25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

MaineGeneral Health Hacked

MaineGeneral Health has announced it has suffered a cyberattack that potentially affects patients of all of its subsidiaries, including MaineGeneral Community Care, MaineGeneral Medical Center, MaineGeneral Rehabilitation and Long Term Care & MaineGeneral Retirement Community.

Patients who received radiology services from MaineGeneral Health after being referred by a specific physician have been affected. The name of that physician has not been disclosed, although a breach report submitted to OCR indicates 500 patients have been affected.

MaineGeneral Health Cyberattack Affects Patients, Employees, and Emergency Contacts

The data exposed in the security breach include dates of birth and emergency contact names, addresses, and telephone numbers. Certain employees have also been affected and have had their names, addresses, and telephone numbers exposed. According to a statement released by MaineHealth, some prospective donors have also been affected.

At the present moment in time, the investigation into the security breach indicates that no further data have been exposed, although the forensic investigation is ongoing. As a precaution against identity theft and fraud, all affected individuals have been offered a year of credit monitoring services without charge through ClearID.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

MaineGeneral Health received a tip-off from the FBI on November 13, 2015, about MainGeneral Health patient data that were posted on a website. That website does not appear to have been accessible by the public. Once notified of the security breach, MaineGeneral Health launched an internal investigation to determine which patients had been affected, the extent of the data breach, and the exact data that were exposed.

An nationally recognized external data forensics company was employed to conduct a thorough forensic analysis of the cyberattack. All systems are being analyzed to determine the full extent of the cyberattack. At this stages, it would appear that Social Security numbers, financial information, Driver’s license numbers, and clinical/medical data were not exposed.

All affected individuals will receive a breach notification letter if they have been affected, and information will be provided to allow them to take additional measures to safeguard their identities and credit. A helpline has been set up for patients to call (1-877-441-2645) for further information, and assistance can be provided to help affected patients initiate the credit protection services being offered.

According to a statement released by Chuck Hays, CEO of MaineGeneral Health, the investigation into the data breach is “an ongoing effort.” He also said, “We will provide additional information as the investigation continues.”

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist