Immune — Self Heal, an iStudio Technologies product

Healthcare · United States · November 2023

Ardent Health Services Ransomware Attack

Over the Thanksgiving holiday in November 2023, a ransomware attack on Ardent Health Services forced more than two dozen hospitals across multiple US states to divert emergency patients and take systems offline.

What happened

On November 23, 2023 — Thanksgiving Day in the United States — Ardent Health Services discovered that it had been struck by a ransomware attack. Ardent operates more than two dozen hospitals and hundreds of care sites across several states, and the timing was almost certainly deliberate: attackers frequently strike over holidays and weekends, when security and IT staffing is thinnest and response is slowest.

Ardent responded by taking its network offline as a precaution, a containment decision that stopped the attack from spreading but also took down the digital systems its hospitals rely on. Across the affected facilities, staff lost access to electronic systems and were forced to revert to manual, paper-based operations.

The most visible consequence was in emergency care. A number of Ardent's hospitals diverted incoming ambulance and emergency patients to other facilities while systems were down — a direct, immediate translation of a cyberattack into a patient-access problem.

The impact

The operational disruption played out across multiple states at once. Emergency departments at several Ardent hospitals went on diversion, redirecting ambulances elsewhere; elective procedures were rescheduled; and clinicians worked without the electronic records and ordering systems that modern hospitals are built around.

Reverting an entire multi-state hospital network to paper — even temporarily — carries real risk. Medication orders, lab results, and patient histories that are normally a click away instead had to be tracked by hand, and the safety checks embedded in electronic systems were unavailable. Staff managed, as they always do, but under significantly more strain and risk.

As with most modern ransomware, the incident carried a data dimension alongside the operational one, triggering breach-notification obligations and the long tail of regulatory and legal follow-up that accompanies exposure of patient information.

How the attack unfolded

  • Timing: the attack was launched over the Thanksgiving holiday, exploiting reduced staffing and slower response.
  • Initial access: the specific entry point was not fully disclosed publicly.
  • Impact and containment: Ardent took its network offline to contain the spread, which disrupted clinical systems across its facilities.
  • Emergency diversion: several hospitals redirected emergency patients while systems were restored.

The recovery

Ardent restored systems progressively over the days and weeks following the attack, prioritizing the return of clinical systems and the lifting of emergency diversions while continuing to operate manually where needed.

The holiday timing compounded the recovery challenge, and the incident became another data point in a clear pattern: ransomware groups deliberately target healthcare when defenders are least available.

How this attack could have been contained

The holiday-timing tactic is exactly why autonomous, always-on response matters. Immune's detect-contain-heal loop does not depend on a fully-staffed security team being awake — it surfaces and contains an attack in seconds regardless of the calendar, closing the window that attackers deliberately target.

The multi-state spread of disruption reflects lateral movement that outran detection. Immune's containment and microsegmentation are built to confine an intrusion to one segment, so an incident at one facility does not force diversions across an entire network.

And the fallback to paper across dozens of hospitals is the harm self-healing recovery exists to prevent — restoring validated, immutable backups in clinical order so emergency systems come back fast rather than over an extended, manual recovery.

Sources

Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.

Protect against attacks like this

How to defend against healthcare ransomware

Don't let an attack become a shutdown

See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.