Ardent Health Services detected unauthorised activity on the morning of 23 November 2023 — Thanksgiving — and determined it to be ransomware. It took its network offline, suspending access to corporate servers, its Epic electronic medical record system, internet and clinical applications, and implemented downtime protocols across 30 hospitals in six states.
By 28 November, half of its 25 emergency rooms were diverting patients needing immediate care to other hospitals, with patient information recorded on paper. The Epic system was restored on 7 December and emergency room diversion ended, with some non-urgent procedures still delayed.
The Date Is Not Incidental
A public holiday morning is when a hospital group has its thinnest technical staffing, its slowest escalation paths and its longest time to assemble a response.
We have recorded the same timing at 22-1218, where a children’s hospital was encrypted the week of Christmas, and at 22-1220. The desk does not assert intent in this case because none was established — but it records that the pattern is consistent enough across the corpus to be worth stating.
Diversion Is The Measurable Harm
Ambulance diversion is one of the few availability harms in this database that produces a number: a patient needing immediate care is taken somewhere else, and the additional journey time is real and quantifiable.
We have argued at 24-1231 that availability harm is uncounted and at 23-0616 that its worst form arrives years later. Diversion is the exception — measurable at the time, by the ambulance service, in minutes. It is still not what any breach notification asks about.
Taking The Network Down Was The Decision
Ardent disconnected deliberately, converting an uncertain compromise into a certain fortnight of degraded operation across thirty hospitals.
We have recorded that decision at 22-0220, where a freight forwarder did the same, and at 22-1002. It is generally correct and it is never free, and we keep finding that the organisations best able to make it quickly are the ones that had already written down what running on paper looks like — which is the guidance at 26-0728.
Compiled from the organisation’s statements and contemporaneous reporting, listed below. No ransomware operation claimed the attack and none is named. No entry route was published. No figure for affected patient records was available at the time and none is asserted. The observation about holiday timing is a pattern this desk records across files, not a finding about intent in this case. Graded high on the operational facts. Corrections: corrections@forensicpost.com.