The Penobscot Valley Hospital in Lincoln began warning patients and employees on Tuesday that their personal information may have been compromised nearly seven months after the security breach took place.
[RELATED: Bomb Threat at Pen Bay Hospital Prompts Police Response…]
The breach first took place on January 28, when the hospital was alerted to suspicious activity in its “information technology environment.”
The hospital initiated its response protocol, took steps to secure its systems, and hired forensic specialists to assist in an investigation, as well as notifying law enforcement.
On February 12, the investigation determined that an unauthorized individual may have accessed some files and folders.
The next update came on June 4, when the investigation determined that personal information and protected health information may have been compromised.
The data may have included names, addresses, dates of birth, Social Security numbers, financial details, and medical information.
Despite the severity of the breach, and learning that files were accessed by a bad actor as far back as February 12, the hospital only just began notifying its patients and employees that their information may have been compromised.
The hospital is offering identity monitoring services to those whose information may have been involved, and asking patients to review their recent statements from insurance companies and health care providers to search for services billed but not received.
It has now implemented “additional safeguards and technical security measures” to prevent future breaches.




Why is it big companies like Amazon never get hacked, yet every arm of our healthcare system is constantly being successfully hacked into.