Healthcare · United States · May 2024
Ascension Ransomware Attack
In May 2024, a ransomware attack on Ascension — one of the largest U.S. health systems with 140+ hospitals — forced a return to manual processes for weeks and disrupted clinical care across multiple states.
What happened
In May 2024, Ascension — a nonprofit health system operating around 140 hospitals across roughly 19 states — detected unusual activity on its network and confirmed that it had suffered a ransomware attack. Coming just months after the Change Healthcare crisis, the Ascension attack was a second major blow to U.S. healthcare in the same year and reinforced how attractive large hospital systems have become as targets.
According to public reporting, the intrusion reportedly began when an employee inadvertently downloaded a malicious file, believing it to be legitimate. That single foothold was enough for the attackers — reported to be the Black Basta operation — to gain access and move through the environment. The attack was later reported to have accessed and exfiltrated data as well as disrupting operations.
As the scope became clear, Ascension took systems offline to contain the damage. Electronic health records, ordering systems, and other clinical technology became unavailable across many of its hospitals, and staff were forced to revert to manual, paper-based workflows for an extended period.
The impact
The operational disruption was severe and sustained. With electronic health records offline, clinicians at affected hospitals lost immediate access to patient histories, medication records, and electronic ordering. Reporting described diverted ambulances, delayed and rescheduled procedures, and the well-documented risks that come with reverting a large, modern hospital to paper for weeks at a time.
Nurses and physicians described the strain of practicing without the digital tools they rely on — manually tracking medications and orders, and working without the safety checks that electronic systems provide. These conditions, sustained over weeks, materially raise the risk of error even when staff perform heroically.
Ascension later reported that personal and health information of a large number of individuals had been affected, adding a significant data-breach dimension and the accompanying notification and regulatory obligations to the operational crisis. The financial impact, through lost revenue and remediation, was reported to be substantial.
How the attack unfolded
- Initial access: an employee reportedly downloaded a malicious file, giving attackers their first foothold — a reminder that a single human moment can open the door.
- Lateral movement: from that foothold, the attackers moved through a very large, multi-state hospital network.
- Exfiltration: data was reported to have been accessed and stolen, consistent with a double-extortion approach.
- Encryption and impact: ransomware and the protective shutdown of clinical systems forced a weeks-long return to manual operations across many hospitals.
The recovery
Ascension restored systems progressively over several weeks, prioritizing the return of electronic health records and core clinical systems while continuing to operate manually where systems remained offline.
As in other large-system attacks, the recovery timeline was driven by the need to validate systems clean before reconnecting them — careful, deliberate work that keeps clinicians on paper longer but avoids reinfecting a freshly restored environment.
How this attack could have been contained
The reported entry point — a malicious file opened by an employee — will never be fully eliminated by training alone. Immune's endpoint and behavioral detection are designed to catch what happens next: the process behavior, file activity, and network connections that follow a malicious download, so a single click does not become a foothold that spreads.
The weeks of lateral movement and staging across a 140-hospital network are exactly the dwell time Immune is built to compress. Deception traps, network monitoring, and continuous access verification target the quiet middle of the attack, raising the alarm before encryption and exfiltration.
And the defining harm here — weeks without an EHR — is what self-healing recovery exists to prevent. Restoring validated, immutable backups in clinical order is designed to bring the record back in a controlled window rather than sustaining paper operations across dozens of hospitals.
Sources
Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.
Related incidents
More ransomware attacks
The February 2024 ransomware attack on Change Healthcare disrupted medical claims and payments nationwide, affecting an estimated 100 million people and becoming one of the costliest healthcare cyberattacks on record.
In October 2022, a ransomware attack on CommonSpirit Health — one of the largest U.S. hospital systems — disrupted electronic health records across multiple states and reportedly carried a financial impact near US$150 million.
Protect against attacks like this
How to defend against healthcare ransomware
Don't let an attack become a shutdown
See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.
