Skip to content

CHC data breach could affect over a million patients

  • by
  • 2 min read

US-based non-profit healthcare provider Community Health Center (CHC) has announced that it suffered a data breach. The organisation is currently in the process of notifying the 1,060,936 individuals affected by the breach.

According to its filing with the Maine attorney general office, CHC doesn’t know the attackers’ identity at the moment. However, it did state that the intruders gained access to its systems in mid-October 2024. The breach wasn’t discovered until January 2, 2025.

Experts were brought in shortly after and discovered that a “skilled criminal hacker” had gained access to its systems. The criminal access was terminated in hours, and there’s no current threat to the company’s servers.

The hackers were able to steal patient files containing personal and health information, including names, birthdays, addresses, phone numbers, Social Security Numbers, medical diagnoses, treatment details, test results, and health insurance details.

This is an image of data breach cyber security 238972348978978

The nature of the attack also remains undisclosed, however, CHC claimed that the hackers didn’t delete or lock any of its data and the criminal activity didn’t affect daily operations. There are also no signs that the stolen data has been misused yet, and Candid.Technology found no such data being sold or promoted on popular hacker forums.

As is the norm with such data breaches, CHC offers affected individuals 24 months of IDX identity protection service, including a $1,000,000 insurance reimbursement policy and fully managed identity theft recovery services.

Hospitals and healthcare organisations have become increasingly popular ransomware targets over the last year. However, as organisations amp up their cyber defences, criminals have switched tactics and have started carrying out data theft attacks instead of locking victims’ files. This means a ransomware gang could be behind the CHC attack.

In the News: Italy bans DeepSeek, starts investigation into data collection

Yadullah Abidi

Yadullah Abidi

Yadullah is a Computer Science graduate who writes/edits/shoots/codes all things cybersecurity, gaming, and tech hardware. When he's not, he streams himself racing virtual cars. He's been writing and reporting on tech and cybersecurity with websites like Candid.Technology and MakeUseOf since 2018. You can contact him here: yadullahabidi@pm.me.

>