In December 2024 Ascension disclosed that around 5.6 million patient and employee records had been taken, including medical information, payment details and Social Security numbers.
The outage had been over since June. By December the story had stopped being a story, and the number arrived into a quiet news cycle.
One Incident, Two Harms, Seven Months Apart
The availability harm was immediate, visible and impossible to hide: hospitals on paper, ambulances diverted, a month of it. The confidentiality harm was invisible until a review finished, and then it was a filing.
The corpus has recorded the second pattern repeatedly — at 24-0620 where a count moved for eleven months, at 25-0403 where a supplier’s loss took six. What Ascension shows is the two clocks running on the same incident at completely different speeds.
Only One Of Them Generates A Legal Obligation
The 5.6 million produced notifications, a regulatory filing and class actions. The month of diverted care produced none of those, because no regime requires an organisation to count what an outage did to patients.
That asymmetry is the whole reason this database over-represents confidentiality. The corpus does not record availability harm less because it matters less; it records it less because nothing compels anyone to measure it.
The Delay Is Structural, And It Still Has A Cost
Establishing whose records sat in an exfiltrated archive genuinely takes months, and this desk has argued against treating that as concealment. But a person whose Social Security number moved in May learned of it in December, and had no way to act in between.
Both things are true, and the corpus records them together rather than picking the more comfortable one.
Compiled from the company’s disclosure and contemporaneous reporting, listed below. Graded high: the 5.6 million figure originates with the organisation’s own notification. It is a count of individuals notified, which is a legal threshold rather than a measure of harm. Corrections: corrections@forensicpost.com.