LOUISIANA CYBER INCIDENT WATCHIndependent. Sourced. Local.
BAYOUBREACH
Menu
Back to incident explorer
INCIDENT BRIEF / HEALTHCARE

Baton Rouge General / General Health System

Confirmed incidentBaton Rouge, LouisianaJun 24–29, 2022

Baton Rouge General continued patient care while switching to paper records after a June cyberattack. Its later investigation established unauthorized network access over several days, with sensitive information in accessible directories. The hospital notified people potentially affected by the incident.

01 / OPERATIONAL IMPACT

What happened to the community?

Temporary paper charting while electronic records and other patient systems were offline. The hospital later identified at-risk directories containing identity, medical, insurance, financial and other sensitive data; this does not mean every data type affected every person.

Recovery & current status

The June 29 statement said care continued at all locations. No present-day operational condition is asserted.

02 / THE TIMELINE

What the sources document

  1. The hospital’s later investigation identified unauthorized network access during this window.

  2. The hospital discovered suspicious activity.

  3. The hospital said care continued while staff temporarily used paper charting.

03 / EVIDENCE & ATTRIBUTION

What is known. What is claimed.

No named actor in the selected primary notice or contemporaneous hospital statement. This record does not assign a ransomware group.

Incident confirmation and attacker attribution are separate questions. A confirmed disruption does not independently verify every claim about stolen data, ransom demands, or responsibility.

04 / FROM INCIDENT TO PREPAREDNESS

Security gap

What to examine in your own environment, and how Fortinet technology could help prevent or limit a similar attack.

Workbook organization match

Understand exposure and protect clinical continuity

The hospital documented unauthorized access and temporary paper charting. The workbook separately records a later Hive listing without a technical account of the intrusion.

What remains unknown: The workbook matches the organization; linkage of the August claim to the June event is not independently established here. Neither an initial access method nor compromised medical devices is established.

Read the incident evidence
RECOMMENDED FORTINET PRODUCT · WORKBOOK

FortiRecon

Exposure discovery and adversary intelligence
Cloud service (SaaS)

Subscription exposure-management and intelligence service; not a physical network appliance.

Why it fits: The workbook recommends clarifying the external intelligence first. Validated exposure findings can guide remediation without treating the Hive allegation as a forensic conclusion.

How the technology works: Continuously discovers exposed assets and prioritizes vulnerabilities, while monitoring leaked credentials, ransomware activity, and other adversary intelligence so teams can remediate exposure and investigate emerging risk before or during an incident.

For it to help: Findings require investigation and remediation; exposure monitoring and ransomware intelligence do not directly block ransomware execution.

Before choosing a model or license
  • Which domains, IP ranges, brands, and vendors are in scope?
  • Who validates and acts on findings?

Choose the capacity and license after reviewing these requirements. This brief does not prescribe an appliance model or promise a historical attack would have been prevented.

Additional controls to validate 4 conditional options
CONDITIONAL FOLLOW-ON

FortiEDR

Endpoint prevention, containment, and response
Endpoint software with cloud or on-premises management

Software agents protect supported endpoints and servers; management components can be cloud, on-premises, or hybrid. This is not an inline hardware firewall.

Why it fits: On supported clinical and administrative computers, endpoint behavior analysis and containment can reduce malware damage. Validate platform support and clinical workflow impacts.

How the technology works: An endpoint agent analyzes malware and suspicious process behavior, can block harmful file access and outbound communications, and supports automated isolation and remediation to limit ransomware damage on protected devices.

For it to help: Protection depends on supported devices running the agent with suitable prevention and response policies; this does not guarantee every ransomware attack is stopped.

CONDITIONAL FOLLOW-ON

FortiAuthenticator + FortiToken

Stronger authentication and centralized identity policy
Hardware or virtual identity server + mobile or hardware tokens

FortiAuthenticator is available as a physical or virtual appliance, including private/public-cloud deployment. FortiToken factors include mobile software and hardware tokens or security keys.

Why it fits: Review integrated remote and administrative login paths if authentication gaps are found.

How the technology works: Centralizes authentication for integrated applications, VPNs, and administrative access, adding FortiToken factors and identity policies so a stolen password alone is less likely to provide access to protected resources.

For it to help: Phishing resistance requires an appropriate FIDO2 flow; OTP or push alone is not equivalent. Enabling MFA does not establish revocation of already stolen application sessions.

CONDITIONAL FOLLOW-ON

FortiPAM

Privileged credential and session controls
Virtual appliance

The current datasheet identifies a virtual appliance for privileged credential and session management. Do not label it a recommended physical box.

Why it fits: Conditional on a verified privileged-access gap, especially third-party maintenance accounts and sessions.

How the technology works: Vaults and rotates privileged credentials, brokers access under role-based policies, and records privileged sessions; administrators can restrict commands or terminate sessions to reduce credential exposure and misuse of elevated access.

For it to help: Apply these controls to onboarded accounts and brokered sessions; unmanaged credentials or direct access that bypasses FortiPAM remain outside that enforcement path.

CONDITIONAL FOLLOW-ON

FortiNAC

Device discovery and network access control
Hardware or virtual appliance

The product line includes hardware appliances and virtual machines, with Control and Application Server functions and separate licensing. Enforcement depends on compatible network integrations.

Why it fits: Only if a medical-device visibility or access-control gap is verified. Plan device isolation with clinical teams; healthcare sector membership alone is not evidence of lateral spread.

How the technology works: Identifies devices on the network and applies access policies through compatible network equipment. Quarantine workflows can restrict a suspicious device while the team investigates.

For it to help: Requires compatible network integrations and tested policies. Medical-device changes need clinical safety review; a hospital incident alone does not prove a device visibility gap.

ASK YOUR IT TEAM OR SERVICE PROVIDER

Can IT and clinical leaders demonstrate a safe containment decision that preserves essential patient-care workflows?

Request conversation
Mapping & assessment notes

Prepared using Five_State_Ransomware_Fortinet_Positioning.xlsx, October 8, 2026 snapshot.

Louisiana account row 30; listing evidence row 61; evidence ID RL-28693. The lead product and conditional follow-ons follow that account row. FortiToken is explained alongside FortiAuthenticator using current vendor documentation.

Matched to the organization identified in the workbook. This does not independently establish that the listing describes this historical incident.

Workbook’s provider record

These are present-day control examples, reviewed October 9, 2026. “Security gap” means an area to evaluate, not a proven failure at the named organization. Products, configurations, historical availability and the actual attack path vary. No product is asserted to have certainly prevented this incident.

How we assess control fit
05 / READ THE ORIGINALS

Sources & further reading