Ransomware
HIPAA Journal
Primary Source βIncident Details
Acadian Ambulance Service, a Louisiana-based emergency medical services provider, was attacked by the Daixin Team ransomware gang between June 19-21, 2024. The group claimed to have exfiltrated data on approximately 10 million patients and threatened public release unless a $7 million ransom was paid. Acadian negotiated but offered only $173,000 and ultimately did not pay. The breach was reported to HHS OCR as affecting 2,896,985 individuals, with data including names, addresses, Social Security numbers, dates of birth, and detailed medical/patient intake information. Acadian Ambulance is seeking dismissal of a resulting class action lawsuit.
Technical Details
- Initial Attack Vector
- CWE-284: Improper Access Control
- Vendor / Product
- Acadian Ambulance EMS systems
- Malware Family
- Daixin Team ransomware
Timeline
- 2024-06-19 Breach occurred
- 2024-08-20 Publicly disclosed
- 2024-11-01 Customers notified