Nearly 6 million people exposed by massive healthcare breach — including credit cards, SSNs and more

An open lock depicting a data breach
(Image credit: Shutterstock)

A disastrous cybersecurity breach earlier this year at one of the largest healthcare systems in the United States left the sensitive data of 5.6 million patients and employees exposed.

A Feb.29, 2024 ransomware attack at Ascension Health, which operates roughly 140 hospitals, 40 senior care facilities and 175,000 associated providers across the nation, wasn’t discovered until May 8th when it caused chaos in the systems forcing hospitals to use manual and paper based systems when computer and phone systems were shut down.

Ascension Health handles over 16 million patient visits annually, and reported that though the data involved will vary and cannot be confirmed for each individual it may include any of the following:

  • Medical information such as medical record numbers, dates of service, types of lab tests or procedure codes
  • Payment information, such as credit card information or bank account numbers
  • Insurance information such as Medicaid or Medicare ID numbers
  • Policy numbers or insurance claims
  • Government identification such as social security numbers, tax ID numbers, drivers license or passport numbers
  • Personal information including dates of birth or addresses

The organization has now begun the process of notifying the 5,599,699 potentially affected patients and employees as the data review is being completed. Affected individuals should expect to receive notice letters within the next 2-3 weeks, and Ascension will be offering 24 months of credit and CyberScan monitoring, as well as $1,000,000 insurance reimbursement policy and fully managed ID theft recovery services.

In an announcement Ascension said “although patient data was involved…there remains no evidence that data was taken from our Electronic Health Records (EHR) and other clinical systems, where our full patient records are securely stored.”

Ascension has also stated that since the attack they have successfully “restored all systems, clinical functions, and Electronic Health Record access that were impacted by the incident,” which left hospitals in chaos attempting to treat patients while computers and phone lines were down.

The initial breach was caused by an employee accidentally downloading a malicious file; the ransomware group Black Basta is believed to be responsible for the cyberattack. Black Basta is a ransomware-as-a-service and was first identified in April 2022, more than 500 organizations have been victim to its attacks.

After the Ascension attack, both the FBI and CISA, the Cybersecurity and Infrastructure Security Agency, released advisories with recommendations for hospitals and critical infrastructure organizations to follow which include security measures such as: installing updates for operating systems, software and firmware as soon as they are released, require phishing-resistant MFA for as many services as possible and train users to recognize and report phishing attempts.

More from Tom's Guide

Amber Bouman
Senior Editor Security

Amber Bouman is the senior security editor at Tom's Guide where she writes about antivirus software, home security, identity theft and more. She has long had an interest in personal security, both online and off, and also has an appreciation for martial arts and edged weapons. With over two decades of experience working in tech journalism, Amber has written for a number of publications including PC World, Maximum PC, Tech Hive, and Engadget covering everything from smartphones to smart breast pumps. 

Read more
An open lock depicting a data breach
Massive healthcare data breach just exposed the personal info of 1 million Americans — what to do now
Screen graphic showing data breach warning
5 worst data breaches of 2024 — including the mother of all breaches
An open lock depicting a data breach
3.5 million hit in major law firm data breach — full names, SSNs, dates of birth, addresses and more exposed
Globe Life insurance company logo on a cell phone in front of a monitor display the About page for the company. Shadowy hand holds the phone.
850,000 people exposed in massive insurance data breach — full names, dates of birth and SSNs
An open lock depicting a data breach
The top 10 data breaches of 2024
An open lock with a digital background and a cross and bones indicating a cyberattack
More than 70 million students and teachers had their personal data stolen in PowerSchool breach
Latest in Online Security
23andME box
23andMe has declared bankruptcy — here's how to delete your data now
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Latest in News
Nintendo Switch 2
Nintendo Switch 2 tipster may have just leaked release month and launch plans
Disney Plus logo
Disney Plus upgrade just fixed one of my biggest problems with the home page
Tom Hiddleston as Robert Laing in "High Rise" now streaming on Netflix
5 best Netflix movies in March you haven't watched yet
iPhone 16 with Apple Intelligence logo for iOS 18.1
iOS 18.4: All the newest Apple Intelligence features coming to your iPhone
Maria Debska in "Just One Look" now streaming on Netflix
3 best Netflix shows in March you haven't watched yet
Split image featuring the Galaxy S25 Edge (left) and Galaxy S25 Ultra (right)
Samsung Galaxy S25 Edge just tipped for two Galaxy S25 Ultra-level features