The Covenant Health 2025 data breach occurred when an unauthorized party entered the healthcare organization's information-technology environment on May 18, 2025 and accessed some patient information. Covenant Health learned of unusual activity on May 26, secured and restored its systems, and began a comprehensive investigation with third-party forensic specialists. The company's official notice directly confirms access to personal and health data.
Covenant Health's initial filing with the Maine Attorney General covered roughly 7,800 people; an updated filing dated December 31, 2025 increased the figure to 478,188 after the review was completed. pwnCount and totalRecords use this latest official total. Claims about a number of files or volume of data are not added to the person count, and LeakData imports no patient records.
How Was the Incident Confirmed?
Covenant Health's official “Notice of Data Security Incident” page publishes the date the unauthorized party entered its IT environment, the discovery date, confirmation of access to patient information, and the affected fields. The organization said it began mailing letters to known affected individuals on July 11, 2025 and would send additional notices as its detailed data review identified more patients.
The updated Maine Attorney General filing provides the expanded final scope of 478,188 people. SecurityWeek independently reported both the company notice and the increase from the initial 7,800-person filing. The sources agree that patient information was actually accessed; the Qilin group's claim of 850 GB and 1.3 million files is not a company-confirmed person total and is not used as a record count.
What Is the Attack and Investigation Timeline?
The forensic investigation determined that the unauthorized party accessed Covenant Health's environment on May 18, 2025. The organization received an alert about unusual activity on May 26 and began securing and restoring systems while investigating the source of the incident. The first public notice and letters appeared on July 11, when review of the affected information and people was still underway.
Completion of the detailed data review in December produced a substantial increase in the reported population. The December 31 update in Maine records 478,188 people. This sequence illustrates how an early notice may reflect only the subset verified at that time; LeakData uses the newest official regulator count rather than preserving the smaller interim figure as the final impact.
What Personal and Health Data Was Affected?
The company said contents varied by patient but could include a name and one or more additional fields. Confirmed categories are addresses, dates of birth, medical record numbers, and Social security numbers. These identifiers can be abused for identity verification, healthcare-account matching, and financial fraud, so the incident is assigned high severity and critical sensitivity.
Health-related categories also included treatment information such as diagnoses, treatment dates, and treatment types, as well as health-insurance information. Not every field was involved for every person; the company used the phrase “one or more.” LeakData limits its classes to the categories in the official notice and does not assume undisclosed fields such as medications, laboratory results, or payment-card data.
Which Organizations and Patients Were in Scope?
Covenant Health is based in Andover, Massachusetts and provides healthcare services across New England and Pennsylvania. The official notice identifies affiliated entities as St. Joseph Hospital in Nashua, New Hampshire; St. Joseph Healthcare in Bangor, Maine; and St. Mary's Health System in Lewiston, Maine. This entry treats them as one breach covered by the same corporate investigation.
The 478,188 figure is Covenant Health's updated affected-person total, not an estimate created by separately adding regulator filings for each facility. Separate records are therefore not created for the affiliated hospitals, and a person whose information appeared at more than one facility is not intentionally counted again. All services in every operating state are not assumed affected; scope remains limited to notified individuals.
What Should Affected People Do?
Covenant Health offered free credit monitoring and identity-theft protection to people whose Social security numbers may have been involved. Notice recipients should enroll within the stated period, monitor credit reports for new accounts, and review unfamiliar insurance claims. If a health-plan statement lists a service that was not received, the individual should contact the plan and healthcare organization promptly.
The company said it was unaware at the notice date of fraudulent misuse of personal information related to the event. That does not remove the long-term risk, particularly because Social Security and medical record numbers are difficult or impossible to replace. A security freeze, fraud alert, strong multifactor authentication, and monitoring of tax accounts can be considered according to each person's documented exposure.
How Should This LeakData Record Be Read?
pwnCount and totalRecords are 478,188, the updated scope filed with the Maine Attorney General on December 31, 2025. breachDate is May 18, 2025, the first unauthorized-access day established by the investigation. Detection on May 26, initial notification on July 11, and completion of the review in December are separate stages; the old 7,800-person interim notice is not added to the final total.
importedRecordCount is zero, and LeakData stores no names, addresses, Social security numbers, medical record numbers, diagnoses, or insurance information. The entry contains only the verified event summary, current person count, data classes, timeline, and protection guidance. If the regulator or company publishes a newer correction, the total and content can be reassessed from that primary document.