LOUISIANA CYBER INCIDENT WATCHIndependent. Sourced. Local.
BAYOUBREACH
Menu
Back to incident explorer
INCIDENT BRIEF / HEALTHCARE

Lake Charles Memorial Health System

Confirmed incidentLake Charles, LouisianaOct 20–21, 2022

Lake Charles Memorial detected unauthorized network activity in October 2022. Its investigation found patient information in files accessed or obtained by an intruder. The health system later notified patients; reporting put the affected population near 270,000. Hive separately claimed responsibility.

01 / OPERATIONAL IMPACT

What happened to the community?

The hospital listed identity, insurance, payment and limited clinical data, with Social Security numbers in some cases. It said its electronic medical record was inaccessible to the intruder. The Record reported 269,752 affected people from the HHS filing.

Recovery & current status

No current recovery status asserted; distinguish file exposure from access to the electronic medical record.

02 / THE TIMELINE

What the sources document

  1. The hospital’s investigation identified this unauthorized network-access window.

  2. Hive listed the organization on a leak site, according to The Record. The claim is separate from the hospital’s findings.

  3. Patient notification mailings began, according to the hospital’s notice.

03 / EVIDENCE & ATTRIBUTION

What is known. What is claimed.

Attacker claim reported by journalists; hospital notice does not name a group or confirm ransomware. The Record reports Hive listed the hospital on its leak site November 15. The group's claimed encryption date differs from the hospital's confirmed access window; the two dates describe different assertions.

Incident confirmation and attacker attribution are separate questions. A confirmed disruption does not independently verify every claim about stolen data, ransom demands, or responsibility.

04 / FROM INCIDENT TO PREPAREDNESS

Security gap

What to examine in your own environment, and how Fortinet technology could help prevent or limit a similar attack.

Separate technical assessment

Sensitive files and visibility into data leaving the network

The health system reported patient information in files accessed or obtained during unauthorized network activity. It said the intruder could not access the electronic medical record.

What remains unknown: The notice does not establish the entry point or transfer route. There is no matching Louisiana account row in the workbook.

Read the incident evidence
RECOMMENDED FORTINET PRODUCT · ASSESSMENT

FortiDLP

Sensitive data movement and egress controls
Cloud platform with endpoint agents

Cloud-native data-protection platform using endpoint agents and supported cloud integrations; not a universal inline appliance for all server traffic.

Why it fits: The workbook’s general data-protection guidance fits a review of sensitive files outside the main medical-record system. Covered transfers can be inspected and restricted by policy.

How the technology works: Inspects sensitive data and user activity through endpoint agents and supported cloud integrations, using content, origin, and behavioral context to flag risky movement and enforce controls on covered egress paths.

For it to help: Coverage follows deployed agents and supported integrations or egress paths; it is not universal exfiltration blocking for arbitrary servers or unseen traffic.

Before choosing a model or license
  • Which devices, cloud drives, and egress paths need coverage?
  • What data is sensitive?
  • Which policies can safely block activity?

Choose the capacity and license after reviewing these requirements. This brief does not prescribe an appliance model or promise a historical attack would have been prevented.

Additional controls to validate 1 conditional options
CONDITIONAL FOLLOW-ON

FortiNDR

Network behavior detection and response support
Hardware/VM sensors; on-premises platform or cloud service

FortiNDR offers on-premises hardware and VM deployments; FortiNDR Cloud is SaaS with supported hardware or virtual sensors. Sensor placement determines the traffic available for analysis.

Why it fits: If the relevant network traffic is visible to sensors, unusual outbound movement can support earlier investigation and coordinated containment.

How the technology works: Analyzes observed network traffic to detect signs of lateral movement, command activity, and data exfiltration, providing investigation context and integrations that help security teams coordinate containment with enforcement tools.

For it to help: Detection depends on sensor visibility into relevant traffic; containment requires an enabled response workflow or integration with an enforcement tool.

ASK YOUR IT TEAM OR SERVICE PROVIDER

Where do patient-file exports and shared copies live, and which of their transfer paths are actually monitored or controlled?

Request conversation
Mapping & assessment notes

Prepared using Five_State_Ransomware_Fortinet_Positioning.xlsx, October 8, 2026 snapshot.

No matching Louisiana account row was found. This assessment applies the workbook’s general product guidance and linked technical sources; it is not presented as an account recommendation from the sheet.

These are present-day control examples, reviewed October 9, 2026. “Security gap” means an area to evaluate, not a proven failure at the named organization. Products, configurations, historical availability and the actual attack path vary. No product is asserted to have certainly prevented this incident.

How we assess control fit
05 / READ THE ORIGINALS

Sources & further reading