Lake City Cancer Care, LLC Data Breach
Lake City Cancer Care Email System Compromised
What happened in the Lake City Cancer Care, LLC data breach?
The Lake City Cancer Care, LLC data breach was reported on June 27, 2025 and affected 15,142 individuals. The breach type was Hacking/IT Incident involving Email. This breach occurred in Florida. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Affected Hospital in Our Directory
Lake City Cancer Care, LLC Breach Details
Lake City Cancer Care Data Breach Report
Incident Overview
Lake City Cancer Care, LLC, a healthcare provider based in Florida, experienced a significant data breach involving unauthorized access to its email systems. The breach was reported to the U.S. Department of Health and Human Services on June 27, 2025, affecting 15,142 individuals. The unauthorized access to email systems represents a common but serious vulnerability in healthcare IT infrastructure, as email accounts typically contain sensitive patient communications, appointment records, and protected health information (PHI). This incident underscores the ongoing cybersecurity challenges facing mid-sized oncology practices and the importance of strong email security protocols in healthcare settings.
Company Response and Investigation
Upon discovery of the unauthorized access to their email systems, Lake City Cancer Care initiated an investigation to determine the scope and nature of the breach. The organization worked to identify which email accounts were compromised, what information may have been accessed, and the timeframe during which unauthorized access occurred. As required by HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), the organization began the process of notifying affected individuals and relevant authorities. The submission date of June 27, 2025, indicates when the breach was formally reported to HHS, though the actual discovery and investigation timeline may have extended over several weeks prior to this official notification.
Technical Details of the Breach
The breach involved a hacking or IT incident targeting the organization's email infrastructure. Email systems are frequently targeted by threat actors because they serve as central repositories for sensitive communications and often contain links to other organizational systems. Common attack vectors for email compromise include phishing campaigns, credential stuffing, exploitation of unpatched vulnerabilities, and brute-force attacks against weak authentication mechanisms. The involvement of a business associate in this breach suggests that the compromised email systems may have contained communications with or information about third-party vendors, billing entities, or other healthcare partners. Email-based breaches typically result in broader exposure than isolated database compromises because email accounts often contain diverse types of information accumulated over extended periods.
Organizational Context
Lake City Cancer Care, LLC operates as an oncology-focused healthcare provider in Florida. Cancer care practices typically maintain extensive patient records including treatment plans, medication histories, diagnostic imaging reports, and ongoing communications regarding chemotherapy, radiation therapy, and other cancer treatments. These organizations serve vulnerable patient populations dealing with serious illnesses and often maintain particularly sensitive health information. The practice's size—serving 15,142 affected individuals—suggests a regional oncology provider with multiple locations or a substantial patient base. Florida-based healthcare organizations operate under both state privacy laws and federal HIPAA requirements, with additional considerations for healthcare data security standards specific to the state.
Patient Impact and Notification
Approximately 15,142 individuals had their information potentially exposed through the email system compromise. These patients likely include current and former cancer care patients whose medical records, appointment information, treatment details, and personal health information were stored in or transmitted through the compromised email accounts. Affected individuals may have received notification letters detailing the breach, the types of information potentially exposed, and recommended protective measures. Under HIPAA requirements, Lake City Cancer Care was obligated to provide written notification to affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach. The notification should have included a description of the breach, types of information involved, steps individuals should take to protect themselves, and information about the organization's response to the incident.
Industry Context and HIPAA Implications
Email system compromises represent a significant category of healthcare data breaches, accounting for a substantial portion of reported incidents annually. According to HHS breach notification data, hacking and IT incidents consistently rank among the top causes of healthcare data breaches, with email systems being particularly vulnerable targets. The involvement of a business associate in this breach highlights the extended responsibility healthcare organizations bear for their vendors' security practices. Under HIPAA's Business Associate Rule, covered entities like Lake City Cancer Care are responsible for ensuring that business associates implement appropriate safeguards for PHI, and breaches involving business associates must still be reported to affected individuals. This incident reflects broader industry trends showing that healthcare organizations of all sizes face sophisticated cyber threats, and that email security remains a critical vulnerability despite years of awareness and investment in cybersecurity measures.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Lake City Cancer Care, LLC Breach
Monitor credit reports from all three major bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review explanation of benefits (EOB) statements and medical bills carefully for unauthorized services, claims, or providers; contact your insurance company and Lake City Cancer Care immediately if you identify suspicious activity
Change passwords for all online healthcare accounts, email accounts, and financial accounts, using strong, unique passwords; enable multi-factor authentication wherever available
Watch for suspicious communications claiming to be from healthcare providers, insurers, or financial institutions; verify any requests for personal information by contacting organizations directly using known phone numbers or websites rather than information provided in unsolicited communications
Consider enrolling in credit monitoring or identity theft protection services if offered by Lake City Cancer Care as part of their breach response; document all communications related to the breach for your records
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Florida Breaches
Search all breaches reported in Florida
Were You Affected?
Patients affected by large healthcare data breaches may be eligible for compensation through class action lawsuits.
Learn about data breach lawsuitsTechnical Notes
Lake City Cancer Care, LLC Has 2 Reported Breaches
This organization has been involved in multiple reported data breaches.
View full breach history for Lake City Cancer Care, LLC