Cornerstone Behavioral Healthcare cut off the attackers within an hour and refused to pay. Working out who was affected took another two months.

 

What happened

Ransomware hit Cornerstone Behavioral Healthcare on May 26, 2026. The Bangor provider spotted it the same day the attack began and suspended the attackers' access within an hour, according to the notice it published under the HIPAA Breach Notification Rule and Maine's Notice of Risk to Personal Data Act. Staff powered the affected machines down fast enough that under 10% of the data on them was encrypted. Cornerstone refused the ransom demand and restored its own data. Its first count put 2,830 people at risk, covering names, addresses, dates of birth, health care information, substance use disorder treatment information, insurance and MaineCare details, and Social Security numbers.

 

Going deeper

On July 22, nearly two months after the attack, Cornerstone found that a log of appointment reminders had also been sitting on the affected systems. That log held records for another 12,000 people, listing names, dates of birth, appointment times, and reminders about documentation due. Total reported to the Department of Health and Human Services on July 27: 14,830 individuals, more than five times the original estimate. Cornerstone said it was still investigating whether anything further about those 12,000 was involved. An appointment reminder log is not where anyone looks first for protected health information, which is the point worth taking from this. For a behavioral health provider, a list of names paired with appointment dates discloses that a person is in treatment, without a diagnosis appearing anywhere in the file.

 

What was said

Cornerstone "did not pay the ransom and was able to stop the attack and restore its electronic data," the organization stated in its published notice. It directed affected individuals to its Privacy Officer in Bangor and confirmed it had notified the HHS Secretary under 45 CFR 164.408.

 

In the know

The #StopRansomware Guide from CISA and the FBI tells organizations to isolate affected systems from the network first and to power devices down only if disconnecting them is not possible. Shutting a machine off wipes whatever was held in memory, and that is often where evidence of what an attacker touched lives. Cornerstone's choice limited the encryption to under 10%. It may also help explain why a second set of 12,000 people surfaced eight weeks later rather than in the initial review.

 

The big picture

Behavioral health and addiction treatment providers hold the records where exposure does the most damage, and they tend to run on the smallest IT budgets in healthcare. Cornerstone operates two outpatient offices. Ransomware has climbed steadily as a cause of healthcare breaches over that period, going from no recorded cases in 2010 to more than 30% of breaches by 2021, with hacking and IT incidents accounting for 88% of all patient records exposed between 2010 and 2024, according to a cross-sectional analysis in JAMA Network Open. Small providers are not exempt from that trend, and a treatment record naming someone as a substance use disorder patient carries employment, custody, and licensing consequences that a credit freeze does nothing about. Knowing which systems hold that data, including the peripheral ones like reminder logs and scheduling exports, is what determines whether a scope review takes days or months.

 

FAQs

Why did the affected count more than quintuple?

Cornerstone's first review covered the systems where patient records are stored. The appointment reminder log sat elsewhere on the affected machines and was identified later. Breach counts commonly rise as reviews reach data stores that fall outside an organization's primary clinical systems.

 

Is an appointment reminder protected health information?

Yes. Any information identifying a person as having received or sought care from a covered entity qualifies, whether or not it names a condition. For providers treating stigmatized conditions, the fact of the appointment can be the most sensitive element in the file.

 

Should systems be shut down or disconnected during ransomware?

Disconnect first. Federal guidance recommends isolating affected devices from the network while leaving them powered on, and reserving shutdown for cases where disconnection is not possible. Powering down stops encryption but destroys memory evidence investigators need.

 

What does refusing to pay change?

Nothing about the notification obligations, which turn on whether protected health information was accessed rather than on how the incident resolved. Refusing avoids funding the operation and avoids relying on criminals to honor a deletion promise, though it requires working backups.

 

Do substance use disorder records carry extra protections?

They do. Federal rules at 42 CFR Part 2 restrict how these records can be used in legal proceedings against a patient, and OCR has been able to enforce them directly since February 2026. Providers operating under both frameworks answer to one notification standard and two sets of confidentiality obligations.