All Breaches
June 19, 2024 Verified Sensitive Record Healthcare

Acadian Ambulance 2024 Data Breach

The Acadian Ambulance 2024 data breach occurred when a threat actor maintained unauthorized access to the private ambulance provider's network from June 19 through June 21, 2024 and removed files from its systems. Acadian Ambulance identified suspicious activity on June 21, isolated systems to prevent further access, and began a forensic investigation with third-party computer specialists.

The breach list maintained by the US Department of Health and Human Services Office for Civil Rights shows 2,896,985 affected individuals. pwnCount and totalRecords use that regulatory total. The affected files contained identity and medical information collected during ambulance-service intake, but LeakData imports no patient or employee records.

How Was the Data Theft Confirmed?

Acadian Ambulance said in notification letters that its investigation determined a threat actor accessed the network between June 19 and June 21. The organization also confirmed that files were exfiltrated from its systems during that window. The incident therefore rests on acquisition found by the company's forensic review rather than only a possibility of access.

The HHS OCR entry classifies the event as a Hacking/IT Incident, the affected location as Network Server, and the entity type as Healthcare Provider. HIPAA Journal compared the organization notice with the federal filing and corroborated the access window, exfiltration, affected population, and data fields. Together, the two sources establish a genuine reportable health-data breach.

What Was the Incident and Notification Timeline?

Verified network access began on June 19, 2024 and ended when the provider discovered suspicious activity on June 21. breachDate is June 19, the beginning of the access window. The organization isolated systems, activated backup and redundancy mechanisms, and responded in an effort to limit disruption to patient care.

Reviewing the files, identifying affected people, and locating accurate contact information took more than two months. Acadian Ambulance reported the event to HHS OCR on August 20, 2024 and began mailing notification letters. Although discovery, investigation, and notification dates differ, the record represents the same June access event.

What Personal and Medical Information Was Affected?

Depending on the person, affected information may include names, mailing addresses, and dates of birth. Social security numbers were also among the disclosed sensitive fields. Medical information collected during ambulance-service intake was involved, creating lasting healthcare-privacy risk in addition to the danger of identity theft.

The organization did not say every person had every field. Its official notice did not confirm payment cards, bank accounts, passwords, email contents, or every detailed case field named by the attacker as part of the general scope. The data classes use only categories from the organization notice and do not automatically add attacker assertions to patient files.

How Should the Total of 2,896,985 Be Read?

The HHS OCR row shows 2,896,985 individuals for Acadian Ambulance Service Inc. This is the affected population reported to the regulator and is substantially lower than the attacker's assertion of 10 million “unique records.” pwnCount and totalRecords use only the HHS value; claimed row counts and the service-area population are not added.

Acadian Ambulance serves most of Louisiana, a large part of Texas, and selected areas in Tennessee and Mississippi. Reaching a service region of roughly 24 million people does not mean 24 million people were breached. LeakData does not convert operating reach into victims and does not exceed the verified federal total.

How Are the Daixin Team Claims Treated?

Daixin Team claimed responsibility in July 2024, asserting that it took about 10 million unique records, demanded a $7 million ransom, and would publish data if it was not paid. The group named a broader set of fields that included patient names, birth dates, phone numbers, medical and case histories, and employee information.

Those statements are attacker claims and were not confirmed in full by Acadian's regulatory notification. LeakData identifies the group for context but does not treat the 10 million figure, ransom amount, or every claimed field as an organization-confirmed finding. The reliable core is company-confirmed exfiltration, the HHS population, and information types in the official notice.

What Should Affected People Do?

Acadian Ambulance said it had identified no attempted or actual misuse of the stolen data when the incident was disclosed and offered complimentary credit monitoring and identity-theft protection. Notice recipients should check the enrollment deadline, review credit reports, and consider a security freeze if their Social Security number was involved.

Medical statements should be reviewed for unfamiliar ambulance services, providers, or insurance claims. Calls and messages claiming to represent Acadian should be verified through a contact channel independently obtained from its official website before personal information is provided. importedRecordCount is zero; LeakData does not store or publish names, addresses, birth dates, Social security numbers, or medical information.

2.9 Million
Affected Accounts
5
Data Types
Critical
Severity
Yes
Verification

Exposed Data Types

5
Names
Physical addresses
Dates of birth
Social security numbers
Medical information

Additional Information

Added DateJuly 27, 2026
Breach DateJune 19, 2024
Domainacadianambulance.com
SourceUnauthorized network access and confirmed exfiltration of files containing patient information
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information