Ascension Lawsuit: Data Breach, Class Action, and September 2025 Ruling

The Ascension data breach lawsuit is a consolidated class action in the U.S. District Court for the Eastern District of Missouri covering roughly 5.6 million people whose personal and medical information was exposed in a May 2024 ransomware attack on the St. Louis–based Catholic health system. In September 2025, Senior District Judge John A. Ross allowed the case to proceed on negligence and state consumer protection claims, and the parties are now in discovery. No class certification ruling, settlement, or trial date has been publicly reported.1Fierce Healthcare. Class Action Against Ascension Over 2024 Cybersecurity Breach May Continue, Judge Rules

What the May 2024 Attack Exposed

Ascension detected the intrusion on May 8, 2024. The Black Basta cybercriminal group got in after an employee downloaded a file believed to be legitimate. Only 7 of Ascension’s roughly 25,000 servers were compromised, but the stolen data was broad: names, dates of birth, Social Security numbers, medical record numbers, insurance details, payment card and bank account information, and various clinical records. Ascension later confirmed that 5,599,699 individuals were affected. It found no evidence that full electronic health records or clinical systems were directly accessed.2HIPAA Journal. Ascension Cyberattack 2024

The attack also shut down the tools clinicians rely on. Electronic health records, patient portals, phone systems, scheduling, and electronic prescribing all went offline. Ambulances were diverted. Elective surgeries and non-emergency appointments were postponed. Some pharmacies closed.3Healthcare Dive. Ascension Cyberattack Data Breach Affected 5.6 Million It took approximately six weeks to restore access to electronic medical records.2HIPAA Journal. Ascension Cyberattack 2024 KFF Health News reported that clinicians worked from handwritten notes and improvised spreadsheets during the outage, and described near-misses with medication dosing, an ER patient who received a narcotic intended for someone else and had to be intubated, and a cardiac arrest patient who died after staff waited four hours for lab results that never arrived.4KFF Health News. Hospitals Cyberattacks Ascension Patient Care

Ascension began mailing individual notification letters on December 19, 2024. It offered affected individuals two years of free credit monitoring and identity theft protection, along with a $1 million insurance policy. A spokesperson said Ascension’s teams were “trained for these kinds of disruptions” and declined to answer specific questions about reports of compromised care.2HIPAA Journal. Ascension Cyberattack 20244KFF Health News. Hospitals Cyberattacks Ascension Patient Care

How the Class Action Was Formed

Suits started landing within days. Katherine Negron filed the first class action on May 12, 2024, in the U.S. District Court for the Northern District of Illinois. Ana Marie Turner filed a parallel case the next day in the Western District of Texas. Both were brought by the Law Offices of T.J. Jesky.5Healthcare Finance News. Ascension Faces Class Action Lawsuits After Black Basta Ransomware Attack Those cases and other related filings were consolidated in the Eastern District of Missouri before Senior District Judge John A. Ross under docket No. 4:24-cv-00669.6PACER Monitor. Negron v. Ascension Health

What the Lawsuit Alleges

The consolidated complaint accuses Ascension of failing to maintain adequate security, protect patient information, monitor its systems for intrusions, train employees to recognize phishing attacks, comply with FTC cybersecurity guidelines and HIPAA standards, and follow industry best practices. Plaintiffs argue the attack was foreseeable and preventable, and that Ascension stored sensitive data in a way that left its network vulnerable. They say they now face an ongoing risk of identity theft and fraud, and point to reports of suspicious bank activity and personal information appearing on the dark web after the breach.1Fierce Healthcare. Class Action Against Ascension Over 2024 Cybersecurity Breach May Continue, Judge Rules Some plaintiffs also alleged physical injury from care delayed by the IT shutdown.7HealthExec. Lawsuit Against Ascension Over Data Breach Affecting 5.6M Patients Moves Forward

The suit seeks monetary damages, court-ordered improvements to Ascension’s data security, mandatory annual security audits, and credit monitoring services. Plaintiffs have demanded a jury trial.5Healthcare Finance News. Ascension Faces Class Action Lawsuits After Black Basta Ransomware Attack

The September 2025 Ruling

Ascension moved to dismiss, arguing that plaintiffs could not show any actual injury traceable to the breach and therefore lacked standing. On September 23, 2025, Judge Ross largely rejected that argument. He held that the nature of the exposed information, combined with plaintiffs’ reports of suspicious bank activity and dark web notifications, established a risk of future harm high enough to confer legal standing.8Healthcare Dive. Ascension Cyberattack Data Breach Class Action Lawsuit Moves Forward

Claims That Survived

  • Nationwide negligence, including allegations that Ascension was negligent per se for failing to meet its legal duty of care.
  • State consumer protection subclass claims under the laws of Arkansas, Florida, Illinois, Wisconsin, Michigan, and Indiana.

Claims That Were Dismissed

  • Breach of contract. The court found Ascension had not entered into an enforceable contract with patients to protect their data in the manner plaintiffs described.
  • Unjust enrichment and invasion of privacy. The judge accepted Ascension’s argument that the health system did not benefit from the attack; the hackers, not Ascension, organized the theft.
  • The Oklahoma state-law claim, dismissed on specific grounds related to that state’s statute.

The case now represents patients from seven states and has entered the discovery phase, where both sides will exchange evidence and documents. As of mid-2026, no class certification motion, settlement, or trial date has been publicly reported.1Fierce Healthcare. Class Action Against Ascension Over 2024 Cybersecurity Breach May Continue, Judge Rules7HealthExec. Lawsuit Against Ascension Over Data Breach Affecting 5.6M Patients Moves Forward

A Separate Late-2024 Breach Involving a Former Vendor

If you received a breach notice from Ascension in early 2025, it may relate to a different incident. In December 2024, Ascension learned it had inadvertently shared patient information with a former business partner, Cleo, whose systems were then targeted by the Cl0p ransomware gang. Unauthorized access was confirmed in January 2025. Ascension reported that 437,329 individuals were affected, with names, Social Security numbers, medical record numbers, insurance details, and clinical information exposed. Those individuals had previously received care at Ascension facilities in Alabama, Michigan, Indiana, Tennessee, and Texas, with 114,692 Texas residents among them. Ascension’s own systems were not compromised in this incident, and it again offered two years of free credit monitoring.9HIPAA Journal. Ascension Data Breach at Former Business Partner The Missouri class action addresses the May 2024 ransomware attack, not this separate incident.

What Affected Patients Can Do Now

If you received a notification letter about the May 2024 breach, you were automatically included in Ascension’s offer of two years of free credit monitoring and identity theft protection and are covered by a $1 million insurance policy through the vendor Ascension retained.2HIPAA Journal. Ascension Cyberattack 2024 Accepting that monitoring does not require you to opt out of the class action, and no settlement fund exists yet to file a claim against. Class members do not need to take action to remain in the case at this stage; if the court later certifies a class or approves a settlement, affected patients would receive further notice with instructions on claims deadlines, exclusion rights, and objection procedures.