Cornerstone Behavioral Healthcare (Cornerstone) is issuing this notice pursuant to the Breach Notification Rule of the Health Insurance Portability and Accountability Act (HIPAA) and Maine’s Notice of Risk to Personal Data Act.
On May 26, 2026, Cornerstone discovered that a breach of the security of certain PHI that Cornerstone maintains occurred as a result of a ransomware attack. This ransomware attack was initiated on the same day it was discovered, and any access the ransomware attackers had to Cornerstone’s systems was suspended within an hour of discovery. Ransomware is a type of malicious software that attempts to deny access to data. In this case, the ransomware was encrypting Cornerstone’s data so that Cornerstone could not access it.
The ransomware included a demand that Cornerstone pay a ransom to regain access to its data. Cornerstone did not pay the ransom and was able to stop the attack and restore its electronic data. Cornerstone believes that less than 10% of the data in the affected computers and servers may have been encrypted by the ransomware attackers before Cornerstone was able to quickly power them down upon discovery of the attack.
Cornerstone undertook a prompt investigation of the incident and has determined that the following types of PHI and/or personal information concerning 2,830 individuals may have been compromised as a result of this incident, including: names, addresses, other contact information, dates of birth, health care information, substance use disorder treatment information, insurance/MaineCare information and social security numbers.
On July 22, 2026, Cornerstone’s continued investigation of the ransomware incident revealed that a log of appointment reminders for an additional 12,000 individuals may have been viewed or accessed during the ransomware attack. This log included patient names, dates of birth, appointment times and reminders of documentation due, and Cornerstone is investigating whether any additional PHI or personal information was involved with respect to these 12,000 individuals.
Cornerstone has taken the following measures to investigate this breach, to mitigate the harm to persons affected by the breach and to protect against any further breaches:
- Cornerstone’s leadership and information technology employees investigated the scope of the attack and promptly restored the affected data.
- Cornerstone wiped the affected computers and purchased new computers for its staff to use going forward.
- Cornerstone also reviewed its systems, policies and procedures and implemented additional security measures to reduce the likelihood of an attack like this from occurring in the future. These measures included implementing extra layers of security for its servers and providing special training for its employees on ransomware.
Containing Candida Auris Across the Care Continuum
Early Entry: Manager's Critical Role in Construction Planning
OhioHealth Van Wert Hospital Earns Critical Access Hospital Designation
Designing a Home Away from Home
Stephens County Hospital Becoming Part of Wellstar Health System