Cornerstone Behavioral Healthcare
Incident posture
Linked entities
- Victim
- Cornerstone Behavioral Healthcare
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Cornerstone Behavioral Healthcare, a Worcester Maine based mental health and substance use disorder treatment provider, reported that a ransomware attack compromised protected health information of patients. The intrusion was detected and contained within an hour, with affected systems powered down to limit encryption to less than ten percent of data. Initial review indicated that approximately two thousand eight hundred thirty patients’ information, including names, addresses, contact details, dates of birth, health care and substance use disorder treatment records, insurance and Social Security numbers, was exposed. Subsequent analysis revealed that an appointment reminder log containing names, birth dates, appointment times and related notes for about twelve thousand additional patients was also accessed, bringing the total potentially affected to fourteen thousand eight hundred thirty individuals. The organization declined to pay the ransom demand, wiped the compromised hardware, replaced equipment, reviewed and strengthened security policies, and provided workforce training on ransomware prevention.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Cornerstone Behavioral Healthcare identified a ransomware attack on May 26, 2026, the same day the attackers gained access to its network. Upon discovery, the organization blocked the attacker’s access within an hour and powered down computers on the affected parts of the network to limit file encryption. Cornerstone estimated that less than 10% of the data on the affected computers and servers was encrypted. The initial investigation found that the protected health information of approximately 2,830 patients was compromised, including names, addresses, contact information, dates of birth, health care information, substance use disorder treatment information, insurance/MaineCare details, and Social Security numbers.
On July 22, 2026, further investigation revealed that a log of appointment reminders was also compromised, affecting approximately 12,000 patients. The appointment reminder log contained names, birth dates, appointment times, and reminders of documentation due. After completing the investigation, Cornerstone informed the HHS’ Office for Civil Rights that the protected health information of a total of 14,830 patients was potentially compromised in the incident. The breach notification letter stated that Cornerstone received a ransom demand but chose not to pay.
All affected computers were wiped and replaced with new systems as part of the response. The organization reviewed all systems, policies, and procedures and implemented additional security measures on its servers. Special training on ransomware was provided to the workforce. Cornerstone issued a breach notification letter to affected patients detailing the ransom demand and decision not to pay.
Sources
Sources available to members: 1 source.