Central Maine Healthcare (CMH) disclosed a data breach that exposed sensitive information for 145,381 individuals, including patients and current/former employees. Attackers maintained unauthorized access to CMH systems for more than two months, from March 19 to June 1 (discovered June 1), affecting an integrated healthcare delivery system serving roughly 400,000 people and operating facilities including Central Maine Medical Center, Bridgton Hospital, and Rumford Hospital.
CMH reported that exposed data varied by individual but could include full names, dates of birth, treatment information, dates of service, provider names, health insurance information, and Social Security numbers. CMH’s investigation and impact analysis concluded on November 6, 2025, and the organization has been notifying affected individuals on a rolling basis while offering free credit monitoring and establishing a dedicated support line; CMH also warned of elevated risk of phishing, impersonation, and fraud, advising patients to review provider and insurance statements for suspicious activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
In January 2026, CMH publicly disclosed that a 2025 cyberattack exposed data belonging to more than 145,000 individuals. At the time of reporting, no threat actor had publicly claimed responsibility.
By December 29, 2025, CMH had completed notifications to affected individuals, set up a dedicated response line, and offered 12 months of free credit protection services. It also advised patients to watch for phishing, impersonation, fraud, and suspicious medical or insurance activity.
On November 6, 2025, CMH concluded its investigation and impact analysis, determining that 145,381 individuals were affected. The review found that exposed data may have included names, dates of birth, treatment and service details, insurance information, and in some cases Social Security numbers.
CMH started sending notifications to affected individuals on July 31, 2025, as its investigation progressed. The organization also began providing support resources related to the breach.
On June 1, 2025, CMH detected unusual activity, secured affected systems, launched an investigation with third-party cybersecurity experts, and notified law enforcement. The organization later identified this date as the end of the attackers' access window.
Central Maine Healthcare later determined that an unauthorized party first gained access to its IT environment on March 19, 2025. The intrusion ultimately affected patient and employee data across the healthcare system.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.