
Several hospitals across the US suffered operational disruptions following a significant cyber attack on healthcare provider Ardent Health Services.Nashville, Tennessee-based Ardent Health Services runs a network of thirty hospitals and over 200 healthcare facilities across six U.S. states. Founded in 1993, the healthcare company was acquired by Ventas in 2015 for $1.75 billion and has more than 26,000 employees today.Information about Ardent Health Services suffering a security incident came to light after several healthcare organisations managed by the company started reporting network outages. These included UT Health East Texas, Hillcrest HealthCare System in Oklahoma and Lovelace Health System in New Mexico.While Ardent did not initially comment on the cyber security incident, it later announced that on November 23, it became aware of an “information technology cybersecurity incident” and immediately launched an internal investigation with assistance from third party cyber security experts to understand the nature and scope of the same.The investigation revealed that the company was a victim of a ransomware incident that involved threat actors encrypting several internal systems and disrupting the company’s daily operations and the healthcare facilities managed by it.“The Ardent technology team immediately began working to understand the event, safeguard data, and regain functionality. As a result, Ardent proactively took its network offline, suspending all user access to its information technology applications, including corporate servers, Epic software, internet and clinical programs,” Ardent said.The company added that the ransomware attack caused disruptions to its clinical and financial operations, but its IT team is working hard to get its systems back online and that “patient care continues to be delivered safely and effectively in its hospitals, emergency rooms, and clinics.“In an abundance of caution, our facilities are rescheduling some non-emergent, elective procedures and diverting some emergency room patients to other area hospitals until systems are back online,” it added.According to NBC News, multiple hospitals managed by Ardent Health Services suffered severe disruption to their daily operations. Hospitals including Hillcrest HealthCare System in Oklahoma, Lovelace Health System in New Mexico, and UT Health in Texas reported diverting their emergency room patients and ambulances to other healthcare facilities in the aftermath of the attack.Emergency rooms of Hackensack Meridian’s Mountainside Medical Center and Pascack Valley Medical Center in New Jersey also diverted all new cases to other facilities.Ardent said it is working with law enforcement authorities and third party cyber security experts to recover its systems as soon as possible but could not comment on when its systems will be back online.“The investigation and restoration of access to electronic medical records and other clinical systems is ongoing. Ardent is still determining the full impact of this event and it is too soon to know how long this will take or what data may be involved in this incident,” Ardent added.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543