Immune — Self Heal, an iStudio Technologies product

Healthcare · United States · May 2024

Ascension Ransomware Attack

In May 2024, a ransomware attack on Ascension — one of the largest U.S. health systems with 140+ hospitals — forced a return to manual processes for weeks and disrupted clinical care across multiple states.

What happened

In May 2024, Ascension — a nonprofit health system operating around 140 hospitals across roughly 19 states — detected unusual activity on its network and confirmed that it had suffered a ransomware attack. Coming just months after the Change Healthcare crisis, the Ascension attack was a second major blow to U.S. healthcare in the same year and reinforced how attractive large hospital systems have become as targets.

According to public reporting, the intrusion reportedly began when an employee inadvertently downloaded a malicious file, believing it to be legitimate. That single foothold was enough for the attackers — reported to be the Black Basta operation — to gain access and move through the environment. The attack was later reported to have accessed and exfiltrated data as well as disrupting operations.

As the scope became clear, Ascension took systems offline to contain the damage. Electronic health records, ordering systems, and other clinical technology became unavailable across many of its hospitals, and staff were forced to revert to manual, paper-based workflows for an extended period.

The impact

The operational disruption was severe and sustained. With electronic health records offline, clinicians at affected hospitals lost immediate access to patient histories, medication records, and electronic ordering. Reporting described diverted ambulances, delayed and rescheduled procedures, and the well-documented risks that come with reverting a large, modern hospital to paper for weeks at a time.

Nurses and physicians described the strain of practicing without the digital tools they rely on — manually tracking medications and orders, and working without the safety checks that electronic systems provide. These conditions, sustained over weeks, materially raise the risk of error even when staff perform heroically.

Ascension later reported that personal and health information of a large number of individuals had been affected, adding a significant data-breach dimension and the accompanying notification and regulatory obligations to the operational crisis. The financial impact, through lost revenue and remediation, was reported to be substantial.

How the attack unfolded

  • Initial access: an employee reportedly downloaded a malicious file, giving attackers their first foothold — a reminder that a single human moment can open the door.
  • Lateral movement: from that foothold, the attackers moved through a very large, multi-state hospital network.
  • Exfiltration: data was reported to have been accessed and stolen, consistent with a double-extortion approach.
  • Encryption and impact: ransomware and the protective shutdown of clinical systems forced a weeks-long return to manual operations across many hospitals.

The recovery

Ascension restored systems progressively over several weeks, prioritizing the return of electronic health records and core clinical systems while continuing to operate manually where systems remained offline.

As in other large-system attacks, the recovery timeline was driven by the need to validate systems clean before reconnecting them — careful, deliberate work that keeps clinicians on paper longer but avoids reinfecting a freshly restored environment.

How this attack could have been contained

The reported entry point — a malicious file opened by an employee — will never be fully eliminated by training alone. Immune's endpoint and behavioral detection are designed to catch what happens next: the process behavior, file activity, and network connections that follow a malicious download, so a single click does not become a foothold that spreads.

The weeks of lateral movement and staging across a 140-hospital network are exactly the dwell time Immune is built to compress. Deception traps, network monitoring, and continuous access verification target the quiet middle of the attack, raising the alarm before encryption and exfiltration.

And the defining harm here — weeks without an EHR — is what self-healing recovery exists to prevent. Restoring validated, immutable backups in clinical order is designed to bring the record back in a controlled window rather than sustaining paper operations across dozens of hospitals.

Sources

Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.

Protect against attacks like this

How to defend against healthcare ransomware

Don't let an attack become a shutdown

See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.