Ascension Seton disclosed breach of two legacy websites run by vendor Vertex

Organization
Ascension Seton
Exploit
Third-Party Data Breach
Industry
Healthcare

Ascension Seton, the Austin-based hospital system, disclosed in early June 2023 that two of its legacy websites had been breached more than three months earlier. The health system said unauthorized access to Seton.net and DellChildrens.net occurred on March 1 and March 2, 2023, and that the activity was detected on March 2.

Both sites were built and operated by Vertex, a third-party technology vendor. Information that visitors had entered through the two sites was potentially exposed, including names, addresses, email addresses, phone numbers, insurance details, Social Security or tax identification numbers, credit card numbers and some clinical information. Ascension said its hospital networks and electronic medical record systems were not affected.

Vertex engaged a forensic investigator and notified law enforcement. Ascension said that, based on the investigation to that point, it did not believe any information had been extracted, shared or misused.

The health system took the two sites offline and replaced them with new versions hosted in-house. It also said it had reviewed its vendor processes and changed what information it collects through its websites. Affected individuals were offered complimentary credit monitoring and identity theft protection, and a dedicated assistance line was set up.

Local coverage did not put a figure on the number of people involved. Trade reporting later placed the total notified at 148,606, with filings to the U.S. Department of Health and Human Services listing 17,191 individuals at Ascension Seton and 1,415 at Ascension Providence in Waco.

Sources