Central Maine Healthcare has agreed to establish a $1,368,025 settlement fund to resolve consolidated class action claims arising from its 2025 data breach.
What happened
The healthcare system detected unusual network activity on June 1, 2025, and an investigation later determined that an unauthorized party had accessed its information technology environment between March 19 and June 1. According to Central Maine Healthcare, the intruder may have accessed or acquired files containing names, dates of birth, treatment information, dates of service, provider names, health insurance information and, for some patients, Social Security numbers.
The Data Security Incident noted, “On November 6, 2025, Central Maine Healthcare completed its investigation and analysis of the data security incident. Central Maine Healthcare first became aware of the incident on June 1, 2025, after it detected unusual activity in its information technology (“IT”) network and immediately took steps to protect and secure its systems.”
The settlement agreement identifies a class list of approximately 218,884 people who received individual breach notices. On July 9, 2026, the Maine Business and Consumer Court preliminarily approved the proposed settlement without deciding whether Central Maine Healthcare had violated the law.
In the know
Affected patients argued that the organization had a responsibility to take reasonable steps to protect the information in its care and that its security measures may not have met that standard. This responsibility is supported by the HIPAA Security Rule, which requires healthcare providers to protect electronic health information, and by Maine’s data breach law, which requires organizations to investigate breaches and promptly notify affected residents.
However, patients generally cannot sue an organization directly for violating HIPAA. Private data breach lawsuits instead rely on legal claims such as negligence, breach of contract, or violations of consumer protection law. In this case, the accusations came from the affected patients’ consolidated complaint, not from a government finding that Central Maine Healthcare broke the law. An organization can be both the victim of a cyberattack and potentially responsible for failing to take reasonable precautions against it.
Why it matters
The Central Maine Healthcare settlement fits a wider pattern of healthcare data breach litigation recently covered by Paubox. In Healthcare Services Group agrees to $3M settlement after 2024 breach, several lawsuits were consolidated before the organization agreed to establish a settlement fund while continuing to deny wrongdoing. ApolloMD agrees to $4.02M settlement following class action lawsuit followed the same path after four separate lawsuits were combined into one case.
The Central Maine agreement also resembles LifeBridge Health agrees to $575,000 settlement over 2024 data breach, which offered reimbursement for documented losses, an alternative cash payment, and additional monitoring while LifeBridge denied liability.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
Can delayed breach notification increase a healthcare organization’s legal exposure?
Yes. HIPAA generally requires notification without unreasonable delay and no later than 60 days after discovering a breach of unsecured protected health information, while some state laws impose shorter deadlines.
Why is determining the breach discovery date so necessary?
The discovery date can start regulatory notification periods and affect whether patients argue that the organization responded too slowly.
Is a healthcare organization responsible when the breach begins with a vendor?
Responsibility depends on which organization controlled the information, the cause of the incident, contractual duties, and each party’s response. A business associate agreement does not remove the covered entity’s responsibility to select appropriate vendors and monitor how protected health information is handled.
