Regional Urology: Oschner LSU Health Regional Urology Data Breach Investigation

Regional Urology: Oschner LSU Health Regional Urology Data Breach Investigation

Regional Urology Reports Data Breach Affecting Legacy Systems

Regional Urology disclosed a data breach involving unauthorized access to sensitive personal and health information stored in retired systems. On October 10, 2025, the organization detected unusual activity in legacy infrastructure that had been inactive since 2022. An investigation confirmed that an unauthorized third party accessed and potentially exfiltrated data on or around October 5, 2025.

The exposed information varies by individual but may include:

  • Full names
  • Social Security numbers
  • Dates of birth
  • Medical record numbers
  • Treatment details (provider names, dates of service, medical history, imaging, and procedure records) related to care received before December 31, 2022

Regional Urology published a breach notice on its website and filed an official report with the U.S. Department of Health and Human Services’ Office for Civil Rights on December 9, 2025. Affected individuals are being notified of the specific data compromised and offered complimentary credit monitoring services. The incident underscores the risks associated with unmaintained legacy systems in healthcare.

Source: https://straussborrelli.com/2025/12/22/oschner-lsu-health-regional-urology-data-breach-investigation/

REGIONAL UROLOGY, LLC cybersecurity rating report: https://www.rankiteo.com/company/regional-urology-asc-llc

"id": "REG1766441262",
"linkid": "regional-urology-asc-llc",
"type": "Breach",
"date": "10/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Healthcare',
                        'name': 'Regional Urology',
                        'type': 'Healthcare Provider'}],
 'customer_advisories': 'Posted notice on website with details of the breach '
                        'and offered complimentary credit monitoring services',
 'data_breach': {'data_exfiltration': 'Confirmed',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Name',
                                              'Social Security number',
                                              'Date of birth',
                                              'Medical record number',
                                              'Provider names',
                                              'Date of treatment',
                                              'Medical history',
                                              'Imaging or procedure '
                                              'information']},
 'date_detected': '2025-10-10',
 'date_publicly_disclosed': '2025-12-09',
 'description': 'Regional Urology experienced a data breach where sensitive '
                'personal identifiable information and protected health '
                'information may have been compromised. Unusual activity was '
                'detected in retired systems, leading to an investigation that '
                'confirmed unauthorized access and acquisition of sensitive '
                'data.',
 'impact': {'data_compromised': 'Sensitive personal identifiable information '
                                'and protected health information',
            'identity_theft_risk': 'High',
            'systems_affected': 'Legacy systems retired since 2022'},
 'investigation_status': 'Completed',
 'recommendations': 'Providing affected individuals with complimentary credit '
                    'monitoring services',
 'references': [{'source': 'Regional Urology Breach Notice'}],
 'regulatory_compliance': {'regulations_violated': 'HIPAA',
                           'regulatory_notifications': 'Filed notice with U.S. '
                                                       'Department of Health '
                                                       'and Human Services’ '
                                                       'Office for Civil '
                                                       'Rights'},
 'response': {'communication_strategy': 'Posted notice on website and filed '
                                        'official notice with HHS OCR'},
 'threat_actor': 'Unauthorized third party',
 'title': 'Regional Urology Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.