2026 Cornerstone Behavioral Healthcare — May 26 ransomware; 14,830 patients (HHS); SUD/SSNs
Data compromised
Names, addresses, contact info, DOBs, healthcare and substance-use disorder treatment information, insurance/MaineCare, SSNs; later also appointment-reminder log (names, DOBs, appointment times)
Technical writeup
Verified provider notice summarized by HIPAA Journal — September 3, 2026. Cornerstone Behavioral Healthcare (Worcester, Maine mental-health and substance-use treatment) detected a ransomware attack May 26, 2026, blocked access within about an hour, and limited encryption to under 10% of data on affected systems. Initial review found ~2,830 patients’ PHI compromised; July 22 review added an appointment-reminder log covering ~12,000 patients. HHS OCR was informed that 14,830 patients’ PHI was potentially compromised in total. Exposed categories include SSNs, substance-use disorder treatment information, and MaineCare/insurance data. Cornerstone said it received a ransom demand and did not pay; systems were wiped and replaced with additional controls. recordsAffected 14830 from HHS filing via HIPAA Journal; companyConfirmed true.
Root cause
Ransomware attack detected May 26, 2026 the same day attackers gained access; access blocked within an hour; ransom demand received and not paid