Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-14 ยท updated: 2026-09-14 ยท tags: [incident, breach, healthcare, litigation, united-states] ยท confidence: high ยท severity: medium ยท affected_sectors: [Healthcare] ยท au_impact: true

Two US healthcare providers have agreed to settle class action litigation arising from separate data security incidents that exposed patient information. Central Maine Medical Center, a Lewiston, Maine-based nonprofit, will pay $1,368,025 to resolve a consolidated action over a 2025 intrusion in which the forensic investigation found that attackers had access to its network between 19 March and 1 June 2025, obtaining personal and protected health information. Notification letters were mailed to 218,884 individuals, and the incident caused the shutdown of IT systems, network servers and the phone system when it was identified on 1 June 2026.

Six putative class actions were consolidated into In re Central Maine Data Security Litigation, naming Central Maine Healthcare Corporation and Central Maine Medical Center. The defendants deny all claims of fault, wrongdoing and liability, and settled to avoid the time, cost and uncertainty of continued litigation. Class members may claim documented unreimbursed losses up to $5,000 or a pro rata cash payment estimated at around $60, plus a one-year medical record monitoring membership; the objection and opt-out deadline was 13 September 2026, claims close on 28 September, and the final fairness hearing is set for 28 October.

Susan B. Allen Memorial Hospital has separately settled its own action on comparable terms. The detail worth carrying forward is the timeline rather than the figure: the intrusion window ran over two months before detection, and the resulting action is the second multi-provider settlement in this digest's recent coverage after the Palomar Health and Summit Medical Group agreements reported on 11 September. US healthcare litigation is settling on a predictable curve while the underlying exposure โ€” long dwell times in environments that cannot be taken offline โ€” has not changed.

Attribute Detail
Sector Healthcare
Date 2026-09-14
Source HIPAA Journal
Reliability Tier 2
Breach class Confirmed breach โ€” notification and litigation record

Source