Thousands of Louisiana patients have been hit by a cyberattack that hit medical centers in the US state. LSU Health New Orleans issued a HIPAA violation notice on November 20 after an attack targeted an employee's email account.

“The intrusion appears to have occurred on September 15, 2020, and access to the mailbox was discovered and disabled on September 18, 2020,” LSU Health said.
The emails and attachments to the compromised account contained limited information about patients treated at Lallie Kemp Regional Medical Center, Leonard J. Chabert Medical Center, WO Moss Regional Medical Center, the former Earl K. Long Medical Center in Baton Rouge, Bogalusa Medical Center, University Medical Center in Lafayette, and the temporary LSU hospital in New Orleans.
Patient information leaked by the breach includes names, medical record numbers, account numbers, dates of birth, social security numbers, dates of service, types of services received, phone numbers and/or addresses, and insurance identification numbers.
The type and amount of patient information affected by the incidentvaried depending on the location and email. LSU said that “some” of the emails “contained patients’ bank account numbers and health information, including a diagnosis.”

LSU Health said that while “it is possible that this information was accessible,” the health care services department “did not discover that the attacker actually accessed or misused patient information in the employee’s mailbox.”.
The total number of patients affected by the breach is not yet known.
“When the breach was discovered, the LSU Health Services Department’s Compliance and Privacy Office began the difficult and arduous process of identifying any patients whose information may have been compromised,” LSU Health said.
“While extensive research has found thousands of patients, we continue to discover more.”
LSU encourages all patients who may have been affected to monitor their credit transactions for possible identity theft. The healthcare provider said the “strict privacy and security policies” in place until now will be reviewed to determine if improvements can be made.
