Menu
Browse

Cyber Incident Victim: Central Maine Healthcare

Date:

Mar 2025

Location:

United States of America

Summary

Central Maine Healthcare experienced a data breach after detecting unusual activity on its network, with an intrusion that persisted for several months before discovery. The breach exposed personal data including names, dates of birth, Social Security numbers, medical and health insurance information, and addresses for approximately 145,000 individuals. Following the investigation, the organization began notifying affected individuals and provided a toll‑free response line, along with one year of credit and identity theft monitoring services that include dark web surveillance. A law firm is now reviewing potential legal claims on behalf of those impacted.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On June 1, 2025, Central Maine Healthcare detected unusual activity on its computer network and became aware of a potential data breach. A subsequent forensic investigation determined that cybercriminals had infiltrated the network and gained access to files from March 19, 2025 through June 1, 2025. The intrusion spanned approximately two and a half months. The organization enlisted third‑party cybersecurity experts to assist with the investigation.

Cyber Incident Image

The investigation concluded that the attackers potentially accessed and acquired files containing the personal information of approximately 145,000 individuals. Exposed data included names, dates of birth, Social Security numbers, medical information, health insurance details, treatment details, provider names, dates of service, and mailing addresses. This information represented a combination of personal identifiers and protected health information. The breach affected patients across the organization's facilities in Maine, including Central Maine Medical Center in Lewiston and the Bridgton and Rumford hospitals.

Central Maine Healthcare began notifying potentially affected individuals on July 31, 2025, and continued outreach with a final round of notifications sent on December 29, 2025. To support those impacted, the organization established a dedicated toll‑free incident response line for inquiries and provided one year of credit and identity theft monitoring services that include dark web monitoring. The investigation into the attack was completed on November 6, 2025, with the assistance of the third‑party experts. Following the breach, Murphy Law Firm commenced an investigation into possible legal claims on behalf of affected individuals, exploring a class action lawsuit. In 2025, Central Maine Healthcare was acquired by Prime Healthcare Foundation.

Sources
Sources available to members
2 sources