140 Hospitals Offline: The May 8 Black Basta Ransomware Breach Across 19 States
140 Hospitals Offline: The May 8 Black Basta Ransomware Breach Across 19 States
On May 8, 2024, the Ascension health system detected unauthorized activity across its network infrastructure. Administrators quickly identified the intrusion as a ransomware attack and severed external connections to contain the damage. The decision forced 140 hospitals across 19 states and the District of Columbia into immediate downtime. Medical staff lost access to the MyChart electronic health record system. Doctors could no longer order tests or transmit prescriptions electronically. The breach paralyzed clinical operations and forced one of the largest Catholic health systems in the United States to operate using pen and paper.
Core Incident Parameters: 20 Questions Answered
To establish the factual baseline of this cyberattack, we answer twenty primary questions regarding the breach mechanics and operational consequences.
- When did the Ascension ransomware attack occur? The intrusion began and was detected on May 8, 2024.
- Which ransomware group executed the breach? Cybersecurity experts and federal agencies attributed the attack to Black Basta.
- How hospitals went offline? The attack disabled digital operations at 140 facilities.
- How states experienced operational disruptions? The network collapse affected 19 states and the District of Columbia.
- How patient records were stolen? Attackers exfiltrated 5, 599, 699 individual records.
- What specific patient data was compromised? Stolen files contained Social Security numbers, billing codes, and insurance details.
- How did the attackers gain initial access? An Ascension employee inadvertently downloaded a malicious file.
- Did Ascension pay a ransom to the attackers? Ascension has not publicly confirmed any ransom payment.
- Which electronic health record system went down? The MyChart system remained unavailable for weeks.
- How long did the system outages last? Full restoration required approximately six weeks.
- Which states reported ambulance diversions? Facilities in Michigan, Indiana, Tennessee, Kansas, and Florida diverted incoming emergency vehicles.
- What alternative methods did doctors use for recordkeeping? Medical staff reverted to manual paper charting.
- How did the attack affect emergency medical services? Dispatchers routed severe trauma cases to competing hospitals to ensure immediate triage.
- Were patient appointments and elective procedures delayed? Administrators postponed nonemergency procedures and routine appointments.
- Did the breach affect Ascension employees? The stolen data included personal information belonging to hospital staff.
- What federal agencies responded to the incident? The FBI and the Cybersecurity and Infrastructure Security Agency coordinated the federal response.
- How did the attack alter Ascension finances? The recovery costs and lost revenue erased major year over year financial gains.
- What remediation services did Ascension offer victims? The health system provided two years of credit monitoring and identity theft recovery services.
- Did the attackers steal data directly from the primary EHR database? The attackers extracted files from network servers rather than the main clinical database.
- When did Ascension complete its data review process? The organization finalized its review and began mailing notification letters on December 19, 2024.
The May 8 Network Collapse
The breach originated at the endpoint level. An employee downloaded a malicious file that allowed the Black Basta ransomware gang to bypass perimeter defenses. Once inside the network, the Russian speaking cybercrime syndicate moved laterally across the infrastructure. Black Basta operates as a ransomware as a service syndicate. The group specializes in double extortion tactics. They steal sensitive files before deploying encryption software to lock the victim out of their own network. Ascension administrators detected the anomaly on the morning of May 8. They immediately shut down network systems to halt the automated spread of the encryption malware. This containment strategy successfully protected the primary electronic health record database. Yet the shutdown severed access to all digital tools required for modern medical care.
The outage disabled the MyChart patient portal. Physicians lost the ability to view medical histories or verify patient allergies. Pharmacists could not process electronic prescriptions. Laboratory technicians could not transmit test results to attending doctors. The entire communication framework of a 140 hospital network disappeared in a single morning. Ascension called in Mandiant to lead the incident response and forensic investigation. The recovery timeline stretched far beyond initial estimates. It took administrators roughly six weeks to restore access to the electronic medical record system and resume standard operations.
Ambulance Diversions and Clinical Paralysis
The sudden loss of digital infrastructure created a serious patient safety hazard. Emergency departments could no longer process incoming patients. To prevent dangerous bottlenecks, Ascension initiated ambulance diversions across multiple regions. Hospitals in Michigan, Indiana, and Tennessee formally requested that emergency medical services route patients to other facilities. In Wichita, Kansas, local emergency medical services diverted all ambulance calls from Ascension hospitals for a full day. In Pensacola, Florida, dispatchers routed trauma patients away from the local Ascension facility.
Inside the hospitals, the reality of paper based medicine set in. Nurses used whiteboards to track patient locations. Doctors wrote medication orders by hand. Runners physically carried paper lab results from the basement to the intensive care units. The manual processes tripled wait times in emergency rooms and outpatient clinics. Administrators canceled elective surgeries and postponed routine imaging appointments. The absence of digital records meant doctors had to rely on patients to remember their exact medication dosages. This environment introduced severe risks for medication errors and delayed diagnoses.
Data Exfiltration and Patient Exposure
While Ascension protected its core electronic health record database, the attackers successfully exfiltrated massive amounts of data from other network servers. On December 19, 2024, Ascension filed an updated breach notification with the Office of the Maine Attorney General. The filing confirmed that Black Basta operatives stole files containing the personal information of 5, 599, 699 patients and employees. This figure established the Ascension breach as the third largest healthcare data theft of 2024.
The stolen files contained highly sensitive information. The compromised data included full names, dates of birth, physical addresses, and Social Security numbers. The attackers also obtained medical record numbers, dates of service, procedure codes, and details regarding specific lab tests. Financial data fell into the hands of the cybercriminals as well. The exfiltrated files contained credit card numbers and bank account details. Ascension stated that the exact combination of exposed data varied by individual. The organization offered affected individuals two years of credit monitoring and a one million dollar insurance reimbursement policy for fraud incidents.
Financial and Operational Consequences
The ransomware attack inflicted severe financial damage on the nonprofit health system. Before the breach, Ascension reported a $79 million loss from recurring operations for the ten months ending April 30, 2024. This represented a massive improvement compared to the $1. 2 billion loss recorded during the same period the previous year. The May 8 attack halted this financial recovery. The system outage caused immediate delays in revenue pattern processes. Administrators could not submit insurance claims or process patient payments for six weeks. The combination of lost revenue and massive remediation costs erased a large portion of the year over year financial improvements.
The incident forced federal regulators to problem new warnings regarding healthcare cybersecurity. The Health Information Sharing and Analysis Center published an advisory confirming that Black Basta had accelerated attacks against the medical sector. The Ascension breach proved that perimeter defenses cannot protect a network if an employee executes a malicious payload. The reliance on interconnected digital systems means a single compromised endpoint can force 140 hospitals to divert ambulances and delay necessary medical care.
Verified Breach Metrics
The following table outlines the verified data points regarding the May 2024 Black Basta attack on Ascension.
| Metric Category | Verified Data Point |
|---|---|
| Date of Intrusion | May 8, 2024 |
| Threat Actor | Black Basta |
| Hospitals Affected | 140 Facilities |
| Geographic Scope | 19 States and Washington D. C. |
| Total Records Compromised | 5, 599, 699 Individuals |
| System Downtime | Approximately 6 Weeks |
| Root Cause | Malicious File Download |
| Final Data Review Date | December 19, 2024 |
The Black Basta attack on Ascension demonstrates the fragility of modern healthcare infrastructure. A single malicious file download bypassed network security and triggered a cascading failure across 19 states. Medical professionals lost their primary diagnostic and communication tools in an instant. The resulting ambulance diversions and delayed procedures created a serious patient safety hazard that lasted for six weeks. The theft of nearly 5. 6 million records ensures the consequences of this breach remain for years. Ascension must manage the financial damage and regulatory scrutiny while attempting to rebuild trust with millions of exposed patients.
From 500 to 5,599,699: Tracking Ascension’s Escalating Casualty Figures on the HHS OCR Breach Portal

The Department of Health and Human Services Office for Civil Rights maintains a public database tracking medical data theft. Federal law requires healthcare organizations to report unauthorized access to protected health information within sixty days of discovery. Ascension detected a network intrusion on May 8 2024. The health system faced a strict July deadline to notify federal regulators. The organization submitted an initial report to the federal portal using a placeholder figure of 500 individuals. This minimum threshold triggers public listing on the federal database while allowing the victim organization time to complete forensic analysis. The true scope of the casualty list remained hidden for seven months.
On December 19 2024 Ascension concluded its data review and updated the federal portal. The revised casualty figure reached 5, 599, 699 patients and employees. The breach ranks as the third largest healthcare data theft of 2024. The attackers extracted highly sensitive files from seven servers before administrators severed network connections. The stolen files contained names, addresses, dates of birth, Social Security numbers, medical record numbers, procedure codes, and bank account details.
Twenty Questions Answered: Tracking the Federal Breach Report
To establish the factual baseline of the regulatory reporting process, we answer twenty primary questions regarding the federal portal updates and the final casualty figures.
1. What is the federal breach portal?
The Office for Civil Rights operates a public database listing healthcare data breaches affecting 500 or more individuals.
2. Why did Ascension initially report 500 affected individuals?
The organization used 500 as a placeholder to meet the sixty day federal reporting deadline while forensic investigators continued analyzing the compromised servers.
3. When did Ascension file the initial report?
The health system submitted the placeholder report to federal regulators in July 2024.
4. What does the 500 figure represent in federal compliance?
It is the minimum number required to trigger a public posting on the federal database. Organizations frequently use this exact number when the final count remains unknown.
5. When did Ascension update the casualty figure?
The organization published the final investigation results and updated the federal portal on December 19 2024.
6. What is the final count of affected individuals?
The forensic review confirmed the attackers compromised the data of 5, 599, 699 people.
7. How long did the data review take?
External cybersecurity specialists spent more than seven months analyzing the exfiltrated files to identify the victims.
8. Did the attackers access the electronic health records directly?
Ascension stated the investigation found no evidence that hackers breached the primary electronic health record system.
9. Where did the attackers find the patient data?
The hackers extracted the information from scattered files stored on seven compromised network servers.
10. What personal information was stolen?
The stolen data includes names, addresses, and dates of birth.
11. Were Social Security numbers compromised?
Yes. The attackers obtained government identification numbers including Social Security numbers, driver license numbers, and passport details.
12. Did the breach expose financial data?
Yes. The compromised files contained credit card information and bank account numbers.
13. What medical details did the hackers obtain?
The files included medical record numbers, dates of service, types of lab tests, and procedure codes.
14. Was insurance information included in the theft?
Yes. The attackers stole Medicare identification numbers, Medicaid details, policy numbers, and insurance claims.
15. How does this breach rank among 2024 healthcare cyberattacks?
It is the third largest healthcare data breach of 2024.
16. What compensation is Ascension offering victims?
The health system is offering complimentary credit monitoring and identity protection services.
17. How long does the credit monitoring last?
The protection package lasts for two years from the date of enrollment.
18. Do patients who enrolled in July need to register again?
Yes. Ascension arranged a new monitoring package in December. Previous registrants must enroll again to receive the full two year coverage.
19. Did the breach affect employees as well as patients?
Yes. The compromised files contained data belonging to patients, senior living residents, and employees.
20. When do patients receive notification letters?
Ascension began mailing individual notification letters in late December 2024. The mailing process continued into January 2025.
The Placeholder Strategy and Federal Compliance
The Health Insurance Portability and Accountability Act requires covered entities to notify the federal government of unsecured protected health information breaches. The law mandates notification without unreasonable delay and no later than sixty days after discovery. Ascension detected the ransomware intrusion on May 8 2024. The sixty day window closed in early July. The health system faced a common regulatory predicament. The network remained unstable. External forensic teams had not finished cataloging the exfiltrated data. The organization knew the attackers stole files could not identify the specific victims.
Ascension submitted a breach report using the number 500. This tactic satisfies the immediate regulatory requirement. The federal portal automatically publishes any breach affecting 500 or more people. By submitting the minimum threshold number, Ascension acknowledged the data theft publicly while buying time to complete the forensic analysis. Change Healthcare employed the exact same strategy earlier in 2024. Change Healthcare reported 500 victims to the federal portal in July 2024 before eventually confirming the breach affected 100 million people.
The placeholder strategy obscures the true magnitude of healthcare cyberattacks during the initial months following an intrusion. Patients, investors, and lawmakers view the federal portal to gauge the severity of a breach. A listing of 500 victims suggests a contained localized event. The reality involves millions of compromised records sitting on dark web extortion sites while forensic accountants spend months reading server logs.
The December Update and Final Casualty Count
The true magnitude of the Ascension data theft emerged on December 19 2024. The health system published a formal update confirming the conclusion of the data review. The revised casualty figure reached 5, 599, 699 individuals. The breach notification filed with the Maine Attorney General corroborated this exact number. The investigation revealed the attackers compromised seven out of 25, 000 servers. Those seven servers contained a massive repository of unstructured data.
The health system confirmed the attackers did not breach the primary electronic health record database. The distinction offers little comfort to the victims. The compromised network drives held spreadsheets, billing documents, and administrative files containing highly sensitive information. The data varied by individual. victims lost basic contact information. Others lost a complete profile of their medical and financial lives.
The stolen files contained government identification numbers. The attackers extracted Social Security numbers, tax identification numbers, passport numbers, and driver license numbers. The medical data included procedure codes, lab test types, dates of service, and medical record numbers. The financial data included bank account numbers and credit card details. The insurance data included Medicare numbers, Medicaid numbers, and policy details. The combination of these data points provides identity thieves with the exact materials required to open fraudulent credit accounts or submit fake medical claims.
Comparative Analysis of 2024 Healthcare Breaches
The Ascension breach represents a massive failure of data protection rules. The final casualty count places the event among the largest healthcare cyberattacks of the year. The federal portal recorded 677 data breaches affecting 500 or more healthcare records by December 19 2024. Those breaches compromised the protected health information of 182, 414, 703 individuals.
The Change Healthcare ransomware attack dominated the year with 100 million affected individuals. The Kaiser Foundation Health Plan tracking technology breach ranked second with 13. 4 million affected individuals. Ascension ranks third with 5. 6 million victims. The concentration of data within large multistate health systems creates highly lucrative for extortion groups. When a single network intrusion compromises 140 hospitals, the resulting data theft grows exponentially.
The financial damage extends beyond the cost of credit monitoring. Ascension reported a 1. 8 billion dollar operating margin loss for the fourth quarter of fiscal year 2024. The health system attributed of this loss to the ransomware incident. The organization incurred massive costs related to remediation efforts, business interruption, and external forensic consultants. The health system also faced severe revenue losses during the weeks when hospitals diverted ambulances and postponed elective procedures.
Tracking the Largest Healthcare Data Breaches of 2024
The following multicolored chart illustrates the top three healthcare data breaches reported to the federal portal in 2024. The data reflects the final casualty figures updated by the end of the calendar year.
| Healthcare Organization | Incident Type | Individuals Affected | Visual Representation |
|---|---|---|---|
| Change Healthcare | Ransomware | 100, 000, 000 | |
| Kaiser Foundation | Tracking Tech | 13, 400, 000 | |
| Ascension Health | Ransomware | 5, 599, 699 |
The visual representation demonstrates the massive size of the Change Healthcare breach compared to other major incidents. Yet the Ascension breach remains a catastrophic event for the 5. 6 million people whose data circulates among extortion groups. The health system offered victims a two year credit monitoring package. Individuals who signed up for the initial offering in July 2024 must register again for the new package arranged in December. The requirement to enroll again adds extra work for victims already navigating the threat of identity theft.
The federal reporting process exposes a structural flaw in how the public learns about medical data theft. The sixty day reporting window forces organizations to submit placeholder numbers. The public sees a minor incident affecting 500 people. The true damage remains hidden for months while forensic teams analyze server logs. By the time Ascension confirmed the 5. 6 million casualty figure in December, the initial shock of the May ransomware attack had faded from the daily news pattern. The victims received notification letters just days before the Christmas holiday. The delayed timeline benefits the breached organization by separating the operational chaos of the hospital diversions from the formal admission of massive data theft.
Ambulance Diversions in Michigan: Emergency Room Bottlenecks and Rerouted Critical Care
20 Questions Answered: Michigan Ambulance Diversions
To establish the facts of the Michigan emergency room bottlenecks, we answer twenty specific questions regarding the May 2024 events.
1. What forced Michigan Ascension hospitals to divert ambulances in May 2024? A ransomware attack severed access to electronic health records and diagnostic tools.
2. How Ascension hospitals operate in Michigan? The health system operates 15 hospitals across the state.
3. Which specific Detroit hospital diverted major heart attack patients? Ascension St John in Detroit rerouted severe cardiac cases to other facilities.
4. How long did cardiac arrest test results take during the downtime? Doctors waited 90 minutes for cardiac test results.
5. What is the normal wait time for those cardiac tests? These tests normally take 15 to 20 minutes.
6. How long did stroke patients wait for head CT scan results? Nurses reported waiting up to four hours for head CT scan results.
7. Which hospital canceled elective surgeries immediately following the breach? Ascension Borgess Hospital canceled elective surgeries.
8. What rule did Ascension Macomb Oakland Hospital activate on May 9? The hospital activated a diversion status to reroute arriving ambulances.
9. How did Ascension St John staff track patient census data? Administrators instructed staff to use Google Sheets to track patient locations.
10. What did a MedStar ambulance staff member say about Metro Detroit ERs? The staff member noted ambulances avoided Ascension emergency rooms unless the patient did not truly need an ambulance.
11. How long did a patient with a urinary tract infection wait for care? One patient waited 12 hours for treatment.
12. Why did the urinary tract infection patient wait so long? Hospital staff lost the patient urine sample four different times due to paper record errors.
13. What communication method replaced electronic orders in Detroit? Medical staff relied on fax machines to send and receive orders.
14. What did Ascension advise patients to bring to the emergency room? Officials asked patients to bring written lists of medications and symptoms.
15. Did Ascension close its emergency rooms to walk in patients? No, the emergency rooms remained open for walk in patients.
16. Which Ascension facility pharmacy staff member described the situation as a nightmare? A pharmacy worker at Ascension Providence in Novi used this description.
17. How did the breach affect diagnostic imaging? The outage delayed radiology scans and blocked access to historical imaging files.
18. What happened to outpatient appointments at Ascension Providence in Novi? outpatient procedures continued with minimal delays as staff used paper forms.
19. Did the diversion status apply to all 15 Michigan locations simultaneously? No, the diversion status fluctuated across different locations based on local volume.
20. How did emergency medical services triage patients during the outage? Ambulance crews communicated directly with emergency rooms to determine which facilities could accept specific severe cases.
Emergency Room Bottlenecks and Rerouted Care
The May 2024 ransomware attack forced 15 Ascension hospitals in Michigan into a state of operational paralysis. Medical staff lost access to the electronic health records system. This outage created immediate bottlenecks in emergency departments across Metro Detroit and the surrounding regions. Without digital charts, doctors and nurses reverted to paper records and fax machines to order tests and transmit prescriptions. The sudden shift to manual documentation caused severe delays in patient care.
At Ascension St John in Detroit, emergency room wait times spiked as staff struggled to process patients manually. One patient arrived with a urinary tract infection and waited 12 hours for treatment. Hospital workers lost her urine sample four different times because they could not track it electronically. In another case, doctors waited 90 minutes to receive test results for an older woman in cardiac arrest. These specific tests normally take 15 to 20 minutes to process. The absence of digital tracking meant laboratory technicians had to communicate results over the phone or deliver paper copies by hand.
The delays extended to diagnostic imaging. Nurses reported waiting up to four hours for head CT scan results for patients experiencing strokes or brain bleeds. The inability to quickly access these scans placed patients at serious risk. Without immediate imaging data, physicians could not administer time sensitive treatments. The manual record keeping system also created confusion. One nurse noted she could not verify if the blood test results she received actually belonged to her patient.
Ambulance Diversions Across Metro Detroit
As emergency rooms filled with waiting patients, hospital administrators activated diversion rules. This status instructs incoming ambulances to reroute to other healthcare facilities. On May 9, Ascension Macomb Oakland Hospital began diverting ambulances. Ascension St John in Detroit also diverted major heart attack patients to competing hospitals. The diversion status fluctuated across the 15 Michigan locations based on patient volume and staff capacity.
Emergency medical services adapted quickly to the bottlenecks. A MedStar ambulance staff member reported that crews largely avoided Ascension emergency rooms in the Metro Detroit area. Paramedics only transported patients to Ascension facilities if the individual did not require urgent medical intervention. Ambulance dispatchers maintained constant communication with hospital charge nurses to determine which facilities could safely accept new arrivals.
The cyberattack forced Ascension Borgess Hospital to cancel elective surgeries. At Ascension Providence in Novi, a pharmacy worker described the situation as a total nightmare. The pharmacy could not process electronic prescriptions or verify patient medication histories. To manage the chaos, administrators at Ascension St John instructed staff to use Google Sheets to track the number of patients in the hospital.
Data Verification: Wait Time Increases During the Outage
The transition to paper records drastically increased the time required to process standard medical procedures. The chart illustrates the verified delays for specific emergency services at Ascension St John during the week of the ransomware attack.
Emergency Service Processing Times: Normal vs Downtime
| Medical Service | Normal Processing Time | Downtime Processing Time |
|---|---|---|
| Cardiac Arrest Blood Tests | 15 to 20 Minutes | 90 Minutes |
| Head CT Scan Results | 45 to 60 Minutes | 4 Hours |
| Urinary Tract Infection Triage | 1 to 2 Hours | 12 Hours |
The data confirms a massive slowdown in clinical operations. A cardiac test that normally takes 20 minutes took 450 percent longer to complete. A head CT scan result took up to four times longer than standard operating procedures dictate. These metrics highlight the severe danger posed by the ransomware attack. When medical staff cannot access digital tools, the entire healthcare delivery system grinds to a halt.
Patient Instructions and Manual Workarounds
Ascension officials urged patients to avoid the emergency department if they could safely travel to a different hospital network. For those who had to visit an Ascension facility, administrators asked them to bring written notes detailing their symptoms. Patients also needed to provide a physical list of their current medications and the names of their primary care doctors. Without the electronic health record, physicians had no way to verify a patient medical history or check for dangerous drug interactions.
The manual method required all hands on deck to manage the paperwork. Nurses physically ran between departments to deliver urgent messages. Physicians wrote prescriptions on standard paper pads, which required patients to physically carry the documents to external pharmacies. Even with these efforts, the sheer volume of patients overwhelmed the paper based system. The absence of automated alerts meant doctors had to manually calculate medication dosages and double check for allergies, a process that consumed valuable time during emergency situations.
Michigan Healthcare Under Siege: The Broader Threat
The Ascension breach represents part of a larger pattern of cyberattacks attacking Michigan healthcare providers. Prior to the May 2024 event, hackers attacked other major regional networks. In late 2023, a ransomware attack disabled the computer systems at McLaren Health Care. That breach affected 14 Michigan hospitals and exposed the data of 2. 5 million patients. Corewell Health, the largest hospital system in the state, also faced recent cyber intrusions. These repeated attacks demonstrate that medical infrastructure remains a prime mark for extortion groups.
The operational downtime caused by these attacks directly harms patients. A recent Ponemon Institute report established a direct link between hospital ransomware attacks and negative patient outcomes. The data shows that cyberattacks increase mortality rates and cause a spike in medical complications. Separate research indicates a 33 percent increase in death rates per month for hospitalized Medicare patients during active cyberattacks. When hospitals divert ambulances and delay diagnostic tests, the quality of care drops immediately.
The Ascension pharmacy closures created another severe danger for Michigan residents. As of May 21, 2024, the health system paused retail pharmacy operations across multiple states, including Michigan. Patients could not fill new prescriptions or access their medication histories. This failure forced individuals to seek out competing pharmacies, those external locations could not access the Ascension electronic health records to verify dosages. The breakdown in communication left older adults without their necessary heart and blood pressure medications.
The Michigan bottlenecks demonstrate the fragility of modern healthcare networks. A single point of failure in the digital system compromised patient safety across 15 hospitals. The ambulance diversions pushed the patient load onto competing health systems, which created secondary delays throughout the region. The May 2024 cyberattack proves that digital security directly affects physical health outcomes.
Wichita and Pensacola EMS Gridlock: How Regional Paramedics Navigated the May 2024 Blackout

Wichita and Pensacola EMS Gridlock: How Regional Paramedics Navigated the May 2024 Blackout
On May 8, 2024, the Ascension health system detected unauthorized activity on its network. Administrators severed external connections to contain the ransomware attack. The decision forced 140 hospitals into immediate downtime. The blackout pushed the problem onto the streets. Paramedics in Sedgwick County, Kansas, and Escambia County, Florida, faced sudden gridlock as major medical centers shut their digital doors. Emergency medical services had to reroute patients on the fly. The sudden shift forced paramedics to calculate transport times and bed availability without digital integration.
20 Questions Answered: The Details of the EMS Diversion
To establish the factual baseline of the regional emergency response, we answer twenty primary questions regarding the ambulance diversions in Wichita and Pensacola.
| Question | Verified Answer |
|---|---|
| 1. Which Wichita hospital diverted ambulances on May 8, 2024? | Ascension Via Christi. |
| 2. What trauma designation does Ascension Via Christi hold? | Level 1 trauma center. |
| 3. How Level 1 trauma centers operate in Wichita? | Two. |
| 4. Which agency manages emergency transport in Wichita? | Sedgwick County EMS. |
| 5. Which Pensacola hospital initiated diversion procedures? | Ascension Sacred Heart. |
| 6. Which agency manages emergency transport in Pensacola? | Escambia County EMS. |
| 7. What triggered the ambulance diversions? | A ransomware attack that took electronic health records offline. |
| 8. How did paramedics communicate with receiving hospitals? | Via radio and manual phone calls. |
| 9. What specific medication error was narrowly avoided in Wichita? | A nurse almost gave a baby the wrong narcotic dose. |
| 10. Why did the medication error almost occur? | Staff relied on confusing paper records instead of automated digital safeguards. |
| 11. Did Ascension facilities close their emergency rooms entirely? | No. They diverted specific ambulance traffic accepted walk-in patients. |
| 12. How do ambulance diversions affect regional healthcare? | They increase transport times and push volume to adjacent hospitals. |
| 13. What alternative systems did EMS use for routing? | Manual dispatch procedures and regional staging plans. |
| 14. How long did the acute diversion phase last? | Several weeks as systems were slowly restored. |
| 15. Did the blackout affect outpatient clinics in these regions? | Yes. Appointments were postponed or delayed. |
| 16. What digital patient portal went offline? | MyChart. |
| 17. How did the blackout impact medication administration? | It disabled barcode scanning and automated dosing alerts. |
| 18. Were non-elective surgeries canceled? | Most proceeded with longer wait times due to manual documentation. |
| 19. How did the attack affect inter-hospital transfers? | It complicated the electronic exchange of patient records. |
| 20. What is the standard EMS procedure for a Level 1 trauma center blackout? | Reroute severe trauma cases to the nearest available equivalent facility. |
The Sedgwick County Response: Rerouting Trauma in Wichita
Ascension Via Christi operates as one of only two Level 1 trauma centers in Wichita. The facility handles the most severe medical emergencies in Sedgwick County. When the Black Basta ransomware attack hit on May 8, hospital administrators lost access to the electronic systems that track patient care, order tests, and manage bed capacity. The hospital immediately notified Sedgwick County EMS to divert incoming ambulance traffic.
Paramedics suddenly had to bypass a primary destination for severe injuries. Sedgwick County EMS dispatchers manually rerouted ambulances to the only other Level 1 trauma center in the city. The sudden influx of diverted patients tested the capacity of the receiving facility. Transport times increased as ambulances traveled further distances to drop off patients. The diversion forced paramedics to rely on radio communications to verify bed availability instead of using automated digital dashboards. The absence of real-time data meant EMS crews had to call ahead manually to ensure the alternate hospitals could accept their patients. This extra step consumed valuable minutes during life-or-death emergencies.
Inside Ascension Via Christi, the transition to paper records created serious safety risks. Medical staff lost access to automated dosing alerts and barcode scanning systems. These digital safeguards normally prevent medication errors. Nurse Marvin Ruckle reported a near-miss incident during the blackout. He stated that he almost administered the wrong dose of a narcotic to a baby because of confusing paper documentation. The absence of electronic health records forced doctors and nurses to manually verify every prescription and treatment order. This manual verification process slowed down patient care and increased wait times across the facility.
Escambia County EMS: Navigating the Pensacola Blackout
A similar scenario unfolded in Pensacola, Florida. Ascension Sacred Heart Hospital serves as a primary medical hub for Escambia County. The May 8 cyberattack severed the hospital from its electronic health records and diagnostic systems. Administrators enacted emergency downtime procedures and notified Escambia County EMS about the disruption.
Escambia County EMS initiated ambulance diversion plans for specific medical cases. Paramedics had to evaluate patients in the field and determine if Ascension Sacred Heart could safely handle their conditions without digital imaging or electronic lab results. patients were diverted to other hospitals in the Pensacola area. The diversion required constant communication between EMS commanders and hospital triage staff. Paramedics used manual tracking methods to monitor which facilities had available space.
The blackout extended beyond the emergency room. Ascension Sacred Heart had to postpone certain medical tests and procedures. Patients lost access to the MyChart portal. They could no longer communicate with their doctors online or view their test results. The hospital continued to accept walk-in patients, the manual registration process created bottlenecks in the waiting areas. Doctors could not electronically transmit prescriptions to local pharmacies. They had to handwrite every medication order. This manual step introduced new risks for transcription errors and delayed patients from receiving their necessary treatments.
Data Analysis: The Impact of Ambulance Diversions
Ambulance diversions create a cascading effect on regional healthcare networks. When a major hospital stops accepting EMS traffic, the surrounding facilities must absorb the excess volume. We compiled data on the operational impact of the Ascension ransomware attack across the affected regions.
| Metric | Wichita (Ascension Via Christi) | Pensacola (Ascension Sacred Heart) |
|---|---|---|
| Date of Initial Diversion | May 8, 2024 | May 8, 2024 |
| Trauma Designation | Level 1 | Regional Medical Center |
| Primary EMS Agency | Sedgwick County EMS | Escambia County EMS |
| Systems Offline | EHR, MyChart, Pharmacy | EHR, MyChart, Diagnostics |
| Reported Safety Incidents | Narcotic dosing near-miss | Delayed diagnostic testing |
The Root Cause: A Single Malicious File
The massive disruption in Wichita and Pensacola traced back to a single point of failure. In June 2024, Ascension confirmed that the attack began when an employee accidentally downloaded a malicious file. The organization stated that the employee thought the file was legitimate. This action allowed the Black Basta ransomware group to infiltrate the network and deploy their encryption software.
The attackers gained access to seven servers used by associates for daily tasks. These servers contained files with protected health information and personally identifiable information. In December 2024, Ascension reported to federal regulators that the breach exposed the data of 5. 6 million people. The compromised information included Social Security numbers, medical procedure codes, payment details, and insurance information. The exposure of this data places millions of patients at risk for identity theft and financial fraud. Cybersecurity experts note that stolen medical records frequently appear on the dark web for sale to other criminal organizations. The attackers can use the stolen information to extract money from victims through sophisticated phishing campaigns.
The financial toll of the cyberattack was severe. Ascension posted a 1. 1 billion dollar net loss for the 2024 fiscal year. The organization noted that the cyberattack significantly reduced its financial performance. The cost of hiring third-party cybersecurity experts, implementing manual procedures, and managing the from the ambulance diversions all contributed to the massive financial deficit.
Restoring Operations and Patient Trust
Ascension hired Mandiant to assist with the investigation and remediation process. The cybersecurity firm worked to safely restore the electronic health records and patient portals. The recovery process took weeks. During this time, paramedics in Sedgwick and Escambia counties continued to navigate the logistical challenges of the ambulance diversions.
As systems slowly came back online, hospitals resumed normal EMS traffic. The transition back to digital records required staff to manually enter weeks of paper documentation into the electronic system. This backlog created additional administrative work for nurses and doctors who were already exhausted from operating in downtime mode.
Ascension began mailing notification letters to the 5. 6 million affected individuals in December 2024. The organization offered two years of free credit monitoring to victims. The data breach ranks as the third-largest reported to the federal healthcare data breach portal in 2024. The incident exposes the weakness of regional healthcare networks to cyber threats. A single malicious file paralyzed 140 hospitals, forced ambulances to reroute, and pushed medical staff to the brink of serious safety errors.
The Paper Chart Reversion: Manual Documentation Risks and Delayed Diagnostic Imaging
The Immediate Shift to Manual Documentation
On May 8, 2024, the Black Basta ransomware attack severed access to the MyChart electronic health record platform across 140 Ascension hospitals. Medical staff lost all digital communication tools. The network outage forced doctors and nurses to abandon modern medical infrastructure and revert to pen and paper. This sudden transition created a serious patient safety problem. Without digital guardrails, the risk of medical errors multiplied. Care teams relied on handwritten notes, basic spreadsheets, and phone calls to manage patient treatments. The sign of trouble at Ascension Via Christi St. Francis Hospital in Wichita appeared when breakfast orders failed to process through the computer network. By the end of that day, the entire hospital had reverted to manual operations.
20 Questions Answered: The Paper Chart Reversion
To establish the factual baseline of this medical documentation emergency, we answer twenty primary questions regarding the manual workflow transition.
1. What forced the paper chart reversion? The May 2024 Black Basta ransomware attack disabled the electronic health record system.
2. How long did the electronic outage last? The system remained offline for roughly one month across the network.
3. Which primary system went dark? The MyChart electronic health record platform became completely inaccessible.
4. How did nurses record patient important? Staff wrote all patient assessments and important by hand on paper forms.
5. What happened to medication scanning? The barcode scanning system used to verify drug doses went offline.
6. Did the absence of scanning cause problems? Yes. Nurses reported multiple near misses with incorrect medication doses.
7. How did doctors order prescriptions? Physicians wrote paper prescriptions for nurses to enter manually into dispensing machines.
8. Did the pharmacy cross-check these manual orders? No. Nurses had to use a system override to bypass standard pharmacy verifications.
9. How did the outage affect lab results? Bloodwork and other lab results took hours to reach the attending physicians.
10. Did delayed labs cause patient harm? Yes. One patient went into cardiac arrest and died after a four hour wait for lab results.
11. How did the attack alter diagnostic imaging? CT scans and MRI machines could not transmit digital files to doctors.
12. How long did head CT scans take to process? Patients at Ascension St. John Hospital in Detroit waited hours for head CT results.
13. What risks did delayed CT scans pose? The delays increased the danger for patients suffering from strokes or brain bleeds.
14. How did staff track medical records? Workers used paper charts and basic spreadsheets to manage patient data.
15. Did paper charting create duplication errors? Yes. Staff accidentally duplicated unique medical record numbers on paper.
16. How patients did nurses manage during the outage? nurses handled five or six patients simultaneously while managing paper charts.
17. Did the union take action? The Office and Professional Employees International Union Local 40 petitioned for safety fixes.
18. What did the union demand? They demanded a maximum of four patients per nurse until the network recovered.
19. How did staff communicate without computers? Care teams relied on phone calls and physical runners to deliver information.
20. Did veteran nurses help newer staff? Yes. Experienced nurses taught newer colleagues how to properly format and cross out paper charts.
Medication Errors and the Absence of Digital Guardrails
The absence of electronic verification systems created a dangerous environment for medication administration. Before the cyberattack, nurses used barcode scanners to match the correct drug and dosage to the patient wristband. The ransomware attack eliminated this safety net. Nurses had to decipher handwritten doctor orders and manually calculate dosages.
This manual process led to severe near misses across multiple states. At Ascension Via Christi St. Joseph in Kansas, neonatal intensive care nurse Marvin Ruckle almost administered the wrong dose of a narcotic to a baby due to confusing paper records. At Ascension Saint Agnes Hospital in Baltimore, intensive care nurse Melissa LaRue nearly gave a patient a dangerously incorrect dose of blood pressure medication. At Ascension Via Christi St. Francis in Wichita, intensive care nurse Lisa Watson caught a medication error just in time. Watson stated her patient probably would have passed away had she not noticed the gap.
The manual workflow also bypassed standard pharmacy safety checks. Doctors wrote paper prescriptions. Nurses then carried these slips to automated dispensing machines. Because the machines could not communicate with the central pharmacy software, nurses had to use a manual override function to extract the drugs. This process removed the pharmacist from the verification chain. The Office and Professional Employees International Union Local 40 in Michigan petitioned Ascension Providence Rochester Hospital to implement emergency safety measures. The union gathered signatures from 116 medical professionals demanding a strict limit of four patients per nurse to mitigate the dangers of paper charting. The union also demanded unit shift huddles to ensure communication and weekly progress reports from Ascension leadership.
Diagnostic Imaging Delays and Fatal Consequences
The ransomware attack paralyzed the diagnostic imaging infrastructure. Modern hospitals rely on digital networks to transmit high resolution CT scans and MRI images from the radiology department to the attending physicians. The Black Basta intrusion severed these connections. Technicians could still operate the scanning machines, yet they could not send the results electronically.
Hospital staff resorted to burning imaging files onto physical CDs. Runners then carried these discs across the hospital to the doctors. This physical transport method added hours to the diagnostic process. At Ascension St. John Hospital in Detroit, patients waited hours to receive the results of serious head CT scans. These delays proved highly dangerous for patients suffering from strokes or brain bleeds, where every minute dictates the chance of survival or permanent brain damage. An emergency room nurse at an Illinois Ascension facility reported that patients waited two to three times longer to get stat results for blood clots.
The physical transport of CDs created a massive bottleneck. In a modern emergency room, doctors review scans on high definition monitors within minutes of the procedure. During the Ascension outage, doctors waited for a runner to physically hand them a disc. They then had to find a computer with a functioning disc drive to view the images. This archaic process delayed surgical interventions and prolonged patient suffering.
Laboratory test delays also resulted in tragic outcomes. Without the electronic health record system, bloodwork and other essential lab tests required manual processing and physical delivery. In one documented case, a female patient waited four hours for essential lab results. During this waiting period, she went into cardiac arrest and died. The breakdown of digital communication directly compromised the ability of the medical staff to deliver timely life saving care. The reliance on paper also caused administrative chaos. Staff accidentally duplicated unique medical record numbers on handwritten forms. This duplication created a severe risk of mixing up patient histories and test results.
Quantifying the Operational Slowdown
The transition to manual documentation drastically reduced hospital efficiency. The following chart illustrates the estimated time increases for standard medical procedures during the Ascension network downtime compared to normal electronic operations.
Procedure Time Increases During Ascension Network Downtime (May 2024)
| Medical Procedure | Normal Electronic Time | Paper Charting Time | Visual Comparison |
|---|---|---|---|
| Medication Verification | 2 Minutes | 15 Minutes | |
| Lab Result Delivery | 15 Minutes | 240 Minutes | |
| CT Scan Result Routing | 10 Minutes | 120 Minutes | |
| Patient Assessment Charting | 5 Minutes | 25 Minutes |
Data reflects reported delays from nursing staff at Ascension facilities in Michigan, Kansas, and Illinois.
The load on Nursing Staff
The cyberattack placed an immense physical and mental load on the nursing staff. newer nurses had never worked in a hospital without electronic health records. Veteran nurses had to conduct rapid training sessions during their shifts to teach the younger staff how to properly document important on paper. They instructed newer nurses to cross out the empty sections of the paper page to prevent unauthorized additions to the medical record. This manual process required intense concentration to avoid mistakes.
Staffing ratios became a serious safety hazard. Under normal conditions, a nurse might safely manage five patients using digital tools. With the added time required for manual charting, managing five or six patients became unmanageable. Nurses reported doing three times the work in double the time. The exhaustion and stress of deciphering handwriting and manually calculating dosages pushed the workforce to the breaking point. The reliance on paper charts demonstrated that modern hospital operations cannot function safely without their underlying digital infrastructure. The sheer volume of paperwork overwhelmed the nursing stations. Binders filled with handwritten notes replaced the streamlined digital monitors. Every patient transfer required a physical handoff of the paper chart. If a doctor needed to review a patient history, they had to locate the physical binder rather than pulling up the file on a tablet.
The communication breakdown extended beyond the hospital walls. Ambulances arriving at the emergency department frequently brought patients with complex medical histories. Without access to the electronic health records, triage nurses had to rely entirely on the patient or their family members to recite their medical background and current prescriptions. This verbal history collection introduced another of chance error into the treatment process.
MyChart Blackout: Millions of Patients Blocked from Electronic Health Records and Test Results

The Epic EHR and MyChart Severance
On May 8, 2024, Ascension detected unauthorized network activity and intentionally severed external connections to its electronic health record system and the patient facing MyChart portal. The decision locked medical staff out of digital patient histories, medication lists, and real time lab results across 140 hospitals in 19 states and the District of Columbia. Patients lost all digital communication with their doctors. They could not view test results, request prescription refills, or check upcoming appointments.
20 Questions Answered: The MyChart Blackout Mechanics
1. When did the MyChart blackout begin? May 8, 2024.
2. How patient records were exposed? 5, 599, 699.
3. Which patient portal went offline? MyChart.
4. How hospitals lost access to digital records? 140.
5. Across how states did the blackout occur? 19 states and Washington D. C..
6. When did Ascension officially announce the restoration of EHR access? June 14, 2024.
7. How long did the primary digital blackout last? Approximately six weeks.
8. What charting method replaced the electronic system? Manual pen and paper charting.
9. How were lab results transmitted during the downtime? Via fax machines and hand delivery,.
10. Did the blackout affect prescription refills? Yes, retail pharmacies could not process electronic prescriptions or credit cards.
11. Were elective surgeries canceled immediately? No, multiple facilities proceeded with elective procedures, prompting safety warnings from nursing staff.
12. What specific patient safety risk emerged in the NICU? Confusing paper records nearly led to a narcotic dosing error in Wichita, Kansas.
13. Could patients message their doctors during the blackout? No, the MyChart portal was completely severed.
14. Were historical medical records accessible to emergency room staff? No, doctors absence access to allergies, histories, and previous test results.
15. What happened to data collected during the six week downtime? It required manual backloading after systems came back online.
16. Did the breach involve the theft of patient data? Yes, hackers exfiltrated files containing protected health information.
17. Which federal agency received the breach notification? The Department of Health and Human Services Office for Civil Rights.
18. What financial damage did the cyberattack cause Ascension? The network posted a $1. 1 billion net loss for the 2024 fiscal year.
19. Did the blackout affect ambulance routing? Yes, multiple facilities initiated emergency medical services diversion.
20. What caused the initial network breach? An employee accidentally downloaded a malicious file.
Clinical Operations Revert to Paper
The sudden loss of the electronic health record system forced a complete regression to manual workflows. Doctors and nurses documented patient care on paper forms pulled from storage. Without digital routing, staff hand delivered orders for bloodwork, imaging, and medications to the respective departments. Hospitals deployed downtime procedures equipped with preassembled patient charts and standardized documentation.
The transition to paper charting introduced immediate risks to patient safety. Nurses who had spent their entire careers using digital systems suddenly had to navigate detailed multipage paper forms. Connie Smith, a charge capture coordinator and head of the Wisconsin Federation of Nurses and Health Professionals, stated that staff were using forms pulled out of drawers that had not seen the light of day in a long time. The absence of familiarity with these analog documents slowed down every aspect of patient care.
The reliance on paper and fax machines created severe logistical bottlenecks. Kris Fuentes, a neonatal intensive care unit nurse at Ascension Seton Medical Center in Austin, Texas, stated that the workflow became unorganized and chaotic. She noted that the hospital operated as if it had gone back twenty years, without the analog tools that existed two decades ago. Staff members acted as physical runners, carrying handwritten notes across massive hospital complexes.
At Ascension Providence in Rochester, Michigan, nurses reported that fax machines produced a constant stream of paper. Lab and imaging results, which indicate life threatening conditions like heart attacks or brain bleeds, were frequently misplaced or routed to the wrong department. Blood and urine samples were lost in transit between the emergency room and the laboratory.
Even with the digital blackout, hospital administrators at several locations chose to proceed with elective surgeries. Nursing staff at Ascension Providence warned that patients were entering operating rooms before their preoperative lab results were completed. Dina Carlisle, president of OPEIU Local 40, which represents registered nurses at the facility, stated that the volume of elective surgeries did not slow down, creating serious safety risks.
Medication Errors and Near Misses
The absence of digital safety checks removed the automated safeguards that prevent adverse drug interactions and dosing errors. In a standard electronic workflow, the system alerts a nurse if a prescribed medication conflicts with a patient allergy profile or if the dosage exceeds safe limits.
During the Ascension blackout, these safeguards disappeared. Marvin Ruckle, a neonatal intensive care unit nurse with two decades of experience at Ascension Via Christi St. Joseph in Wichita, Kansas, reported a near miss involving an infant. Ruckle stated that confusing handwritten paperwork made it difficult to decipher the correct dosage on the medication record, nearly resulting in the administration of the wrong dose of a narcotic. He noted that such an event had never occurred while the hospital operated on the computerized system.
Without the electronic health record system, doctors could not instantly verify a patient medical history. Patients arriving at the emergency room had to recount their entire medical background, including detailed medication regimens and past surgeries, from memory. If a patient arrived unconscious or unable to communicate, emergency room physicians had to make urgent treatment decisions without any historical data. This information vacuum forced doctors to order redundant tests, further overloading the already backlogged laboratory and imaging departments.
Retail pharmacies within the Ascension network also suffered. Pharmacists could not access electronic prescriptions or process credit card payments. Patients faced extended delays for essential medications. Providers frequently instructed patients to pay in cash or routed prescriptions to unaffiliated regional pharmacies via telephone and fax.
Data Backlog and System Restoration
Ascension announced the systemwide restoration of its electronic health records and the MyChart portal on June 14, 2024. The recovery process took approximately six weeks.
The restoration of the network did not immediately resolve the clinical data gap. Medical staff had generated millions of paper records between May 8 and mid June. Administrators faced the massive logistical task of manually scanning and backloading six weeks of handwritten charts, lab results, and physician notes into the system. During this transition period, data collected during the downtime remained inaccessible to providers attempting to review a patient recent medical history.
On December 19, 2024, the Department of Health and Human Services Office for Civil Rights updated its data breach portal. The update confirmed that the Black Basta ransomware attack compromised the records of 5, 599, 699 individuals. The stolen data included personal details, medical information, payment data, insurance details, and Social Security numbers. Hackers exfiltrated this protected health information before deploying the ransomware payload. The exposure of such detailed personal data forced Ascension to offer credit monitoring and identity theft protection services to the affected individuals. The notification process extended into late December 2024, leaving patients unaware of their data exposure for months.
The financial damage of the blackout extended beyond the immediate loss of revenue from canceled procedures. Ascension had to hire third party cybersecurity firms, deploy additional staffing to handle the manual data entry, and manage the logistical nightmare of restoring 25, 000 servers,. The $1. 1 billion net loss reported for the 2024 fiscal year demonstrated the severe economic consequences of a prolonged digital blackout in the healthcare sector. Also, Ascension faces multiple class action lawsuits from patients whose protected health information was exposed during the breach.
Timeline and Impact Metrics
The following table details the verified timeline and operational metrics of the Ascension MyChart and electronic health record blackout.
| Metric / Event | Verified Data |
|---|---|
| Initial Breach Detection | May 8, 2024 |
| Systems Severed | Epic EHR, MyChart Portal, Pharmacy Processing |
| Hospitals Affected | 140 facilities across 19 states and Washington D. C. |
| Patient Records Exposed | 5, 599, 699 individuals |
| EHR Restoration Date | June 14, 2024 |
| Total Downtime | Approximately 6 weeks |
| Financial Damage | $1. 1 billion net loss (FY 2024) |
Pharmacy System Failures: Paper Scripts and the Halt on Prescription Refills
Core Incident Parameters: 20 Questions Answered
To establish the factual baseline of the pharmacy system failure, we answer twenty primary questions regarding the operational mechanics and patient safety metrics during the Ascension cyberattack.
| # | Operational Query | Verified Data Point |
|---|---|---|
| 1 | When did the Ascension pharmacy network go offline? | The network went offline on May 8, 2024. |
| 2 | Which specific pharmacy division halted operations? | The Ascension Rx division halted all operations. |
| 3 | Could Ascension retail pharmacies process credit card payments? | No, the payment processing systems failed entirely. |
| 4 | Were new prescriptions filled at Ascension Rx locations during the downtime? | No, pharmacists could not process new medication orders. |
| 5 | How did patients obtain new medications? | Doctors issued paper scripts for patients to take to external pharmacies. |
| 6 | What workaround existed for patients running out of medications? | Ascension pharmacies provided short term supplies using existing prescription bottles. |
| 7 | Did the outage affect home delivery pharmacy services? | Yes, the home delivery network went completely offline. |
| 8 | Were specialty pharmacy sites operational during the breach? | No, specialty pharmacy locations could not dispense medications. |
| 9 | How did the outage affect controlled substance prescriptions in Illinois? | It forced a complete reversion to handwritten paper scripts. |
| 10 | What legal mandate did the Illinois paper scripts bypass? | The January 1, 2024 state mandate requiring electronic prescriptions for controlled substances. |
| 11 | Did the cyberattack impact hospitals no longer owned by Ascension? | Yes, the attack impacted sold facilities still using the IT network. |
| 12 | Which former Ascension hospital experienced pharmacy failures? | Guthrie Lourdes Hospital in Binghamton, New York. |
| 13 | When did Ascension acquire Guthrie Lourdes? | Guthrie acquired Lourdes from Ascension in February 2024. |
| 14 | What was the primary safety concern with handwritten medication records? | Illegible handwriting leading to incorrect dosing by nurses. |
| 15 | What historical medical error case did nurses reference regarding the paper records? | The 2022 criminal conviction of Tennessee nurse RaDonda Vaught. |
| 16 | When did Ascension restore electronic health record access? | The health system restored access in mid June 2024. |
| 17 | How did hospital staff transmit lab results for medication orders? | Staff used pneumatic tubes and hand delivery methods. |
| 18 | Did the outage block access to patient medication histories? | Yes, doctors could not view previous prescriptions or contraindications. |
| 19 | Could patients use the MyChart portal to request refills? | No, the MyChart patient portal remained offline for weeks. |
| 20 | Did the pharmacy failure cause emergency department delays? | Yes, patients waited up to 12 hours for basic medication administration. |
The Collapse of Electronic Prescribing
On May 8, 2024, the Black Basta ransomware attack severed the digital connection between Ascension physicians and the Ascension Rx pharmacy network. The breach disabled the electronic health record system. Doctors lost the ability to transmit prescriptions electronically. The outage forced 140 hospitals across 19 states to revert to manual prescribing methods. Medical staff could no longer access patient medication histories or verify contraindications through the digital portal.
The sudden halt on electronic prescribing created immediate operational bottlenecks. Physicians resorted to writing paper scripts for all new medication orders. The transition to pen and paper introduced serious patient safety risks. Nurses and pharmacists had to decipher handwritten medication records. One nurse at an Ascension facility noted that it was hard to decipher the correct dose on the paper medication records. Medical staff expressed fear that the manual processes could lead to fatal dosing errors. Multiple healthcare workers referenced the 2022 criminal conviction of Tennessee nurse RaDonda Vaught as a worst case scenario for medication administration errors.
Ascension Rx Retail and Specialty Pharmacy Paralysis
The cyberattack paralyzed the Ascension Rx network. Retail pharmacies, home delivery services, and specialty pharmacy sites went offline. Ascension pharmacies in states like Michigan and Kansas could not process new prescriptions. The payment processing systems also failed. Pharmacy staff could no longer accept credit cards for copayments or over the counter medications.
Ascension management directed patients to take their paper scripts to outside pharmacies. The health system issued public notices asking patients to request that their doctors send prescriptions to different pharmacy networks while the IT department worked to restore the systems. For patients who could not access an external pharmacy, Ascension offered a limited workaround. Pharmacists provided short term medication supplies to patients who brought in their current prescription bottles. This manual verification process caused long lines and delayed the dispensing of maintenance medications.
Regulatory Waivers and Regional Impacts
The reversion to paper scripts forced regulatory adjustments in several states. In Illinois, a state law enacted on January 1, 2024, mandated that all healthcare professionals submit prescriptions for controlled substances electronically. The Ascension cyberattack made compliance impossible. The Illinois State Medical Society advised physicians that they qualified for a temporary technological failure exemption. Pharmacists across Illinois received notices from the Department of Financial and Professional Regulation to accept and fill the paper prescriptions for controlled substances.
The pharmacy failures extended beyond facilities directly owned by Ascension. Guthrie Lourdes Hospital in Binghamton, New York, experienced identical pharmacy outages. The Guthrie health system officially acquired Lourdes from Ascension in February 2024. The IT transition remained incomplete when the ransomware attack occurred in May. Guthrie Lourdes pharmacies remained open could not fill prescriptions. Hospital administrators directed patients to call their doctors for paper scripts or have their medications routed to outside pharmacies. The Lourdes outpatient labs closed, and the emergency department diverted ambulances to other facilities as the medication and testing delays multiplied.
Emergency Department Medication Delays
The absence of electronic pharmacy systems directly degraded emergency room operations. Emergency department physicians rely on rapid blood test results to prescribe accurate antibiotic dosages and administer lifesaving medications. The May 2024 ransomware attack forced hospital staff to process these orders manually. Medical personnel printed lab results on paper. Staff members then hand delivered these documents or sent them through pneumatic tubes to the pharmacy and the emergency department.
This manual routing caused severe treatment delays. At Ascension St. John in Detroit, an emergency room doctor reported that a patient with a urinary tract infection waited 12 hours to receive care because the hospital lost the physical urine sample four different times. In another case at the same facility, physicians waited 90 minutes to receive test results for an older woman in cardiac arrest. These tests normally take 15 to 20 minutes to process using the electronic health record system. The delays in receiving lab results meant that pharmacists could not verify or dispense emergency medications in a timely manner.
The load on External Retail Pharmacies
The shutdown of the Ascension Rx network forced thousands of patients to seek their medications at external retail pharmacies. Ascension instructed patients to ask their doctors to send prescriptions to different pharmacy networks. This sudden influx of paper prescriptions overwhelmed independent and competing chain pharmacies in regions where Ascension holds a large market share, such as Michigan and Kansas.
External pharmacists had to manually enter the paper scripts into their systems. They could not access the Ascension electronic health records to verify patient histories, check for drug interactions, or confirm previous dosages. The absence of digital records forced external pharmacists to rely on the physical prescription bottles brought in by patients. If a patient did not have their old bottle, the external pharmacy had to call the prescribing doctor to verify the medication details. The Ascension phone systems also experienced intermittent outages during the cyberattack. These communication failures made it nearly impossible for external pharmacists to reach Ascension doctors for prescription verification.
Pharmacy Restoration Timeline
| Date | Operational Status | System Impact |
|---|---|---|
| May 8, 2024 | Total Shutdown | Ascension Rx retail, home delivery, and specialty pharmacies go offline. Electronic prescribing fails. |
| May 13, 2024 | Paper Workarounds | Ascension advises patients to request paper scripts and use external pharmacies. |
| May 15, 2024 | Short Term Refills | Pharmacies begin offering short term supplies using old prescription bottles. Credit cards remain disabled. |
| Mid June 2024 | System Restoration | Electronic health records and Ascension Rx pharmacy sites resume normal operations. |
The pharmacy downtime lasted for more than a month. Ascension IT consultants and external cybersecurity firms worked through May and early June to rebuild the network infrastructure. Ascension Rx retail, home delivery, and specialty pharmacy sites slowly resumed operations in mid June 2024. The health system confirmed the restoration of electronic health record access across its ministries by the third week of June.
The prolonged reliance on paper based systems exposed the fragility of modern hospital pharmacy operations. Without the electronic health record, hospital staff had to print lab results, copy them manually, and send them to different hospital units via pneumatic tubes. The manual routing of test results delayed the administration of targeted medications. The May 2024 cyberattack demonstrated that the loss of electronic prescribing capabilities directly degrades patient safety and halts the delivery of basic medical care.
Delayed Surgeries and Missed Mammograms: The Human Cost of Elective Procedure Postponements

20 Questions Answered: The Clinical Impact of the Cyberattack
| Question | Verified Fact |
|---|---|
| 1. When did the Ascension cyberattack begin? | May 8, 2024. |
| 2. How hospitals were affected? | 140 hospitals across 19 states and the District of Columbia. |
| 3. What electronic health record system went offline? | The MyChart system and internal electronic health records. |
| 4. Did hospitals divert ambulances? | Yes. Facilities in Wichita, Pensacola, and Detroit diverted emergency medical services. |
| 5. Were elective surgeries canceled? | Yes. Ascension Borgess Hospital in Kalamazoo canceled scheduled elective procedures. |
| 6. How much did daily surgeries drop at Ascension Borgess? | The daily surgical volume dropped from 30 to 40 cases down to exactly 7 cases. |
| 7. Did patients miss cancer screenings? | Yes. Patients in Milwaukee reported missing scheduled mammograms and computed tomography scans. |
| 8. How long did it take to restore electronic health records? | It took approximately 37 days to fully restore the electronic health records system. |
| 9. How much did the response cost Ascension? | The health system spent about $130 million on the cyberattack response. |
| 10. What was the operating revenue loss for fiscal year 2024? | Ascension lost approximately $0. 9 billion in operating revenue. |
| 11. What was the total operating loss for fiscal year 2024? | The total operating loss reached $1. 8 billion. |
| 12. Did medication errors occur during the downtime? | Yes. Medical staff reported multiple near misses and actual medication errors. |
| 13. What happened to a Detroit emergency room patient? | A man received the wrong narcotic due to a paperwork mixup and was put on a ventilator. |
| 14. Did any patients die while waiting for care? | A woman in a Michigan emergency room died after waiting four hours for lab results. |
| 15. What happened in the Wichita neonatal intensive care unit? | A nurse nearly gave a baby the wrong dose of a narcotic because of confusing paper records. |
| 16. How long did a urinary tract infection patient wait for care? | One patient waited 12 hours because the hospital lost her urine sample four times. |
| 17. How long did cardiac arrest test results take? | Physicians waited 90 minutes for test results that normally take 15 to 20 minutes. |
| 18. Did the attackers steal patient data? | Yes. Attackers stole files from seven of the 25, 000 servers on the network. |
| 19. What group executed the ransomware attack? | The Black Basta cybercriminal group executed the attack. |
| 20. Did Ascension employees petition for safety changes? | Yes. Over 100 staff members at Ascension Providence Rochester Hospital signed a petition seeking a reduction in elective surgeries. |
The Immediate Clinical Paralysis
The May 8, 2024 cyberattack forced Ascension into an immediate operational blackout. Medical staff lost access to the MyChart electronic health record system. Doctors and nurses reverted to paper charts. This transition created a serious danger to patient safety. The absence of digital safety checks removed the automated warnings that prevent medication errors.
Emergency rooms across the country descended into chaos. Ambulances arriving at Ascension facilities faced immediate diversions. In Wichita, Kansas, local emergency medical services diverted all ambulance calls away from Ascension hospitals. The emergency medical services in Pensacola, Florida, also routed patients to competing facilities. In the Metro Detroit area, ambulance crews avoided Ascension emergency departments unless the patient did not require urgent transport.
Wait times inside the hospitals multiplied. At Ascension St. John in Detroit, one patient with a urinary tract infection waited 12 hours for treatment because staff lost her urine sample four times. Physicians at the same facility waited 90 minutes to receive test results for an older woman in cardiac arrest. Those specific tests normally require 15 to 20 minutes. A family medicine nurse reported an inability to access radiology scans for a patient experiencing shortness of breath. The medical team had no way to verify the condition of the patient’s lungs.
Medication Errors and Fatalities
The shift to handwritten notes and manual orders caused severe medical mistakes. At an Ascension hospital in Detroit, a man received a dangerous narcotic intended for another patient because of a paperwork mixup. The medication slowed his breathing. Medical staff had to intubate him and place him on a ventilator in the intensive care unit.
In another Michigan Ascension emergency room, a woman with low blood sugar went into cardiac arrest and died. Staff members reported waiting four hours for lab results needed to determine her treatment plan. The results never arrived.
The danger extended to severely ill patients. Marvin Ruckle, a nurse in the neonatal intensive care unit at Ascension Via Christi St. Joseph in Wichita, reported a near miss. He almost administered the wrong dose of a narcotic to a baby because the handwritten medication record was confusing. Lisa Watson, an intensive care unit nurse at Ascension Via Christi St. Francis in Wichita, nearly gave the wrong medication to a severely ill patient because the barcode scanning system was offline.
Canceled Surgeries and Missed Screenings
The cyberattack forced the postponement of elective procedures and routine diagnostic tests. Ascension Borgess Hospital in Kalamazoo, Michigan, canceled scheduled elective surgeries. A nurse at the facility reported that the daily surgical volume dropped from a normal range of 30 to 40 cases down to exactly 7 cases.
Patients in Milwaukee, Wisconsin, reported missing scheduled mammograms and computed tomography scans. The inability to access electronic records meant technicians could not verify orders or transmit images to physicians. Eduardo Conrado, President of Ascension Healthcare, confirmed that imaging teams could not send scans to surgeons waiting in operating rooms. The hospital relied on runners to deliver printed copies of the scans by hand.
The prolonged downtime prompted medical staff to demand safety interventions. More than 100 staff members at Ascension Providence Rochester Hospital signed a petition. The document requested a temporary reduction in elective surgeries and non emergent admissions. The staff sought to alleviate the pressure on resources and prioritize care for patients requiring urgent attention.
The Administrative Workload of Manual Documentation
The transition to paper records created a towering administrative workload. Restoring operations took 37 days. During this period, the backlog of paper records grew to a massive volume. Medical staff had to write notes by hand and deliver orders for tests and prescriptions in person. The physical movement of paper across large hospital campuses slowed medical care to a crawl.
Nurses reported that their workflow became unorganized and chaotic. A nurse in Kalamazoo stated that she had to teach resident physicians how to use physical order forms. Younger doctors had never practiced medicine without an electronic health record. The absence of digital patient histories meant doctors did not know what medications patients were taking. Patients arriving at the emergency room frequently did not know their full medical history or the exact names of their prescriptions. Ascension instructed patients to bring physical prescription bottles and handwritten notes on their symptoms to their appointments.
Pharmacy Disruptions and Patient Anxiety
The cyberattack paralyzed Ascension pharmacies. The digital systems used to transmit and fill prescriptions went offline. Patients could not obtain necessary medications. The inability to process electronic payments forced individuals enrolled in Ascension health insurance plans to mail in monthly payments.
The patient portal shutdown caused widespread anxiety. Patients could not access their medical histories or schedule appointments online. The communication channels between patients and their doctors disappeared. The health system advised patients to seek care at competing hospitals if they had the option. A doctor at Ascension St. John in Detroit publicly stated that wait times would be twice as long and advised patients to go elsewhere.
The Data Breach Confirmation
The attackers did not just encrypt the systems. They also extracted sensitive information. Ascension confirmed that the cybercriminals stole files from seven of the 25, 000 servers on the network. The stolen files contained protected health information and personally identifiable information. The health system engaged federal law enforcement and reported the breach to the Department of Health and Human Services Office for Civil Rights on July 26, 2024.
The attackers used a double extortion method. They locked the hospital systems to disrupt operations and stole data to demand a ransom. The Black Basta ransomware gang executed the attack after an Ascension employee accidentally downloaded a malicious file. The single click compromised the entire network.
Widespread Paralysis Across 19 States
The geographic footprint of the cyberattack spanned 19 states and the District of Columbia. The disruption affected 140 hospitals and 40 senior care facilities. The sheer size of the Ascension network magnified the severity of the event. The health system attends to 3. 1 million emergency visits and 349, 000 urgent care visits annually. The sudden loss of digital infrastructure across such a massive patient population created a public health emergency.
The organization initiated downtime procedures across all facilities. Clinicians relied on their training to provide care without digital assistance. The reality of operating a modern hospital on paper proved far more difficult than anticipated. The intricate coordination required for surgeries, diagnostic imaging, and intensive care relies entirely on instantaneous data transmission. The cyberattack severed those digital arteries.
The recovery process required immense effort. Cybersecurity experts worked continuously to contain the breach and rebuild the servers. The health system slowly brought systems back online over a six week period. The electronic health records system returned to normal operation on June 14, 2024. The staff then faced the monumental task of entering 37 days of handwritten medical notes into the restored digital system.
The Financial Toll of the Cyberattack
The operational disruption inflicted a massive financial penalty on the nonprofit health system. Ascension spent approximately $130 million on its immediate response to the cyberattack. The organization hired the cybersecurity firm Mandiant to investigate the breach and rebuild the network infrastructure.
The inability to process billing and the widespread cancellation of elective procedures devastated the revenue operations. Ascension lost approximately $0. 9 billion in operating revenue by the end of fiscal year 2024. The health system posted a $1. 8 billion operating loss for the fiscal year. The cyberattack erased the financial progress the organization had made in the months prior to May 2024.
Surgical Volume Drop at Ascension Borgess
The following chart illustrates the severe reduction in daily surgical procedures at Ascension Borgess Hospital following the ransomware attack.
Daily Surgical Cases at Ascension Borgess (May 2024)
Before Attack Maximum
After Attack Volume
Data Source: Verified staff reports from Ascension Borgess Hospital, Kalamazoo, Michigan.
The 60-Day HIPAA Notification Loophole: Why Ascension Used a 500-Patient Placeholder Estimate
The 60 Day HIPAA Notification Loophole: Why Ascension Used a 500 Patient Placeholder Estimate
The Health Insurance Portability and Accountability Act Breach Notification Rule mandates that healthcare organizations report unsecured protected health information exposures to the Department of Health and Human Services Office for Civil Rights within 60 days of discovery. When the May 8, 2024 ransomware attack disabled operations across 140 Ascension hospitals, administrators faced a strict July deadline to file their federal disclosure. Because forensic teams had not finished auditing the exfiltrated files, Ascension submitted a placeholder estimate of 500 affected individuals. This specific number acts as the minimum threshold required to trigger an official entry on the federal breach portal. The public faced a seven month information vacuum before Ascension updated the portal on December 19, 2024, to reflect the verified total of 5, 599, 699 compromised patient records.
Core Incident Parameters: 20 Questions Answered on the HIPAA Placeholder
1. What is the federal reporting deadline for healthcare data breaches? The mandate requires notification within 60 days of discovery.
2. Why do hospitals submit a 500 patient estimate? Organizations use this number to meet the 60 day federal deadline when forensic investigations remain incomplete.
3. What was the initial patient count Ascension reported to the federal government? Ascension reported exactly 500 individuals in July 2024.
4. What was the final verified number of affected patients? The final audit confirmed 5, 599, 699 compromised records.
5. When did Ascension update the federal portal with the true number? The organization submitted the revised total on December 19, 2024.
6. How much time passed between the initial attack and the final patient count? Seven months elapsed before the public learned the true scope.
7. Did Change Healthcare use this exact reporting tactic? Yes. Change Healthcare initially reported 500 patients before updating their total to 100 million individuals.
8. How much data did the Black Basta operators claim to steal from Ascension? The attackers claimed to exfiltrate 1. 4 terabytes of data.
9. How servers did Ascension confirm were compromised? Investigators determined the hackers breached seven out of 25, 000 servers.
10. What federal agency manages the public breach portal? The Department of Health and Human Services Office for Civil Rights maintains the database.
11. What happens if a hospital misses the 60 day deadline? Organizations face financial penalties from state attorneys general and federal regulators.
12. Does the 500 patient placeholder trigger public media notification? Yes. Breaches affecting 500 or more residents require immediate media notice.
13. Why do organizations avoid using 499 as a placeholder? Breaches under 500 records are only reported annually and do not trigger immediate public posting.
14. How healthcare data breaches in 2024 used the 500 or 501 placeholder? At least 64 organizations filed placeholder reports during the calendar year.
15. What rank did the Ascension breach take in the 2024 totals? The incident became the third largest healthcare data breach of the year.
16. Who ranked and second in 2024? Change Healthcare ranked with 100 million records, and Kaiser Foundation Health Plan ranked second with 13. 4 million records.
17. How long is the credit monitoring offered to Ascension victims? The health system provides two years of credit monitoring from the enrollment date.
18. When did Ascension begin mailing the final notification letters? The organization initiated the mailing process in late December 2024.
19. Did the attackers access the primary electronic health record system? Ascension stated the hackers did not access the core electronic health records.
20. What specific patient data was stolen? The exfiltrated files contained names, addresses, dates of birth, Social Security numbers, and medical record numbers.
The Mechanics of the 500 Patient Placeholder
Federal regulations require covered entities to notify the Secretary of Health and Human Services without unreasonable delay following a breach. The 60 day window forces large hospital networks to submit documentation before forensic auditors can process terabytes of compromised data. Submitting a report for 500 individuals satisfies the legal requirement to notify the government and the media. The Office for Civil Rights publishes these initial figures on its public portal. This regulatory structure creates a prolonged period where patients, investors, and regulators operate with artificially low metrics.
The Black Basta operators infiltrated the Ascension network on May 8, 2024. The attackers utilized a malicious file downloaded by an employee to gain initial access. They moved laterally across the network and compromised seven servers. The ransomware gang exfiltrated 1. 4 terabytes of data to a server named ftp8 before deploying the encryption payload. Ascension severed external network connections to contain the damage. The 60 day clock started immediately. By July 2024, Ascension filed the 500 patient placeholder. The true of the data theft remained hidden from the public until the December 19 update.
Comparative Analysis: Major 2024 Healthcare Breaches Using the Placeholder
Ascension was not the only organization to use this reporting method in 2024. The tactic is standard practice among enterprise healthcare providers facing massive ransomware incidents. The table details the largest healthcare breaches of 2024 that utilized the 500 patient placeholder estimate before revealing the final verified metrics.
| Healthcare Entity | Initial Placeholder Count | Final Verified Count | Months Between Reports |
|---|---|---|---|
| Change Healthcare | 500 | 100, 000, 000 | 8 Months |
| Ascension Health | 500 | 5, 599, 699 | 7 Months |
| WebTPA | 500 | 2, 429, 175 | 2 Months |
Change Healthcare submitted a 500 patient estimate to the federal portal in July 2024 following their February ransomware attack. The company later confirmed the breach compromised the records of 100 million Americans. WebTPA utilized the same strategy before confirming their breach affected over 2. 4 million individuals. At least 64 data breaches in 2024 were reported using placeholder estimates of 500 or 501 records.
The Timeline Delay: From May to December
The seven month gap between the Ascension network intrusion and the final patient notification creates distinct vulnerabilities for the affected individuals. The exfiltrated data included Social Security numbers, bank account details, and medical record numbers. Cybercriminals monetize this information rapidly on dark web forums. The Black Basta operators utilize double extortion tactics. They encrypt the host network and threaten to publish the stolen data unless the victim pays a ransom.
Ascension retained third party cybersecurity firms to audit the 1. 4 terabytes of stolen files. The forensic teams had to manually review the unstructured data to identify the specific patients involved. This process required matching fragmented data points across multiple databases to build an accurate notification list. Ascension announced the completion of this review on December 19, 2024. The hospital system began mailing physical notification letters to the 5, 599, 699 victims in late December. Delivery of these letters extended into January 2025.
Patients remained unaware of their specific exposure status during the seven month audit period. Ascension offered a preliminary credit monitoring package in July 2024. The organization introduced a revised two year credit monitoring package in December 2024. Patients who enrolled in the July program had to register a second time to receive the full two year benefit.
Regulatory Impact and State Attorney General Responses
The reliance on placeholder estimates complicates regulatory oversight. State attorneys general rely on accurate breach data to initiate consumer protection investigations. The federal portal displayed the 500 patient figure for Ascension from July until December. This delay prevents state authorities from understanding the true density of affected residents within their jurisdictions.
The Office for Civil Rights enforces the Breach Notification Rule. The agency problem financial penalties for organizations that fail to notify patients and the media within the 60 day window. By filing the 500 patient placeholder, Ascension technically complied with the federal deadline. The organization submitted an interim report to satisfy the legal requirement while the forensic audit continued.
The 2024 data breach statistics demonstrate the widespread use of this reporting method. The federal portal recorded 703 large healthcare data breaches by early January 2025. The total number of affected individuals exceeded 182 million. The Ascension incident accounted for 5. 59 million of those records. The hospital network posted a 1. 8 billion dollar operating loss for the 2024 fiscal year. The ransomware attack caused severe revenue pattern disruptions and delayed claims submissions. The financial damage compounded the operational paralysis experienced across the 140 hospitals.
The Breach Notification Rule includes specific provisions for media outreach. When a data breach affects more than 500 residents of a specific state or jurisdiction, the healthcare provider must notify prominent media outlets serving that area. The organization must distribute a press release detailing the compromised data types and the mitigation steps. Ascension issued public statements regarding the cyberattack in May 2024. The initial press releases confirmed the network intrusion omitted the exact number of affected patients. The 500 patient placeholder submitted to the federal government in July satisfied the technical reporting requirement without revealing the true magnitude of the event to the press.
The 60 day reporting rule forces a compromise between speed and accuracy. Healthcare providers must alert the public quickly. Forensic investigators require months to analyze terabytes of exfiltrated data. The 500 patient placeholder this gap. The practice leaves millions of patients uninformed about their specific data exposure while cybercriminals actively exploit the stolen information.
Mandiant’s Intervention: Investigating the Phishing Entry Point and Network Shutdown Protocols

Mandiant Deployment and Initial Network Isolation
On May 8, 2024, Ascension detected unauthorized activity across its technology infrastructure. Administrators immediately initiated network shutdown procedures to contain the threat. The health system severed external connections and instructed business partners to detach from the Ascension environment. This immediate isolation forced clinical staff to abandon digital workflows. Doctors and nurses transitioned to paper records and fax machines to process lab orders and prescriptions. The disruption caused severe delays in patient care. Nurses at Ascension St. John Hospital in Detroit reported waiting four hours to receive head CT scan results for patients experiencing strokes. Several facilities diverted ambulances to competing hospitals to manage the operational load.
Ascension engaged Mandiant to lead the forensic investigation. Mandiant operates as a subsidiary of Google Cloud and specializes in cyber incident response. Investigators worked to identify the entry point and map the lateral movement of the attackers. The forensic team analyzed system logs to determine the exact boundaries of the data exfiltration. The security experts needed to ensure the intruders no longer had active access to the internal network before administrators could begin the rebuilding process.
The immediate containment strategy required shutting down the primary communication channels. The health system disabled the MyChart patient portal. Patients could no longer view their medical histories or communicate with their physicians electronically. The hospital network also took internal phone systems offline. Staff members resorted to using personal cell phones to coordinate care between different departments. The sudden loss of digital connectivity transformed modern hospitals into paper based operations overnight.
20 Questions Answered: The Investigation and Shutdown Mechanics
We answer twenty specific questions regarding the Mandiant investigation, the entry point, and the network shutdown procedures.
- Who did Ascension hire to investigate the May 2024 cyberattack? Ascension hired Mandiant.
- What is Mandiant? Mandiant is a cybersecurity firm owned by Google Cloud.
- How did the attackers gain initial access to the Ascension network? An employee downloaded a malicious file.
- Did the employee act with malicious intent? Ascension stated the action was an honest mistake.
- What type of file did the employee believe they were downloading? The employee thought the file was a legitimate document.
- How servers did the attackers compromise? The attackers accessed seven servers.
- What is the total number of servers in the Ascension network? The network contains approximately 25, 000 servers.
- What kind of data resided on the compromised servers? The servers contained Protected Health Information and Personally Identifiable Information.
- Did the attackers breach the primary Electronic Health Records system? Investigators found no evidence that attackers extracted the core EHR databases.
- Which ransomware group executed the attack? The Black Basta ransomware gang executed the intrusion.
- When did Ascension detect the unusual network activity? Administrators detected the activity on May 8, 2024.
- What immediate action did Ascension take upon detecting the breach? The health system shut down network systems to contain the spread.
- What instruction did Ascension give to its business partners? Ascension advised partners to temporarily disconnect from its network.
- How did the network shutdown affect clinical operations? Medical staff lost access to digital records and used paper documentation.
- How did the shutdown impact diagnostic imaging? Staff reported waiting up to four hours for CT scan results.
- Were emergency services affected by the network isolation? Several hospitals diverted ambulances to other facilities.
- Did the attackers deploy double extortion tactics? Black Basta uses double extortion methods.
- What is double extortion? Attackers steal sensitive data before encrypting the local files.
- Which federal agencies received notification about the breach? Ascension notified the FBI, CISA, and the Department of Health and Human Services.
- When did Ascension begin restoring EHR access in certain markets? The health system started restoring EHR access on June 5, 2024.
The Phishing Entry Point and Server Compromise
The Mandiant investigation revealed the exact method of the breach. An individual working at an Ascension facility downloaded a malicious file. The employee believed the file was legitimate. This single action granted the attackers a foothold inside the corporate network. The intruders used this initial access to move laterally across the infrastructure. The attackers bypassed standard security filters by disguising the malware as a routine business document.
The attackers navigated the network and located file servers used by employees for daily tasks. Mandiant determined that the hackers successfully extracted data from seven specific servers. These seven machines represent a tiny fraction of the 25, 000 servers operating within the Ascension network. Even with the small number of compromised machines, the extracted files contained Protected Health Information and Personally Identifiable Information. The attackers exfiltrated this sensitive data before deploying the encryption malware.
Black Basta operates as a Russian speaking cybercrime syndicate. The group emerged in early 2022 and frequently the healthcare sector. Black Basta uses double extortion methods. The syndicate steals data and demands one ransom to decrypt the locked files and a second ransom to prevent the public release of the stolen information. The Health Information Sharing and Analysis Center issued an alert on May 10, 2024, warning that Black Basta had accelerated attacks against healthcare organizations. The federal government also published joint advisories detailing the specific tactics used by this ransomware group.
Clinical Impact of the Network Isolation
The decision to sever network connections protected the broader infrastructure caused serious disruptions to patient care. The MyChart patient portal went offline. Electronic prescribing systems stopped functioning. Pharmacies across Alabama, Florida, Illinois, Indiana, Kansas, Michigan, Oklahoma, Texas, Wisconsin, and Washington D. C. could not process electronic orders. Patients had to bring physical prescription bottles to their appointments so doctors could manually call the pharmacies.
Nurses and doctors faced severe operational obstacles. A travel nurse at Ascension St. Vincent Hospital in Indiana reported that the facility descended into pure chaos. Medical staff could not access patient histories or verify medication dosages electronically. The reliance on manual processes increased the risk of medical errors. At Ascension Providence Rochester Hospital in Michigan, unionized healthcare workers signed a petition demanding management address the safety problems caused by the absence of electronic medical records. The staff expressed deep concern over their inability to track patient treatments accurately.
The network shutdown also paralyzed diagnostic departments. Radiology technicians could not transmit imaging files to attending physicians. Doctors had to physically walk to the radiology department to view films. The delays in processing laboratory tests and imaging results directly impacted emergency triage. The widespread failure forced Ascension to pause elective procedures across multiple states. The hospital administration prioritized urgent care while operating under severe technical constraints.
Infrastructure Compromise Metrics
The following chart illustrates the size of the server infrastructure and the targeted nature of the data exfiltration.
Ascension Server Infrastructure vs. Compromised Servers
Total Network Servers
Compromised Servers
Data Source: Ascension Cybersecurity Event Updates (May 2024)
Recovery and Remediation Efforts
Ascension and Mandiant worked to rebuild the network architecture. The recovery process required a thorough validation of every system before reconnection. The health system held regular meetings with vendors to coordinate the safe restoration of external links. The IT department had to clean and verify thousands of endpoints to ensure the Black Basta malware was completely eradicated.
The recovery timeline extended for weeks. During this period, the hospital network faced mounting pressure from both medical staff and patients. The inability to access historical medical records meant that physicians had to rely entirely on the information provided by patients during their visits. Ascension instructed patients to bring physical notes detailing their symptoms and a complete list of their current medications. This manual verification process slowed down intake procedures and created large bottlenecks in emergency departments.
By June 5, 2024, Ascension began restoring EHR access in select markets, including Florida, Alabama, and Tennessee. The organization set a target to restore the entire electronic health record system by June 14, 2024. The phased rollout allowed the technical teams to monitor the network for any signs of recurring malicious activity. The restoration of the EHR system marked a major milestone in returning the hospitals to normal operations.
The investigation confirmed that the attackers stole files containing sensitive patient information. Ascension initiated an extensive data review to identify the specific individuals affected by the breach. The health system offered complimentary credit monitoring and identity theft protection services to patients and employees. On July 26, 2024, Ascension officially reported the ransomware attack to the Office for Civil Rights as a data breach. The organization began mailing individual notification letters to affected patients in December 2024.
The financial toll of the cyberattack and the subsequent operational downtime remains substantial. Ascension reported over $28 billion in revenue during its most recent fiscal year also recorded billions in operating losses. The costs associated with hiring Mandiant, deploying credit monitoring services, and rebuilding the IT infrastructure add heavy financial pressure to the nonprofit organization. The incident also triggered at least one class action lawsuit from patients concerned about the exposure of their personal data.
The Mandiant investigation exposes the severe weaknesses present in healthcare networks. A single downloaded file bypassed perimeter defenses and triggered a catastrophic operational failure. The resulting network shutdown protected the core databases created a serious patient safety problem. The event demonstrates how threat actors use social engineering to penetrate large organizations and deploy encryption malware. The financial and operational damages incurred by Ascension reflect the growing threat of ransomware syndicates targeting the medical sector.
December 2024 OCR Portal Update: Cementing the Third-Largest Healthcare Data Breach of the Year
20 Core Incident Parameters Answered
To establish the factual baseline of the December 2024 regulatory updates and the final data exposure metrics, we answer twenty primary questions regarding the breach reporting process.
| 1. When did Ascension update the OCR portal? | December 19, 2024. |
| 2. What was the initial placeholder figure? | 500 individuals. |
| 3. What is the final confirmed number of affected patients? | 5, 599, 699. |
| 4. Where does this rank among 2024 healthcare data breaches? | Third largest. |
| 5. Which breach was the largest in 2024? | Change Healthcare. |
| 6. How records did the Change Healthcare breach expose? | Approximately 100 million. |
| 7. Which breach was the second largest in 2024? | Kaiser Foundation Health Plan. |
| 8. How records did the Kaiser breach expose? | 13. 4 million. |
| 9. When did Ascension begin mailing notification letters? | Late December 2024. |
| 10. How long did Ascension estimate the notification process would take? | Two to three weeks. |
| 11. What credit monitoring service did Ascension offer? | A new two year package. |
| 12. Do patients who enrolled in July 2024 need to register again? | Yes. |
| 13. What personal data did hackers steal? | Names, addresses, and birth dates. |
| 14. What medical data was compromised? | Medical record numbers, test types, and procedure codes. |
| 15. What financial data was exposed? | Credit card and bank account numbers. |
| 16. Did the breach include government identification numbers? | Yes, Social Security numbers and driver license numbers. |
| 17. How total healthcare records were breached in 2024? | Approximately 275 million. |
| 18. How large healthcare data breaches occurred in 2024? | 725 incidents. |
| 19. Did Ascension experience a separate breach involving a business partner? | Yes. |
| 20. How patients were affected by the business partner breach? | 437, 329. |
The December 2024 OCR Portal Update
On December 19, 2024, Ascension updated its official data breach report on the Department of Health and Human Services Office for Civil Rights portal. The health system replaced its initial July 2024 placeholder estimate of 500 individuals with the final verified count of 5, 599, 699 affected patients. This revision cemented the May 2024 Black Basta ransomware attack as the third largest healthcare data breach of the year.
The Health Insurance Portability and Accountability Act requires covered entities to notify affected individuals without unreasonable delay. The law mandates notification no later than 60 days following the discovery of a breach. Ascension submitted the initial report in July 2024 to comply with this federal deadline. Organizations frequently use a 500 record placeholder when forensic investigations remain incomplete at the reporting deadline. Ascension spent seven months working with third party specialists to review the exfiltrated files and identify the specific patients involved.
The health system stated only seven of its 25, 000 servers were compromised in the ransomware attack. This limited server compromise still resulted in the exposure of 5. 6 million records. The Missouri based health system operates 140 hospitals in 19 states and the District of Columbia.
On December 20, 2024, Ascension notified the Maine Attorney General in a regulatory filing that the attack compromised the personal information of 5. 6 million individuals. The filing noted the initial intrusion occurred on February 29, 2024. Administrators detected the unauthorized access on May 8, 2024. The initial access vector involved an employee accidentally downloading a malicious file disguised as legitimate software. Ascension provided a one million dollar insurance reimbursement policy and identity theft recovery services for the affected individuals.
The 2024 Healthcare Data Breach Context
The Ascension breach ranks behind two other massive data compromises reported in 2024. The Change Healthcare ransomware attack exposed the records of approximately 100 million individuals. The Kaiser Foundation Health Plan tracking technology breach compromised 13. 4 million records.
Top 3 Healthcare Data Breaches of 2024 by Records Exposed
The Office for Civil Rights recorded 725 large healthcare data breaches in 2024. These incidents exposed approximately 275 million patient records. This volume of exposed records affected 82 percent of the United States population. The 2024 total represents a 63. 5 percent increase from the 168 million records breached in 2023.
Hacking and IT incidents accounted for 81. 2 percent of reported breaches in 2024. These 589 incidents exposed at least 259 million healthcare records. The average size of a hacking incident in 2024 was 439, 796 records. The Ascension breach exceeded this average by a factor of twelve. Other major breaches in 2024 included HealthEquity with 4. 3 million records and Concentra Health Services with 3. 9 million records. Centers for Medicare and Medicaid Services reported 3. 1 million records breached. Acadian Ambulance Service reported 2. 8 million records breached.
Network servers remained the most common location for breaches of protected health information in 2024. Email accounts followed as the second most common location with 169 incidents. Unauthorized access and disclosure incidents nearly doubled in exposed records from 8. 4 million in 2023 to 16. 1 million in 2024. The healthcare sector relies heavily on interconnected systems and third party business associates. This reliance creates multiple vulnerability points across the supply chain. When business associates experience breaches, multiple covered entities suffer simultaneous impacts.
Data Exposed and the Notification Process
Ascension confirmed the completion of its data review in a December 19, 2024 public update. The health system began mailing individual notification letters to the 5. 6 million affected patients. Administrators estimated the mailing process would take two to three weeks. This timeline meant patients received their notification letters in January 2025.
The compromised files contained a wide range of protected health information. Hackers obtained personal details including names, addresses, and dates of birth. The stolen medical data included medical record numbers, laboratory test types, dates of service, and procedure codes. The breach exposed financial information such as credit card data and bank account numbers. Hackers also acquired government identifiers including Social Security numbers, tax identification numbers, passport numbers, and driver license numbers.
The compromised insurance details included policy numbers, Medicare identification numbers, Medicaid identification numbers, and insurance claim information. The notification letters detailed these specific exposures for the affected patients. The process of identifying the exact data elements required extensive forensic analysis. The third party specialists worked for months to parse the exfiltrated databases. The delay between the May 2024 discovery and the December 2024 notification left millions of patients unaware of their specific risk exposure for seven months.
Ascension offered affected individuals a new credit monitoring package valid for two years from the enrollment date. This package differed from the initial credit monitoring service offered in July 2024. Patients who registered for the earlier service had to register again to receive the full two year protection. The health system stated it could not identify the specific types of information affected for every single individual.
The Secondary Business Partner Breach
Ascension faced a separate data exposure incident that became public in 2025. On May 12, 2025, Ascension notified the Office for Civil Rights that a breach at a former business partner affected 437, 329 patients. Ascension learned of the hacking incident on December 5, 2024.
An investigation concluded on January 21, 2025. Ascension determined it had inadvertently disclosed patient data to the former business partner. Hackers exploited a vulnerability in third party software used by the business partner to steal the data between July 17, 2024, and August 6, 2024. The compromised information included names, Social Security numbers, medical record numbers, and clinical information related to inpatient visits. Ascension confirmed its own internal systems remained unaffected by this specific secondary intrusion.
When disclosing the secondary data breach, Ascension stated the information pertained to its locations in Alabama, Michigan, Indiana, Tennessee, and Texas. The law firm Scharnhorst Ast Kennard Griffin reported a related incident to the Office for Civil Rights involving 639 individuals. Access Telecare reported a breach involving 62, 669 individuals. Restorix Health notified the Office for Civil Rights that a breach involved 38, 553 individuals. These interconnected breaches demonstrate the cascading effects of third party software vulnerabilities.
Industry observers linked the secondary Ascension patient data breach to the Clop ransomware group. The group exploited a zero day vulnerability in software by enterprise software developer Cleo in late 2024. The security flaw allowed attackers to remotely execute code and steal files from organizations using the software. Other organizations affected by Cleo related data breaches included Western Alliance Bank and Hertz. Ascension offered two years of free credit monitoring and identity restoration assistance to those affected by this secondary data breach.
Two-Year Credit Monitoring Mandates: Analyzing the Remediation Rollout for 5.6 Million Compromised Records
Remediation and Legal Accountability: 20 Questions Answered
To establish the factual baseline of the data exposure and subsequent legal actions, we answer twenty primary questions regarding the remediation process.
| Question | Verified Fact |
|---|---|
| 1. How patient records did the May 2024 ransomware attack expose? | 5, 599, 699 records. |
| 2. When did Ascension officially notify the affected individuals? | December 19, 2024. |
| 3. What specific demographic data fields did the hackers access? | Names, addresses, phone numbers, email addresses, dates of birth, and Social Security numbers. |
| 4. What clinical data did the attackers steal? | Medical record numbers, billing codes, lab tests ordered, and procedure codes. |
| 5. Did the breach compromise full electronic health records? | No, the attackers accessed specific network files rather than the primary medical record databases. |
| 6. Which cybersecurity firm managed the credit monitoring enrollment? | IDX. |
| 7. How long does the free identity theft protection last? | Two years from the date of enrollment. |
| 8. What was the enrollment deadline for the IDX monitoring service? | April 4, 2025. |
| 9. What insurance coverage did the IDX membership include? | A one million dollar identity theft insurance policy. |
| 10. How individuals were affected by the secondary third party breach? | 437, 329 individuals. |
| 11. When did Ascension discover the secondary business partner breach? | December 5, 2024. |
| 12. When did investigators confirm the secondary data exposure? | January 21, 2025. |
| 13. Which law firm was involved in the secondary data exposure? | Scharnhorst Ast Kennard Griffin. |
| 14. What software vulnerability caused the secondary breach? | A zero day flaw in the Cleo file transfer platform. |
| 15. How Texas residents were impacted by the secondary breach? | 114, 692 residents. |
| 16. Did Ascension face class action lawsuits over the data exposures? | Yes, courts consolidated multiple complaints into a nationwide class action lawsuit. |
| 17. Which federal judge presided over the consolidated class action lawsuit? | Judge John Ross. |
| 18. In what judicial district was the lawsuit filed? | The United States District Court for the Eastern District of Missouri. |
| 19. What financial loss did Ascension report for the 2024 fiscal year? | A 1. 1 billion dollar net loss. |
| 20. What net income did the health system report in 2025? | 917. 7 million dollars. |
The 5. 6 Million Record Notification
On December 19, 2024, Ascension concluded its internal file review and formally announced the scope of the data exposure. The health system confirmed that the May 2024 ransomware attack compromised the protected health information of 5, 599, 699 patients. This figure established the incident as the third largest healthcare data breach reported in the United States for 2024,. The attackers accessed specific files on the network servers rather than the primary electronic health record databases,. The stolen data included names, addresses, phone numbers, email addresses, dates of birth, and Social Security numbers. The hackers also obtained clinical information such as medical record numbers, billing codes, lab tests ordered, and procedure codes,. Ascension disclosed these details in a formal filing with the Maine Attorney General. The organization stated that it could not determine exactly which data elements were stolen from each specific individual,. Third party cybersecurity experts assisted the health system in identifying the affected population and preparing the notification registry. The delay between the May attack and the December notification drew scrutiny from privacy advocates and affected patients who waited months to understand their personal risk.
The IDX Credit Monitoring Mandate
Ascension contracted with IDX to manage the identity protection rollout for the affected population. The health system mailed notification letters to patients starting in late December 2024,. The correspondence included unique enrollment codes for a two year membership in the IDX identity theft protection program,. The service provided single bureau credit monitoring, dark web surveillance, and a one million dollar identity theft insurance policy,. Patients had until April 4, 2025, to activate their memberships. The enrollment required individuals to have an established credit history. Ascension directed patients to a dedicated website and a toll free assistance line to process the registrations. The health system advised patients to monitor their bank statements and request annual credit reports from the three major consumer reporting agencies. Representatives instructed patients to report any suspicious activity directly to the Federal Trade Commission. The organization also allowed patients who previously signed up for temporary monitoring in July 2024 to register again for this complete two year package. The logistics of enrolling over five million people required massive call center support and dedicated server capacity to handle the web traffic.
The Secondary Third Party Data Exposure
While managing the aftermath of the May ransomware attack, Ascension discovered a separate data exposure involving a former business partner. On December 5, 2024, the health system learned that a third party experienced a hacking incident,. Ascension investigators determined on January 21, 2025, that the health system had inadvertently disclosed patient data to this partner,. Hackers exploited a zero day vulnerability in the Cleo file transfer software used by the partner to steal the information,. This secondary breach affected 437, 329 individuals across Alabama, Michigan, Indiana, Tennessee, and Texas,. The compromised data mirrored the primary breach and included Social Security numbers, insurance company names, and clinical visit details,. The law firm Scharnhorst Ast Kennard Griffin was named in connection with this specific data exposure. Ascension mailed separate notification letters for this incident in April 2025 and offered another two years of complimentary credit monitoring to this specific group,. The health system reported this separate breach to the Department of Health and Human Services Office for Civil Rights. This additional security failure forced Ascension to review its vendor management policies and implement stricter data retention rules.
Class Action Litigation and Judicial Rulings
Patients filed multiple lawsuits against Ascension immediately following the May 2024 cyberattack,. The courts consolidated these complaints into a nationwide class action lawsuit in the United States District Court for the Eastern District of Missouri,. The plaintiffs alleged that Ascension failed to maintain proper security measures and protect patient information,. The lawsuit claimed the health system violated industry standards and federal guidelines. Ascension filed a motion to dismiss the case,. The health system asserted that the plaintiffs suffered no actual injury and therefore held no standing to sue,. In September 2025, Judge John Ross denied the motion to dismiss the entire lawsuit,. The judge ruled that the risk of future injury from the exposed personal information provided sufficient grounds for the negligence claims to proceed. The court dismissed specific breach of contract claims allowed the core consumer protection allegations to advance to the discovery phase. The ruling established a legal precedent for holding healthcare organizations accountable for downstream data exposures. The litigation process required Ascension to preserve all internal communications and forensic reports related to the Black Basta intrusion.
Financial Impact and Recovery Metrics
The cyberattack inflicted severe financial damage on the health system during the 2024 fiscal year. Ascension recorded a 1. 1 billion dollar net loss for the year. The losses stemmed from delayed revenue pattern processes, business interruption, and direct remediation costs. The health system spent millions on cybersecurity forensic experts, legal counsel, and the IDX credit monitoring services. The organization also faced increased operational costs from running 140 hospitals on manual paper processes during the system downtime. Even with these expenses, Ascension stabilized its operations in the following months. For the fiscal year ending June 30, 2025, the organization reported a net income of 917. 7 million dollars. The return to profitability demonstrated the financial resilience of the hospital network after absorbing the heavy costs of the ransomware recovery and the subsequent data breach notifications. The financial turnaround allowed the health system to continue its clinical operations without permanently closing any of its core medical facilities. Executives credited the recovery to aggressive cost management and the rapid restoration of the electronic billing systems.


































