[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fovQOYR6X_g8tjlO52w3xNs6sAvyL49VSxDPBdfSsUTs":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":18,"dataClasses":19,"description":22,"source":23,"isVerified":4,"isSpamList":24,"isSensitive":4,"processingStatus":25,"logoUrl":26,"contentUpdatedAt":17,"hasEnglishDescription":4,"severity":27},"6a677cb5353c6be0938495ce","AroostookMentalHealthCenter2026","Aroostook Mental Health Center 2026 Data Breach","aroostook-mental-health-center-2026","amhc.org",{"name":12,"sector":13,"country":14,"website":10},"Aroostook Mental Health Center","Healthcare","United States","2026-03-11T00:00:00.000Z","2026-07-27T15:43:49.776Z","2026-07-27T16:11:12.062Z",501,[20,21],"Personal information (categories not publicly disclosed)","Protected health information (categories not publicly disclosed)","\u003Cp>\u003Cstrong>The Aroostook Mental Health Center 2026 data breach\u003C\u002Fstrong> involved unauthorized access and file copying from the network of Maine behavioral-health provider AMHC. According to the public incident summary, network access occurred from March 11 to March 12, 2026. The organization noticed a network disruption affecting business operations and connectivity on March 12.\u003C\u002Fp>\n\u003Cp>The U.S. Department of Health and Human Services Office for Civil Rights HHS\u002FOCR portal lists 501 affected people for Aroostook Mental Health Center. The federal row classifies the event as a Network Server Hacking\u002FIT Incident.\u003C\u002Fp>\n\u003Ch2>How Was the Aroostook Mental Health Center Incident Verified?\u003C\u002Fh2>\n\u003Cp>The primary source is AMHC's official social-media statement dated March 26, 2026. The organization confirmed a network disruption affecting some business operations, an investigation with cyber incident specialists, and that its name had been posted on the dark web. At the time of that statement, the data-scope review was ongoing and specialists had not yet identified indications of access to sensitive client data.\u003C\u002Fp>\n\u003Cp>Later public records update that initial, interim assessment. The incident summary based on the Maine Attorney General notification says the review determined on March 21 that the network was accessed from March 11 to March 12 and that certain files containing personal information were copied. The HHS\u002FOCR row dated May 5 confirms a 501-person healthcare breach.\u003C\u002Fp>\n\u003Ch2>Incident and Investigation Timeline\u003C\u002Fh2>\n\u003Cp>The incident date is based on the earliest technical activity that can be verified from public sources. The organization began working with cyber incident specialists to restore systems, understand the access, and assess files that might have been involved.\u003C\u002Fp>\n\u003Cp>The incident summary says the review determined on March 21 that the network had been accessed between March 11 and March 12 and that certain files were copied without authorization. AMHC made its first community statement on March 26; its wording that there were no indications of sensitive-data access reflected the investigation at that time. The May 5 HHS entry is not a new attack but the later federal report for the same event.\u003C\u002Fp>\n\u003Ch2>What Information May Have Been Involved?\u003C\u002Fh2>\n\u003Cp>Public sources say certain files contained personal information but do not name detailed fields such as a Social Security number, diagnosis, treatment, insurance, or financial data. The HHS entry confirms that the event concerns a healthcare provider, but that fact alone does not prove that every particular data category appeared for all 501 people.\u003C\u002Fp>\n\u003Cp>Preserving this uncertainty avoids presenting the incident as broader or narrower than the evidence supports.\u003C\u002Fp>\n\u003Ch2>How Should the Affected-Person Count Be Interpreted?\u003C\u002Fh2>\n\u003Cp>501 is the affected-person count published in the HHS\u002FOCR row for Aroostook Mental Health Center; it is not a number of copied files or data fields. The affected-person or record count published by the official source represents the reported scope of the incident. It does not mean that every disclosed data category applied to every person. The absence of a count in the initial community statement does not invalidate the 501-person scope in the later official healthcare breach report.\u003C\u002Fp>\n\u003Cp>When an official individual notice is available, its listed data categories and protection options should guide the assessment of personal exposure.\u003C\u002Fp>\n\u003Ch2>Precautions When the Data Scope Is Unclear\u003C\u002Fh2>\n\u003Cp>When detailed categories are not public, the safest approach is to rely on an individual letter and watch for unusual account activity and phishing. Unexpected links in messages claiming to represent AMHC should not be opened. Even if a sender uses a real service, employee, or date detail, the message should be independently verified through the organization's known website or phone information.\u003C\u002Fp>\n\u003Cp>A behavioral-health relationship can be highly sensitive, making threatening, extortionate, or shaming messages especially harmful. Users should not reply or pay and should preserve evidence. An unfamiliar healthcare service or insurance claim should be reported through official channels to the provider and insurer. If an individual letter offers credit protection, eligibility and terms should be verified from that document.\u003C\u002Fp>\n\u003Ch2>How Should This Incident Be Interpreted?\u003C\u002Fh2>\n\u003Cp>AMHC said it worked with cyber incident specialists after the disruption and focused on restoring systems and understanding the scope. The organization stated that the dark-web posting of its name resulted from choosing not to deal with the cybercriminals behind the disruption and that relevant parties would be updated as the review progressed. This statement confirms the attack but does not establish undisclosed data fields.\u003C\u002Fp>\n\u003Cp>An AMHC event page in LeakData does not mean every visitor was affected or that a particular health detail was necessarily exposed. The record documents the verified network access, HHS's 501-person scope, and the limits of public evidence. Recipients should retain their individual letter and promptly contact the appropriate institution if they see signs that identity, financial, or health data is being misused.\u003C\u002Fp>","Official AMHC statement, HHS\u002FOCR breach report, and ClaimDepot summary linked to the Maine Attorney General disclosure",false,"completed","\u002Fuploads\u002Flogo\u002Famhc_org.png","Low"]