Supply chain ⛓ Supply Chain

Ascension Third-Party Breach (April 2025)

📅 2025-04-01 🏢 Former business partner
Primary Source ↗

Incident Details

Ascension discloses new data breach after third-party hacking incident. ​Ascension, one of the largest private healthcare systems in the United States, is notifying patients that their personal and health information was stolen in a December 2024 data theft attack, which affected a former business partner. The health network operates 142 hospitals nationwide, has over 142,000 employees, and has reported a total revenue of $28.3 billion in 2023. “On December 5, 2024, we learned that Ascension patient information may have been involved in a potential security incident. We immediately initiated an investigation to determine whether and how a security incident occurred,” Ascension says in data breach notifications sent to affected individuals. Third-party company: Former business partner.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Former business partner
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2025-04-01 Breach occurred
  2. 2025-04-30 Publicly disclosed