CSIDB logo
Incident

Baton Rouge General Medical Center

Incident posture

Attack window
Jun 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-18 00:00

Linked entities

Victim
Baton Rouge General Medical Center
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jun 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyber attack targeted Baton Rouge General Medical Center, prompting the organization to implement temporary paper-based charting while electronic medical records and related systems remained offline. Patient care capabilities were maintained across all facilities despite the disruption. The institution collaborated with federal and state authorities alongside security vendors to safeguard patient data integrity during recovery efforts.

Motives

Detailed motive labels are available to members.

4 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Baton Rouge General Medical Center experienced a cyber attack that commenced on Tuesday, June 28, 2022, disrupting hospital operations. The institution publicly acknowledged the incident on June 29 through an official statement, confirming the attack had compromised critical digital systems. While patient care capabilities remained unaffected across all facilities, clinical staff implemented temporary paper-based charting protocols as electronic medical records and related patient systems became inaccessible. This operational shift represented the most visible impact on hospital workflows during the initial response phase. No immediate evidence suggested compromised patient care delivery or emergency service interruptions resulting from the cyber incident. Hospital administrators prioritized maintaining clinical operations through manual documentation processes while forensic investigations commenced.

The organization engaged multiple response partners, including undisclosed federal and state law enforcement agencies, to address the security breach. Internal IT teams collaborated with external cybersecurity vendors to restore affected systems safely, though no specific timeline for full recovery was provided. Hospital leadership emphasized ongoing efforts to verify the security of patient data throughout the containment process. No details regarding the attack vector, potential data exfiltration, or threat actor attribution were disclosed in initial communications. The response strategy focused on maintaining care continuity while systematically evaluating system integrity before reactivating digital infrastructure. Baton Rouge General did not report service cancellations or patient diversions during the incident's acute phase.

Sources

Sources available to members: 1 source.

CSIDB