CSIDB logo
Incident

Cornerstone Behavioral Healthcare

Incident posture

Attack window
May 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-03 17:34

Linked entities

Victim
Cornerstone Behavioral Healthcare
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Cornerstone Behavioral Healthcare, a Worcester Maine based mental health and substance use disorder treatment provider, reported that a ransomware attack compromised protected health information of patients. The intrusion was detected and contained within an hour, with affected systems powered down to limit encryption to less than ten percent of data. Initial review indicated that approximately two thousand eight hundred thirty patients’ information, including names, addresses, contact details, dates of birth, health care and substance use disorder treatment records, insurance and Social Security numbers, was exposed. Subsequent analysis revealed that an appointment reminder log containing names, birth dates, appointment times and related notes for about twelve thousand additional patients was also accessed, bringing the total potentially affected to fourteen thousand eight hundred thirty individuals. The organization declined to pay the ransom demand, wiped the compromised hardware, replaced equipment, reviewed and strengthened security policies, and provided workforce training on ransomware prevention.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Cornerstone Behavioral Healthcare identified a ransomware attack on May 26, 2026, the same day the attackers gained access to its network. Upon discovery, the organization blocked the attacker’s access within an hour and powered down computers on the affected parts of the network to limit file encryption. Cornerstone estimated that less than 10% of the data on the affected computers and servers was encrypted. The initial investigation found that the protected health information of approximately 2,830 patients was compromised, including names, addresses, contact information, dates of birth, health care information, substance use disorder treatment information, insurance/MaineCare details, and Social Security numbers.

On July 22, 2026, further investigation revealed that a log of appointment reminders was also compromised, affecting approximately 12,000 patients. The appointment reminder log contained names, birth dates, appointment times, and reminders of documentation due. After completing the investigation, Cornerstone informed the HHS’ Office for Civil Rights that the protected health information of a total of 14,830 patients was potentially compromised in the incident. The breach notification letter stated that Cornerstone received a ransom demand but chose not to pay.

All affected computers were wiped and replaced with new systems as part of the response. The organization reviewed all systems, policies, and procedures and implemented additional security measures on its servers. Special training on ransomware was provided to the workforce. Cornerstone issued a breach notification letter to affected patients detailing the ransom demand and decision not to pay.

Sources

Sources available to members: 1 source.

CSIDB