Between April 14 and April 15, 2025, McKenzie Memorial Hospital suffered a data breach. The hospital discovered the breach on the second day of the intrusion, June 19, 2025. After the discovery, the hospital reportedly secured its network and law enforcement was notified. Third-party cybersecurity specialists were engaged to investigate the incident.
According to the Department of Health & Human Services disclosure, 58,839 people across the United States have been affected
The review determined that a range of sensitive information may have been accessed including personally identifiable information (PII) such as first and last name, address, phone number, email address, Social Security number, driver's license or state ID number, date of birth, and financial account information, including employee bank account numbers.
In addition, protected health information (PHI) was potentially compromised, including medical diagnosis, date of service, patient account number, medical record number, health insurance claim number, health insurance policy number and treatment cost information.
The data breach was reported to the Maine Attorney General’s office (6 affected residents), the Massachusetts Attorney General’s office (17 affected residents) and the New Hampshire Attorney General’s office (2 affected residents) on July 24, 2025.
The hospital has also posted a Notification of Data Security Incident on its own website.
Written notification letters were sent to all affected individuals for whom the hospital had address information.
As a result of the breach, the hospital reviewed and enhanced its data protection policies and implemented additional safeguards to strengthen its cybersecurity posture.
To support those affected, McKenzie Memorial Hospital is offering complimentary credit monitoring and identity protection services for up to 24 months through Cyberscout, a TransUnion company. Affected individuals are encouraged to enroll in these services within 90 days of receiving their notification letter.
The hospital has established a dedicated call center at 844-536-8079, available Monday through Friday, 8 a.m. to 8 p.m. Eastern Time, to answer questions and provide assistance.
Individuals are urged to remain vigilant by monitoring their credit reports, account statements and explanation of benefits forms for any suspicious activity or errors.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.