Acadiana Radiation Therapy, LLC Data Breach
Acadiana Radiation Therapy Email Breach Affects 2,219 Patients
What happened in the Acadiana Radiation Therapy, LLC data breach?
The Acadiana Radiation Therapy, LLC data breach was reported on June 27, 2025 and affected 2,219 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Louisiana. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Acadiana Radiation Therapy, LLC Breach Details
Acadiana Radiation Therapy Email Security Breach
Acadiana Radiation Therapy, LLC, a healthcare provider based in Louisiana, experienced a significant data breach involving unauthorized access to its email systems. The breach was reported to the U.S. Department of Health and Human Services on June 27, 2025, affecting 2,219 individuals. The incident involved a hacking or IT-related compromise of the organization's email infrastructure, which is a common attack vector for healthcare entities seeking to access patient protected health information (PHI). Email systems often contain sensitive patient communications, appointment details, medical records, and other confidential healthcare information that can be exploited by threat actors.
Company Response
Upon discovery of the unauthorized access to its email systems, Acadiana Radiation Therapy initiated an investigation to determine the scope and nature of the breach. The organization worked to identify which patient records may have been compromised and began the process of notifying affected individuals as required by HIPAA Breach Notification Rule. The entity also engaged with its business associates to understand the full extent of the compromise, as indicated by the involvement of at least one business associate in this incident. The notification process, which commenced following the June 27, 2025 submission date, represents the organization's compliance with federal requirements to inform patients without unreasonable delay and no later than 60 calendar days after discovery of a breach.
Specific Details
The breach occurred within the email location of Acadiana Radiation Therapy's IT infrastructure. Email systems are particularly vulnerable to hacking attempts including phishing attacks, credential compromise, malware deployment, and direct server exploitation. Threat actors targeting healthcare email systems typically seek access to patient records, billing information, and other sensitive data that can be used for identity theft, insurance fraud, or sold on the dark web. The involvement of a business associate suggests that the compromised email system may have contained communications or data shared with third-party vendors, contractors, or service providers who handle patient information on behalf of the radiation therapy center. This multi-party exposure increases the complexity of the breach and the number of entities responsible for patient notification and remediation efforts.
Organizational Context
Acadiana Radiation Therapy, LLC operates as a specialized healthcare provider offering radiation therapy services in Louisiana. Radiation therapy centers are critical components of cancer treatment infrastructure, providing targeted radiation treatments to oncology patients. These facilities maintain detailed patient medical records including cancer diagnoses, treatment plans, imaging results, and ongoing health status information. The organization's email systems would typically contain communications between clinical staff, patient appointment scheduling information, treatment authorization details, and coordination with referring physicians. As a healthcare provider subject to HIPAA regulations, Acadiana Radiation Therapy is required to maintain appropriate safeguards for all patient PHI and to implement administrative, physical, and technical security measures to prevent unauthorized access.
Patient Impact and Notifications
The breach affected 2,219 individuals whose information may have been accessed through the compromised email system. These patients likely include current and former radiation therapy patients whose medical records, appointment information, and personal identifiers were stored in or transmitted through the affected email infrastructure. Notification letters were sent to affected individuals informing them of the breach, the types of information potentially exposed, and recommended steps to protect themselves. The notification process, initiated following the June 27, 2025 submission date, complies with HIPAA requirements to provide patients with specific information about the breach, including a description of what occurred, the types of information involved, steps the organization is taking to investigate and prevent future breaches, and resources available to affected individuals.
Industry Context and HIPAA Implications
Email-based breaches represent a significant portion of healthcare data breaches reported annually. According to HHS breach notification data, compromised email accounts frequently result in exposure of large numbers of patient records because email systems often serve as central repositories for patient communications and documentation. The HIPAA Security Rule requires covered entities and business associates to implement appropriate safeguards including access controls, encryption, audit controls, and integrity controls to protect electronic PHI. Email systems should be protected through multi-factor authentication, encryption of data in transit and at rest, regular security updates, and employee security awareness training. The involvement of a business associate in this breach underscores the importance of Business Associate Agreements (BAAs) and the shared responsibility for HIPAA compliance. Healthcare organizations must ensure that their vendors and third-party service providers maintain equivalent security standards and are contractually obligated to report breaches promptly. Similar email-based breaches have affected numerous healthcare providers across the United States, highlighting the persistent vulnerability of email infrastructure to sophisticated threat actors.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Acadiana Radiation Therapy, LLC Breach
Place a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) and consider placing a credit freeze to prevent unauthorized account opening
Monitor credit reports regularly for suspicious activity and review bank and credit card statements monthly for unauthorized charges or accounts
Change passwords for any online healthcare portals, email accounts, and financial accounts, using strong, unique passwords with multi-factor authentication where available
Be cautious of unsolicited communications claiming to be from healthcare providers or insurance companies, as phishing emails may attempt to harvest additional personal information; verify requests by contacting organizations directly using known phone numbers or websites
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Louisiana Breaches
Search all breaches reported in Louisiana