United States
USA
An unauthorized party gained access to COVENANT HEALTH's IT environment beginning on 18/05/2025 and accessed patient information. After detecting irregular activity on 26/05/2025, Covenant Health discontinued access to data systems across hospitals, clinics and provider practices. The resulting outage impaired phone and internet connectivity, restricted outpatient laboratory services, complicated prescription refills, imaging and appointment handling, and caused St. Mary's Health System to divert ambulances for a period. Full computer services across Covenant Health hospitals and provider practices were reported restored on 30/06/2025. The QILIN ransomware group later claimed responsibility and data theft; public evidence confirms unauthorized access and exfiltration but does not independently establish ransomware encryption as the mechanism of the operational outage.
Estimated severity
84 / 100
Source reliability
92 / 100
Approximate Date
18/05/2025
Targeted Company
COVENANT HEALTH
Distribution & Fulfillment
Procurement & Sourcing
Production & Manufacturing
Sales (Retail & Ecommerce)
Warehousing
Service Delivery
Unrecognized Impact
Supply Chain Relations
No information
United States
USA
No other affected countries reported
Target country
United States
Affected countries
Impacted regions
Duration
No information
Financial impact (USD M)
No information
Impact types
Affected sectors
Affected departments
Attack types
Attributed threat actors
Incident Sources
Please rotate your phone