Desk live·
ForensicPost
Ransomware/Availability/File 23-1123

Ardent Health Took 30 Hospitals Offline After Thanksgiving Ransomware

Ardent Health took its network offline on 23 November 2023, across 30 hospitals in six states. Half its emergency rooms began diverting ambulances, staff returned to pen and paper, and the record system came back on 7 December.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetArdent Health Services
ActorUnattributed
S. Rosler11 min readConfidence: high3 sources reviewed

Ardent Health Services detected unauthorised activity on the morning of 23 November 2023 — Thanksgiving — and determined it to be ransomware. It took its network offline, suspending access to corporate servers, its Epic electronic medical record system, internet and clinical applications, and implemented downtime protocols across 30 hospitals in six states.

By 28 November, half of its 25 emergency rooms were diverting patients needing immediate care to other hospitals, with patient information recorded on paper. The Epic system was restored on 7 December and emergency room diversion ended, with some non-urgent procedures still delayed.

The Date Is Not Incidental

A public holiday morning is when a hospital group has its thinnest technical staffing, its slowest escalation paths and its longest time to assemble a response.

We have recorded the same timing at 22-1218, where a children’s hospital was encrypted the week of Christmas, and at 22-1220. The desk does not assert intent in this case because none was established — but it records that the pattern is consistent enough across the corpus to be worth stating.

Diversion Is The Measurable Harm

Ambulance diversion is one of the few availability harms in this database that produces a number: a patient needing immediate care is taken somewhere else, and the additional journey time is real and quantifiable.

We have argued at 24-1231 that availability harm is uncounted and at 23-0616 that its worst form arrives years later. Diversion is the exception — measurable at the time, by the ambulance service, in minutes. It is still not what any breach notification asks about.

Taking The Network Down Was The Decision

Ardent disconnected deliberately, converting an uncertain compromise into a certain fortnight of degraded operation across thirty hospitals.

We have recorded that decision at 22-0220, where a freight forwarder did the same, and at 22-1002. It is generally correct and it is never free, and we keep finding that the organisations best able to make it quickly are the ones that had already written down what running on paper looks like — which is the guidance at 26-0728.

How we reported this

Compiled from the organisation’s statements and contemporaneous reporting, listed below. No ransomware operation claimed the attack and none is named. No entry route was published. No figure for affected patient records was available at the time and none is asserted. The observation about holiday timing is a pattern this desk records across files, not a finding about intent in this case. Graded high on the operational facts. Corrections: corrections@forensicpost.com.

Sources
  1. Multiple hospitals divert ambulances after ransomware attack on parent companyThe Record
  2. Ardent Health Services Ransomware Attack Affects Hospitals in Multiple StatesHIPAA Journal
  3. Ardent Health Services fully restores patient portal after ransomware attackHealthcare Dive
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary