Covenant Health, a Catholic healthcare provider operating across New England and Pennsylvania, suffered a major data breach in May 2025 after the Qilin ransomware group gained unauthorized access to its systems. The breach exposed sensitive information of approximately 478,188 patients, including names, addresses, dates of birth, medical record numbers, Social Security numbers, health insurance details, and treatment information. Initial reports underestimated the scale, but further forensic analysis revealed the true extent of the compromise. The attackers reportedly stole 852 GB of data, and Covenant Health has since offered affected individuals 12 months of free identity protection services while strengthening its cybersecurity measures.
The incident significantly disrupted operations at several hospitals, particularly St. Joseph Hospital and St. Mary’s Health System in Maine and New Hampshire, where lab services were limited and wait times increased due to the attack. The Qilin ransomware group, known for targeting healthcare and critical infrastructure globally, claimed responsibility for the breach and listed Covenant Health on its data leak site. Federal law enforcement was notified, and the organization began sending breach notification letters to victims at the end of December 2025. The investigation concluded in December, confirming the attackers maintained access to Covenant Health’s IT systems for over a week in May 2025.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
By early January 2026, Covenant Health updated its disclosures to say the May 2025 breach affected 478,188 individuals, far above the initial estimate. The revised total followed additional data analysis and included large numbers of patients in Maine and other northeastern states.
Covenant Health started sending additional notification letters to affected individuals on December 31, 2025. The notices included offers of credit monitoring or identity protection for eligible victims.
The Qilin ransomware gang claimed responsibility for the Covenant Health attack and said it exfiltrated 852 GB of data. Reported stolen information included patient names, Social Security numbers, medical record details, insurance information, diagnoses, and treatment data.
Covenant Health initially reported the May 2025 incident to federal regulators as affecting roughly 7,864 to 7,900 individuals. This early estimate was later found to significantly understate the scale of the breach.
Following detection of the attack, Covenant Health brought in third-party forensic specialists to investigate and notified federal law enforcement. The organization also began remediation and security-hardening efforts after taking systems offline.
On May 26, 2025, Covenant Health detected a ransomware attack later attributed to the Qilin group. The incident caused connectivity issues, system shutdowns, and service disruptions at hospitals and clinics, forcing some operations to revert to manual processes.
Investigators determined that an unauthorized third party gained access to Covenant Health's network on May 18, 2025. During this access window, attackers were able to reach files containing sensitive patient information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
6 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcerescana.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.