Overview of the Ascension Health Cyberattack
In a significant digital security breach, Ascension Health fell victim to a cyberattack on its network systems this week. The US’ largest network of Catholic hospitals has suffered interruptions to daily operations and patient care as a result, with patients checking themselves out to seek healthcare elsewhere.
Cybersecurity Event Detected

Impact of the Cyberattack on Ascension Health

Ascension Health Only the Latest Healthcare Organization Attacked
As CISA and other organizations have warned previously, healthcare
UnitedHealth and Change Healthcare
Last week, UnitedHealth Group CEO Andrew Witty testified before both the House Oversight and Investigations Subcommittee and the Senate Finance Committee about February’s Change Healthcare ransomware attack, finally confirming that the company had paid $22M in cryptocurrency to the BlackCat ransomware gang to regain access to its data. As a second group, known as RansomHub, has posted screenshots to the dark web of some of Change Healthcare’s data and threatened to sell four terabytes including PHI and PII, Witty was unable to say yet how many Americans may have been impacted, although he suggested that it may be “a third” of the nation. The American Hospital Association and other hospital groups have urged UHG in an open letter to provide breach notifications on behalf of medical practices and healthcare organzations.
Kaiser Permanente
Late in April, healthcare giant Kaiser Permanente acknowledged that it may have leaked patients’ personal information to third-party advertising vendors including Google, Microsoft, and X (formerly known as Twitter). Commonly-used tracking pixels or code were the culprit, and shared with the advertisers such information as member names and IP addresses, health encyclopedia search terms, and navigation through the healthcare organization’s website and mobile apps. This leak may affect up to over 13 million current and former members and patients.
Conclusion: Strengthening Cybersecurity After the Ascension Health Cyberattack
The Ascension Health cyberattack, combined with the Change Healthcare and Kaiser Permanente data debacles, should signal the immediate need for a sector-wide reassessment of cybersecurity strategies in healthcare. Protecting sensitive health information is not only a technical and financial requirement but a moral imperative to ensure patient trust and care continuity. Ascension Health’s experience provides valuable lessons in resilience, rapid response, and the importance of proactive security measures and managed IT services in today’s digital age.

