NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits

Central Maine Medical Center & Susan B. Allen Memorial Hospital have agreed to settle class action lawsuits stemming from data security incidents that exposed patient information.

Central Maine Medical Center Data Breach Settlement

Central Maine Medical Center, a Lewiston, Maine-based nonprofit healthcare provider, has agreed to pay $1,368,025 to settle a consolidated class action lawsuit stemming from a 2025 cyberattack and data breach.

The attack was identified on June 1, 2026, and caused the shutdown of IT systems, network servers, and its phone system. The forensic investigation determined that hackers had access to its network between March 19, 2025, and June 1, 2025, and potentially obtained personal and protected health information. According to the lawsuit, notification letters were mailed to 218,884 individuals.

Six putative class action lawsuits were filed in response to the data breach, alleging that Central Maine Healthcare was at fault as reasonable and appropriate cybersecurity measures had not been implemented. The lawsuits were consolidated into a single complaint – In re Central Maine Data Security Litigation – naming the defendants Central Maine Healthcare Corporation and Central Maine Medical Center. The defendants deny all claims and contentions in the lawsuit, including claims of fault, wrongdoing, and liability. The lawsuit was settled to avoid the time, cost, and uncertainty of continued litigation.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The settlement fund will be used to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. The remainder of the settlement fund will be used to pay benefits to the class members. Class members may claim one of two cash payments: A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a claim may be submitted for a one-time, pro rata cash payment, estimated to be around $60 per class member.  In addition to one of those payments, class members may claim a one-year membership to a medical record monitoring service. The deadline for objection and opting out is September 13, 2026. Claims must be submitted by September 28, 2026, and the final fairness hearing has been scheduled for October 28, 2026.

Susan B. Allen Memorial Hospital Data Breach Settlement

A settlement has been agreed to resolve class action litigation against the Butler, Kansas acute-care medical facility, Susan B. Allen Memorial Hospital, to resolve claims stemming from a July 2025 cyberattack and data breach. Hackers gained access to its network and potentially obtained personal and protected health information. The data breach was initially reported to the HHS’ Office for Civil Rights as affecting up to 12,097 individuals, although the HHS’ Office for Civil Rights breach portal has since been updated to indicate that only 11,866 individuals had protected health information compromised in the incident.

Four putative class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint as they had overlapping claims and classes. The consolidated lawsuit, In Re: Susan B. Allen Data Security Litigation, is pending in the District Court of Butler County, Kansas. The plaintiffs allege that the hospital was at fault for the data breach as it failed to implement appropriate cybersecurity measures, and the defendant maintains there was no wrongdoing. A settlement was agreed to avoid the cost, time, distraction, and uncertainty of continued litigation.

The settlement provides two years of credit monitoring and identity theft protection services for all class members. In addition, a claim may be submitted for reimbursement of out-of-pocket losses due to the data breach up to a maximum of $100 per class member. In addition, a claim may be submitted for reimbursement of up to four hours of lost time at $25 per hour. Claims have been capped at an aggregate of $100 per class member. Claims must be submitted by November 12, 2026. Individuals wishing to object to the settlement or exclude themselves must do so by October 13, 2026. The final fairness hearing has been scheduled for December 7, 2026.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist