Ascension Health Alliance
ent_019dea50afbfd194dd7fa4bf28fd1d23
Disclosures
23
State AG · HHS OCR · 13 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
5,599,699
nationwide · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Ascension Health Alliance
- Normalized
- ascension health alliance— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300IMOY6ECI21DH68
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- ascension.org
Disclosure history (23)newest first
- Maryland State AGas victim2025-12-17
Ascension Health filed a supplemental security breach notification with the Maryland Office of the Attorney General on February 3, 2025, supplementing a December 19, 2024 filing. The incident involved a ransomware attack detected on May 8, 2024, affecting approximately 5.47 million individuals nationwide, including 22,293 Maryland residents. Exfiltrated data included PHI, financial account numbers, government IDs, and PII. Ascension engaged cybersecurity experts, notified the FBI and CISA, and provided 24 months of credit monitoring and ID theft recovery services.
- Maine State AGas reporting2025-08-25
Healthcare Services Group, Inc. (HSGI) disclosed an external system breach (hacking) occurring between September 27 and October 3, 2024. HSGI discovered the unauthorized access on October 7, 2024. The incident compromised personal information including names, SSNs, driver's license numbers, financial account info, and full access credentials for approximately 624,496 individuals nationwide, including 3,871 Maine residents. HSGI notified federal law enforcement, implemented additional safeguards, and offered 12 months of credit monitoring through Experian.
- Massachusetts State AGas victim2025-04-28
Ascension Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-04-28. 96 Massachusetts residents were affected.
- MISSOURIHHS OCRas victim2025-04-28
Ascension Health (Missouri) reported to HHS OCR on 2025-04-28 a Hacking/IT Incident affecting 437,329 individuals. Breached information was located on a Network Server. No business associate was identified as present. No further detail was provided in the public HHS disclosure.
- Indiana State AGas victim2025-04-28
Ascension Health reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-30 and was reported on 2025-04-28. 169,183 Indiana residents were affected. 430,910 individuals affected in total.
- Illinois State AGas victim2025-04-01
ASCENSION HEALTH filed a data-breach notice with the Illinois Attorney General in April 2025 (case 25-04-126). The register records the breach as discovered on December 5, 2024. Personal information types reported: medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2025-02-07
Supplemental notice from Ascension Health to the New Hampshire Attorney General regarding a data security incident. Ascension notified 645 NH residents and approximately 5.47 million individuals nationwide. The filing supplements a prior letter from December 19, 2024. Incident details and data types are not specified in this correspondence.
- California State AGas victim2025-02-03
Ascension Health detected a ransomware attack on May 8, 2024, involving unauthorized access to systems on May 7-8, 2024. A cybercriminal exfiltrated files containing patient and associate personal information, including medical records, payment info, and government IDs. The organization engaged cybersecurity experts, notified law enforcement, and offered identity theft protection.
- Oregon State AGas victim2025-02-03
Ascension Health reported a data breach to the Oregon Attorney General. The breach was reported on 2025-02-03. The breach occurred during 2/29/2024 - 5/8/2024. The breach was discovered on 5/8/2024. 5,466,931 individuals were affected. Notice was sent on 12/19/2024.
- Oregon State AGas victim2024-12-19
Ascension Health reported a data breach to the Oregon Attorney General. The breach was reported on 2024-12-19. 5,599,699 individuals were affected.
- California State AGas victim2024-12-19
Ascension Health experienced a ransomware attack resulting in unauthorized access to patient and associate data. The breach occurred between February 29 and June 11, 2024, and was detected on May 8, 2024. A cybercriminal exfiltrated files containing names, medical records, payment info, insurance IDs, and government IDs. Ascension engaged cybersecurity experts, notified law enforcement, and offered identity protection services.
- Massachusetts State AGas victim2024-12-19
Ascension Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-12-19. 2,632 Massachusetts residents were affected.
- Delaware State AGas victim2024-12-19
Doxim Inc., a third-party service provider for Ascension, experienced a security incident on December 30, 2023, involving unauthorized access to files containing personal information. The breach affected approximately 5.6 million individuals nationwide, including 606 Delaware residents. Data exposed included names, addresses, SSNs, and financial account details. Doxim took systems offline, notified law enforcement, and engaged forensic experts. Affected individuals are offered 12 months of credit monitoring via Kroll.
- Washington State AGas victim2024-12-19
Ascension Health reports a ransomware incident detected May 8, 2024, affecting patients and employees. Data exfiltrated included PHI, SSNs, medical record numbers, and financial data. 5,787 Washington residents notified on Dec 19, 2024. Response included FBI/CISA notification and IDX credit monitoring services.
- Maine State AGas victim2024-12-19
Ascension Health disclosed a ransomware attack detected on May 8, 2024, affecting approximately 5.6 million individuals nationwide, including 658 Maine residents. The incident exposed PHI, government IDs, and financial data. Notifications were sent on December 19, 2024, offering 24 months of credit monitoring and ID theft protection.
- Illinois State AGas victim2024-12-01
ASCENSION HEALTH filed a data-breach notice with the Illinois Attorney General in December 2024 (case 24-12-032). The register records the breach as discovered on May 7, 2024. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- MISSOURIHHS OCRas victim2024-07-03
Ascension Health reported to HHS on 2024-07-03 a Hacking/IT Incident affecting 5466931 individuals. Breached information located on Network Server.
- TEXASHHS OCRas reporting2023-06-06
Ascension Seton reported to HHS on 2023-06-06 a Hacking/IT Incident affecting 17,191 individuals. Breached information located on Network Server. A business associate experienced a ransomware incident affecting PHI including names, addresses, SSNs, driver's license numbers, DOBs, financial/insurance info, lab results, medications, and diagnoses. The CE offered free credit monitoring.
- TEXASHHS OCRas reporting2023-06-06
Ascension Providence reported to HHS on 2023-06-06 a Hacking/IT Incident affecting 1415 individuals. Breached information located on Network Server. A business associate experienced a ransomware incident affecting PHI including names, addresses, SSNs, driver's license numbers, DOBs, financial and health insurance info, lab results, medications, and diagnoses. The CE offered free credit monitoring services.
- Montana State AGas victim2021-05-05
CaptureRx, a third-party administrator for Ascension Health, notified patients of unauthorized access to files containing personal information (PII/PHI) on Feb 6, 2021. Access was detected on Feb 19, 2021. CaptureRx investigated, secured systems, and is enhancing policies and training. No evidence of misuse found.
- Massachusetts State AGas reporting2014-01-22
Partners Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2014-01-22. 1 Massachusetts residents were affected. The report records the breach type as paper.
- Massachusetts State AGas reporting2013-09-25
Partners Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2013-09-25. 1 Massachusetts residents were affected. The report records the breach type as undefined.
- CALIFORNIAHHS OCRas reporting2011-06-16
HealthCare Partners (CA) reported to HHS OCR on 2011-06-16 a Theft incident affecting 15,677 individuals. The breached information was located on a Desktop Computer. No business associate was identified. No further detail was provided in the web description.