Ascension Data Breach Class Action Claims Hospital Patient Information Was Exposed

Ascension's May 2024 ransomware attack exposed 5.6 million patients' personal and medical information, leading to a class action lawsuit that remains unsettled as of 2026.

Ascension Health experienced one of the largest healthcare data breaches in recent years, exposing the personal and medical information of approximately 5.6 million patients and employees. The breach occurred when the Black Basta ransomware group gained unauthorized access to Ascension’s systems following a contractor’s misclick on a malicious link in late February 2024. The company discovered the breach on May 7-8, 2024, but did not begin notifying affected individuals until December 19, 2024—roughly seven months later.

The exposed information includes names, mailing addresses, phone numbers, email addresses, Social Security numbers, dates of birth, medical information such as dates of service and procedure codes, insurance details, and government ID numbers. Ascension has offered two years of complimentary credit monitoring and identity theft protection services to affected individuals. As of 2026, the class action lawsuit against Ascension remains in active litigation with no settlement agreement finalized.

Table of Contents

What Personal and Medical Information Was Compromised in the Ascension Breach?

The Black Basta attack exposed a comprehensive set of sensitive data that extends well beyond what many patients might expect. The breach included fundamental personal identifiers—full names, home addresses, phone numbers, and email addresses—but more critically, it also exposed Social Security numbers, dates of birth, and government identification numbers. This combination of information makes victims particularly vulnerable to identity theft because criminals now possess the exact data needed to open fraudulent credit accounts, file false tax returns, or apply for government benefits in a victim’s name. The medical information exposed varies slightly by the portion of Ascension’s network that was compromised. Affected individuals’ records include dates of hospital service, procedure codes, diagnosis codes, lab tests that were ordered, insurance information, and payment details.

However, Ascension has stated that evidence suggests the breach did not include full electronic health records (EHR) from clinical systems. This distinction matters because a complete EHR typically contains detailed clinical notes, medication histories, and treatment plans—though the information already exposed is sensitive enough to enable targeted fraud. The geographic scope of the breach was widespread. Ascension operates hospital and clinic networks across multiple states, with patients in Alabama, Michigan, Indiana, Tennessee, and Texas among those confirmed affected. Some patients who received care at Ascension facilities years ago may have discovered their data was exposed in this breach, demonstrating how long-standing digital records remain vulnerable to attack.

How Long Did It Take Ascension to Discover and Report the Breach?

The timeline of the Ascension breach reveals a critical delay in breach detection. The initial unauthorized access began on February 29, 2024, when a contractor clicked on a malicious link in what appeared to be a routine communication. However, Ascension did not detect this intrusion for more than two months. The company discovered unusual network activity and unauthorized access on May 7-8, 2024, approximately 68 days after the initial compromise. An even longer delay occurred between discovery and notification. Ascension did not begin notifying patients about the breach until December 19, 2024—more than seven months after the May discovery.

federal regulations require healthcare providers to notify affected individuals “without unreasonable delay” and generally within 60 days of discovering a breach, but Ascension fell far short of this timeline. The delay has been attributed to the complexity of the attack, the need to fully understand the scope of compromised data, and negotiations with forensic investigators and legal teams. The lengthy notification period meant that many patients were unaware their information was exposed for an extended period during which criminals could already be using their stolen data. The notification letters were expected to reach patients over a 2-3 week period starting December 19, 2024. Ascension set up a toll-free hotline at 866.408.3556 for patients with questions. The company’s initial notification to the Health and Human Services Office for Civil Rights in July 2024 contained placeholder figures, and the accurate count of 5,599,699 affected individuals was not reported to HHS OCR until December 19, 2024.

Ascension Data Breach Scope by Affected PopulationPrimary Breach (May 2024)5599699 individualsSecondary Breach (December 2024)437329 individualsTotal Individuals Affected6037028 individualsTotal Data Points Compromised10 individualsStates Impacted5 individualsSource: HIPAA Journal, Healthcare Dive, HHS OCR Database

Who Conducted the Ascension Data Breach and Why?

The Black Basta ransomware group was identified as the perpetrator of the Ascension attack. Black Basta is a known cybercriminal organization that specializes in ransomware campaigns against healthcare providers and other high-value targets. The group’s operating model typically involves gaining initial access through a compromised credential or social engineering attack, then deploying malware throughout the victim’s network to encrypt critical systems and steal sensitive data. In Ascension’s case, the initial entry point was particularly mundane yet effective—a contractor unknowingly clicked on a malicious link, likely through a phishing email or compromised website. This single click provided Black Basta with initial system access, from which they were able to move laterally through Ascension’s network, expand their access, and eventually deploy the ransomware that encrypted critical systems.

The Black Basta group has become one of the most prolific ransomware operators targeting U.S. healthcare organizations, suggesting that Ascension was a deliberately selected target rather than a random victim. Ransomware groups like Black Basta typically demand payment in exchange for decryption tools and promises not to publish stolen data. Ascension’s situation was complicated by the operational impact—the ransomware attack caused significant disruption to electronic health record systems, patient portals, and phone systems. Some Ascension facilities were forced to divert ambulances, and elective care was paused. It took approximately six weeks for Ascension to fully restore EHR systems, and the total financial impact was reflected in a $1.1 billion net loss recorded in the company’s fiscal year 2024.

What Protection Services Are Available to Patients Affected by the Ascension Breach?

Ascension is offering two years of complimentary identity monitoring and credit protection services to all affected individuals. For those impacted by the primary May 2024 breach, the services are provided through IDX, a credit monitoring and identity theft protection company. The coverage includes credit monitoring, fraud detection, and identity theft restoration services. Patients do not need to pay out of pocket for these services—Ascension is covering the full cost. Additionally, Ascension has provided a $1 million insurance policy to cover potential losses from identity theft. While this policy backstops individual losses, it is important to understand that the monitoring services are the primary tool for detecting unauthorized activity early.

Victims who catch fraudulent activity early—such as unauthorized credit accounts opened in their name or false tax returns filed on their behalf—can resolve these issues more quickly and with less financial and emotional damage. However, identity monitoring services are not foolproof. They work by alerting individuals when certain activities occur, but they cannot prevent a criminal from trying to use stolen data. For patients impacted by a secondary breach discovered in December 2024 involving a former business partner of Ascension, identity monitoring and credit protection are provided through Kroll. Affected individuals should have received separate notification letters describing which monitoring service they are enrolled in and how to activate their protection. It is critical that affected patients actually enroll in and use these monitoring services, as simply being offered two years of protection does nothing to prevent fraud if the individual never activates the service or check the monitoring alerts.

What Is the Current Status of the Class Action Lawsuit Against Ascension?

The class action lawsuit against Ascension for negligence in safeguarding patient data remains in active litigation as of 2026, with no settlement agreement yet finalized. In a significant ruling, Judge John Ross permitted the case to proceed by allowing plaintiffs’ allegations of negligence to advance, along with several claims based on state consumer protection laws. The judge trimmed some claims from the original complaint, but the core allegations—that Ascension failed to adequately secure patient data and implement appropriate cybersecurity protections—remain viable. The lawsuit was expected to take 12-24 months from the litigation stage to reach a potential settlement, though the actual timeline can be difficult to predict.

Settlements in data breach class actions typically include several components: compensation to affected individuals for their time and inconvenience, sometimes ranging from $25 to several hundred dollars per person depending on the settlement amount and number of claimants; reimbursement for out-of-pocket expenses related to identity theft or credit monitoring beyond what Ascension is already providing; coverage of additional credit monitoring or other services beyond the standard two years; and funding for a claims administration process that verifies which individuals are eligible for compensation. A critical limitation to understand is that settling a class action does not require Ascension to admit wrongdoing. In healthcare data breach settlements, companies typically deny liability while agreeing to settle to avoid the cost and uncertainty of continued litigation. This means that settling does not necessarily mean a court or jury has determined that Ascension was negligent—only that the parties agreed to resolve the dispute. Additionally, the settlement amount that becomes available to individual patients will be reduced by attorney fees, court costs, and claims administration expenses, sometimes resulting in per-person payouts that are smaller than initial estimates.

How Can Patients Monitor for Identity Theft Following the Ascension Breach?

Affected individuals should take immediate action to monitor their financial accounts and credit reports, even before enrolling in the monitoring services Ascension is providing. Patients can access their credit reports for free once per year through AnnualCreditReport.com, which is the official, free source authorized by the federal government. Reviewing credit reports for unauthorized accounts, inquiries, or information that does not belong to them is the first step in detecting fraud.

Beyond credit monitoring, patients should monitor their bank and credit card accounts directly for unauthorized transactions. Many financial institutions offer fraud alerts or account security features that notify customers of suspicious activity in real time. Additionally, patients should monitor their medical records and explanation-of-benefits (EOB) statements from their insurance company to ensure that no one has fraudulently obtained healthcare services using their identity. Healthcare fraud is a distinct risk from financial fraud and can compromise insurance benefits, create erroneous medical records, and trigger billing issues.

The Secondary Ascension Data Breach Affecting Former Business Partner Customers

In December 2024, Ascension disclosed a separate data breach affecting approximately 437,329 patient records through a former business partner whose software was compromised. This secondary breach is distinct from the primary Black Basta ransomware attack and affected different sets of data. The third-party vendor breach exposed hospital admission and discharge dates, diagnosis codes, procedure codes, medical record numbers, physician names, insurance information, and clinical data from hospital stays.

Patients affected by this secondary breach received separate notification letters describing the incident and their eligibility for two years of credit monitoring and identity theft protection services through Kroll. The existence of this secondary breach underscores a broader risk in healthcare: even when a primary healthcare system implements strong security controls, vulnerabilities in third-party vendors and former business partners can create pathways for data exposure. Patients who received care through Ascension’s network and were notified about either the primary breach or the secondary breach should treat both incidents as data exposure risks and ensure they are enrolled in the appropriate monitoring services.


You Might Also Like

Open Settlements You Can Claim Now

Browse current class action settlements accepting claims — several require no proof of purchase: