Cyber Incident Victim: Central Maine Healthcare
Date:
Mar 2025
Location:
United States of America
Summary
Central Maine Healthcare experienced a data breach after detecting unusual activity on its network, with an intrusion that persisted for several months before discovery. The breach exposed personal data including names, dates of birth, Social Security numbers, medical and health insurance information, and addresses for approximately 145,000 individuals. Following the investigation, the organization began notifying affected individuals and provided a toll‑free response line, along with one year of credit and identity theft monitoring services that include dark web surveillance. A law firm is now reviewing potential legal claims on behalf of those impacted.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On June 1, 2025, Central Maine Healthcare detected unusual activity on its computer network and became aware of a potential data breach. A subsequent forensic investigation determined that cybercriminals had infiltrated the network and gained access to files from March 19, 2025 through June 1, 2025. The intrusion spanned approximately two and a half months. The organization enlisted third‑party cybersecurity experts to assist with the investigation.

The investigation concluded that the attackers potentially accessed and acquired files containing the personal information of approximately 145,000 individuals. Exposed data included names, dates of birth, Social Security numbers, medical information, health insurance details, treatment details, provider names, dates of service, and mailing addresses. This information represented a combination of personal identifiers and protected health information. The breach affected patients across the organization's facilities in Maine, including Central Maine Medical Center in Lewiston and the Bridgton and Rumford hospitals.
Central Maine Healthcare began notifying potentially affected individuals on July 31, 2025, and continued outreach with a final round of notifications sent on December 29, 2025. To support those impacted, the organization established a dedicated toll‑free incident response line for inquiries and provided one year of credit and identity theft monitoring services that include dark web monitoring. The investigation into the attack was completed on November 6, 2025, with the assistance of the third‑party experts. Following the breach, Murphy Law Firm commenced an investigation into possible legal claims on behalf of affected individuals, exploring a class action lawsuit. In 2025, Central Maine Healthcare was acquired by Prime Healthcare Foundation.
