefbbb101b0be3f · schema v1 · pii pii-v1
Full breach record for Ascension Health Alliance →On May 8, 2024, Ascension Health detected unauthorized activity on its technology systems resulting from a ransomware attack. A cybercriminal obtained copies of files on May 7–8, 2024, containing patient and employee personal information including medical, payment, insurance, government ID, and other personal data. Approximately 658 Maine residents were notified on December 19, 2024. Total affected individuals numbered 5,599,699. IDX identity protection services were offered for 24 months.
Maine clockDiscovered May 8, 2024 → Filed with AG Dec 19, 2024225d ✗ ME AG >90d32 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_02c1dec26ae275caMontana State AGfiled 2024-12-19Candidate
- bd_87337b5050c1dc47Oregon State AGfiled 2024-12-19Verified
- bd_afc6dca482d6c28aCalifornia State AGfiled 2024-12-19Verified
- bd_ffe2ffef268362d8Washington State AGfiled 2024-12-19Verified
Show 3 more filings ↓Show fewer ↑up to 46d gap
- bd_11a18f6c51cd9cedDelaware State AGfiled 2025-01-16(28d gap)Verified by operator
- bd_8febdcacf791a205California State AGfiled 2025-02-03(46d gap)Verified
- bd_a6331b2f68fc294dOregon State AGfiled 2025-02-03(46d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/e55264f2-ff87-4b28-874d-653cfb735fe6.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 19, 2024
- Raw hash
- 110a91ab3af77cf6e63636c168d8b8b45a2e0323acbb66f5f9b45fbcced893ec
Reporting entity
- Name
- Ascension Health Alliancenorm: ascension health alliance
- Domain
- ascension.org
- Industry
- Healthcare
Victim entity
- Name
- Ascension Health Alliancenorm: ascension health alliance
- Domain
- ascension.org
- Industry
- Healthcare
- Industry
- Healthcarellm
Incident
- Discovered
- May 8, 2024
- Materiality determined
- —
- Notification sent
- Dec 19, 2024
- Affected individuals
- 658
- Data types
- PIIPHIPCIFINANCIALIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- FBICISA
Compliance
- Time to disclose
- 32 weeks(225 days from discovery to filing)
- Compliance flags
- ME AG >90d · 225dME resident >180d · 225d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: May 8, 2024→ Filed with AG: Dec 19, 2024225d 90 days ME AG >90d Maine Discovered: May 8, 2024→ Notified: Dec 19, 2024225d 180 days ME resident >180d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.