Back to the register

Lafourche Medical Group

ArchivedSubmitted 05/28/2021
State
LA
Covered entity type
Healthcare Provider
Individuals affected
34,862
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Email
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Lafourche Medical Group (LMG) has paid $480,000 to the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) and agreed to implement a corrective action plan to settle potential violations of the Health Insurance Portability and Accountability Act (HIPAA) Privacy, Security, and Breach Notification Rules. LMG is a Louisiana medical group specializing in emergency medicine, occupation medicine, and laboratory testing. On May 28, 2021, LMG filed a breach report with HHS stating that a hacker, through a successful phishing attack on March 30, 2021, gained access to an email account that contained electronic protected health information (ePHI). The type of ePHI involved included names, addresses, dates of birth, dates of service, email addresses, telephone numbers, medical record numbers, insurance/health plan beneficiary numbers, guarantor names, diagnoses, and lab results for approximately 34,862 individuals. OCR’s investigation revealed that, prior to the 2021 reported breach, LMG failed to conduct a risk analysis to identify potential threats or vulnerabilities to ePHI across the organization as required by HIPAA. OCR also discovered that LMG had no policies or procedures in place to regularly review information system activity to safeguard protected health information against cyberattacks. In addition to the monetary settlement, LMG will undertake a robust corrective action plan that includes two years of monitoring. A copy of the resolution agreement and corrective action plan may be found at: https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/lafourche-medical-group/index.html.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.