Supply chain
⛓ Supply Chain
Ascension Third-Party Breach (April 2025)
Primary Source ↗Incident Details
Ascension discloses new data breach after third-party hacking incident. Ascension, one of the largest private healthcare systems in the United States, is notifying patients that their personal and health information was stolen in a December 2024 data theft attack, which affected a former business partner. The health network operates 142 hospitals nationwide, has over 142,000 employees, and has reported a total revenue of $28.3 billion in 2023. “On December 5, 2024, we learned that Ascension patient information may have been involved in a potential security incident. We immediately initiated an investigation to determine whether and how a security incident occurred,” Ascension says in data breach notifications sent to affected individuals. Third-party company: Former business partner.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Former business partner
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2025-04-01 Breach occurred
- 2025-04-30 Publicly disclosed