Ascension Announces String of Business Associate Data Breaches
Ascension has announced that it has been affected by a data breach at one of its former business partners. This is the fourth business associate data breach to be announced by Ascension this year, and the fifth since February 2024, as Ascension was also affected by the Change Healthcare data breach. All five of those breaches involved unauthorized access to patient data in 2024. On top of that, Ascension suffered a cyberattack of its own in 2024. The ransomware attack involved unauthorized access to the electronic protected health information of 5.6 million patients.
Ascension is a Missouri-based catholic health system providing services to patients in 16 U.S. states and the District of Columbia. The latest incident occurred at a former (unnamed) business partner and was identified by Ascension on December 5, 2024. An investigation was launched, and in late January, Ascension determined that sensitive patient data had been inadvertently disclosed to the former business partner, which experienced a data breach after a hacker exploited a vulnerability in third-party software.
Ascension confirmed that patients in Alabama, Indiana, Michigan, Tennessee, and Texas had been affected, and the breach was recently reported to the HHS’ Office for Civil Rights as involving the protected health information of 437,329 individuals. The investigation confirmed that the compromised information includes names, demographic information, Social Security numbers, and clinical information related to inpatient visits. As with all of the other business associate data breaches recently announced, the security incident was confined to its business associate’s systems. There was no unauthorized access to data stored on Ascension systems. Ascension said it has conducted a review of its data security measures and will be enhancing them to prevent similar incidents in the future.
A couple of weeks before the April 28, 2025, announcement, Ascension confirmed that it had been affected by a data breach at the Missouri law firm Scharnhorst Ast Kennard Griffin (SAKG). A hacker gained access to the SAKG network, and between July 17, 2024, and August 6, 2024, exfiltrated files containing names, demographic information, medical record numbers, medical treatment information, Social Security numbers, and patient account numbers. SAKG reported the breach to the HHS’ Office for Civil Rights as affecting 639 individuals, although it is not known if that total includes the Ascension patients.
The previous month, Ascension announced that patient data had been exposed in a data security incident at its business associate, Access Telecare. Access Telecare provides telehealth services to patients of Ascension Seton in Texas. This was an email breach that involved unauthorized access to the email accounts of several Access TeleCare patients between November 6, 2023, and January 8, 2024. The compromised data included names, dates of birth, passport numbers, Social Security numbers, treatment information, and financial account information.
In February, Ascension announced that patient data had been compromised in a security incident at the business associate Restrorix Health, which provides wound care management services to patients of Ascension Michigan, Ascension St. Vincent’s Riverside, and Ascension St. Agnes. This was an email account breach that Restorix Health identified on May 30, 2024, and involved unauthorized access to the account between May 7 and May 29, 2024. Ascension was notified about the incident on December 18, 2024. The compromised information included first and last names, dates of birth, driver’s license number, government identification numbers, passport numbers, Social Security numbers, patient ID numbers, medical information, prescription information, dates of service, conditions, diagnosis/treatment information, certificate and license numbers, and/or health insurance information.
The string of business associate data breaches clearly demonstrates that third-party data breaches are a major threat in healthcare, and the difficulty even the biggest healthcare systems have in managing third-party risk.
