Woodfords Family Services said a Medusa ransomware attack discovered on April 8, 2024 exposed the personal information and protected health information of 8,073 individuals, including 7,701 Maine residents. The Maine disability services provider reported that unauthorized access affected files and folders on its network, and a later review found data including names, Social Security numbers, driver’s license numbers, financial account information, health insurance details, and diagnosis and treatment information. The breach was initially reported to HHS in June 2024 with a placeholder figure of at least 500 affected people, while the full scope was not confirmed until internal review and data mining concluded in early 2026.
Woodfords issued preliminary and media notices in 2024 and mailed final notification letters on March 27, 2026, after determining which individuals were affected. The organization is offering 12 months of credit monitoring and identity theft protection to impacted people. The incident marks Woodfords’ second ransomware-related breach in two years, following a separate 2023 attack that affected 17,285 individuals, including PHI tied to 6,691 people.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-27, Woodfords publicly disclosed the breach details, including the final affected population and the nature of the exposed data. Reporting also identified Medusa as the ransomware group that accessed the network.
On 2026-03-27, Woodfords mailed notification letters to affected individuals and said 8,073 people were impacted, including 7,701 Maine residents. The organization also offered 12 months of credit monitoring and identity theft protection.
On 2026-01-29, after data mining and internal review, Woodfords confirmed that the compromised files contained personal information and protected health information. Reported data types included Social Security numbers, driver's license numbers, financial account information, health insurance information, and diagnosis and treatment details.
Also in June 2024, Woodfords reported the incident to the HHS Office for Civil Rights as a ransomware-related breach. The filing used a placeholder estimate of at least 500 affected individuals.
In June 2024, Woodfords issued preliminary and media notices about the April 2024 breach. At that stage, the organization had not yet determined the full scope of affected individuals.
On 2024-04-08, Woodfords Family Services discovered suspicious activity on its network and determined that unauthorized access affected files and folders the same day. Later reporting characterized the incident as a ransomware attack.
In June 2023, Woodfords Family Services experienced an earlier ransomware-related breach. Reporting says that incident affected 17,285 individuals, including protected health information belonging to 6,691 people.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.