Healthcare · United States · November 2023
Ardent Health Services Ransomware Attack
Over the Thanksgiving holiday in November 2023, a ransomware attack on Ardent Health Services forced more than two dozen hospitals across multiple US states to divert emergency patients and take systems offline.
What happened
On November 23, 2023 — Thanksgiving Day in the United States — Ardent Health Services discovered that it had been struck by a ransomware attack. Ardent operates more than two dozen hospitals and hundreds of care sites across several states, and the timing was almost certainly deliberate: attackers frequently strike over holidays and weekends, when security and IT staffing is thinnest and response is slowest.
Ardent responded by taking its network offline as a precaution, a containment decision that stopped the attack from spreading but also took down the digital systems its hospitals rely on. Across the affected facilities, staff lost access to electronic systems and were forced to revert to manual, paper-based operations.
The most visible consequence was in emergency care. A number of Ardent's hospitals diverted incoming ambulance and emergency patients to other facilities while systems were down — a direct, immediate translation of a cyberattack into a patient-access problem.
The impact
The operational disruption played out across multiple states at once. Emergency departments at several Ardent hospitals went on diversion, redirecting ambulances elsewhere; elective procedures were rescheduled; and clinicians worked without the electronic records and ordering systems that modern hospitals are built around.
Reverting an entire multi-state hospital network to paper — even temporarily — carries real risk. Medication orders, lab results, and patient histories that are normally a click away instead had to be tracked by hand, and the safety checks embedded in electronic systems were unavailable. Staff managed, as they always do, but under significantly more strain and risk.
As with most modern ransomware, the incident carried a data dimension alongside the operational one, triggering breach-notification obligations and the long tail of regulatory and legal follow-up that accompanies exposure of patient information.
How the attack unfolded
- Timing: the attack was launched over the Thanksgiving holiday, exploiting reduced staffing and slower response.
- Initial access: the specific entry point was not fully disclosed publicly.
- Impact and containment: Ardent took its network offline to contain the spread, which disrupted clinical systems across its facilities.
- Emergency diversion: several hospitals redirected emergency patients while systems were restored.
The recovery
Ardent restored systems progressively over the days and weeks following the attack, prioritizing the return of clinical systems and the lifting of emergency diversions while continuing to operate manually where needed.
The holiday timing compounded the recovery challenge, and the incident became another data point in a clear pattern: ransomware groups deliberately target healthcare when defenders are least available.
How this attack could have been contained
The holiday-timing tactic is exactly why autonomous, always-on response matters. Immune's detect-contain-heal loop does not depend on a fully-staffed security team being awake — it surfaces and contains an attack in seconds regardless of the calendar, closing the window that attackers deliberately target.
The multi-state spread of disruption reflects lateral movement that outran detection. Immune's containment and microsegmentation are built to confine an intrusion to one segment, so an incident at one facility does not force diversions across an entire network.
And the fallback to paper across dozens of hospitals is the harm self-healing recovery exists to prevent — restoring validated, immutable backups in clinical order so emergency systems come back fast rather than over an extended, manual recovery.
Sources
Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.
Related incidents
More ransomware attacks
In October 2022, a ransomware attack on CommonSpirit Health — one of the largest U.S. hospital systems — disrupted electronic health records across multiple states and reportedly carried a financial impact near US$150 million.
In May 2024, a ransomware attack on Ascension — one of the largest U.S. health systems with 140+ hospitals — forced a return to manual processes for weeks and disrupted clinical care across multiple states.
Protect against attacks like this
How to defend against healthcare ransomware
Don't let an attack become a shutdown
See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.
