St. Mary's Health System: Data breach last year at Central Maine Healthcare affected more than 145,000

St. Mary's Health System: Data breach last year at Central Maine Healthcare affected more than 145,000

Cybersecurity Breach at Central Maine Healthcare Exposes Over 145,000 Patients’ Data

Central Maine Healthcare disclosed a data breach discovered in June 2025, where an unauthorized third party accessed sensitive patient information. The exposed data may have included names, dates of birth, treatment details, and Social Security numbers. The incident affected more than 145,000 individuals approximately 138,000 of them Maine residents making it one of the state’s largest healthcare-related breaches in recent years.

The breach occurred at Central Maine Medical Center in Lewiston, with the healthcare system confirming it has notified all impacted patients. This incident follows a separate breach reported earlier this month by St. Mary’s Health System, also based in Lewiston, which initially underestimated the scope of its exposure. The earlier breach, detected last spring, was later revealed to have affected 478,000 people far exceeding the 8,000 initially reported to the Maine Attorney General’s office.

Both incidents highlight ongoing vulnerabilities in healthcare data security, with unauthorized access leading to large-scale exposure of personal and medical records. Investigations into the breaches remain ongoing.

Source: https://www.mainepublic.org/health/2026-01-14/data-breach-last-year-at-central-maine-healthcare-affected-more-than-145-000

St. Mary's Health System cybersecurity rating report: https://www.rankiteo.com/company/stmarysmaine

"id": "STM1768422816",
"linkid": "stmarysmaine",
"type": "Breach",
"date": "6/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '145000',
                        'industry': 'Healthcare',
                        'location': 'Lewiston, Maine, USA',
                        'name': 'Central Maine Healthcare',
                        'type': 'Healthcare System'}],
 'customer_advisories': 'Notified all patients whose data may have been '
                        'involved in the incident',
 'data_breach': {'number_of_records_exposed': '145000',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Names',
                                              'Dates of birth',
                                              'Treatment information',
                                              'Social Security numbers']},
 'date_detected': '2025-06',
 'date_publicly_disclosed': '2026-01-14',
 'description': 'An unauthorized third party accessed patient information at '
                'Central Maine Healthcare, which may have included names, '
                'dates of birth, treatment information, and Social Security '
                'numbers. The breach affected more than 145,000 people, '
                'including roughly 138,000 Mainers.',
 'impact': {'data_compromised': 'Names, dates of birth, treatment information, '
                                'Social Security numbers',
            'identity_theft_risk': 'High'},
 'references': [{'date_accessed': '2026-01-14',
                 'source': 'Central Maine Healthcare',
                 'url': 'https://www.cmmc.org'},
                {'date_accessed': '2026-01-14', 'source': 'Maine Public'}],
 'regulatory_compliance': {'regulatory_notifications': 'Reported to Maine '
                                                       "Attorney General's "
                                                       'office'},
 'response': {'communication_strategy': 'Notified all patients whose data may '
                                        'have been involved in the incident'},
 'threat_actor': 'Unauthorized third party',
 'title': 'Central Maine Healthcare Data Breach',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.