The Mainline Health Systems 2024 data breach was a security incident on the Arkansas healthcare organization's network on or about April 10, 2024. Mainline's official notification letter confirms that certain network files containing personal and protected health information were affected. The HHS OCR public record reports a scope of 101,104 people.
Possible fields include names, dates of birth, Social Security and driver's-license numbers, financial-account and payment-card details with access information, medical-record and patient identifiers, Medicaid, health insurance, diagnoses, treatments or procedures, clinical data, prescriptions, and provider information. Not every field applied to every person. LeakData imported no patient rows, and importedRecordCount is zero.
How Was the Mainline Health Systems Breach Confirmed?
The primary source is the Notice of Data Security Incident issued for Mainline Health Systems Inc. The organization says the event occurred on or about April 10, 2024, federal law enforcement was notified, outside cybersecurity professionals were engaged, and a manual review was performed to determine the extent of compromised information on its network.
The Maine Attorney General filing confirms 101,104 people and a June 20, 2025 consumer-notification date. HHS OCR uses the same total and classifies Mainline as a Healthcare Provider, the event as a Hacking/IT Incident, and the information location as Network Server. The HIPAA Journal independently compared the letter, state filing, and federal scope.
When Was the Incident and File Review Completed?
Mainline experienced the security incident on or about April 10, 2024 and began investigating as soon as it learned of the issue. The breachDate field uses that publicly disclosed event date. The sources do not provide an earlier access start or a specific end day, so the entry does not invent an unsupported intrusion window.
The organization supplemented its technical investigation with a manual review to identify affected files and people requiring notice. On May 21, 2025, it determined that certain files contained protected personal and health information. Letters were mailed June 20; the roughly fourteen-month interval represents investigation and data matching, not the duration of attacker access.
What Information Was Affected?
The official letter lists full names with dates of birth, Social security numbers, US driver's-license numbers, financial-account numbers and access information, payment-card numbers and access information, medical-record numbers, patient identifiers, Medicaid numbers, and health-insurance policy and group numbers.
Health-related fields include medical diagnoses, treatments or procedures, clinical information, prescriptions, provider names, and provider locations. dataClasses contains only categories directly disclosed by the letter. The notice expressly says not all data elements were affected for every individual, so the same combination is not attributed to all 101,104 people.
What Does the 101,104-Person Scope Mean?
The pwnCount and totalRecords fields use the exact 101,104-person value reported by both HHS OCR and the Maine regulatory filing. It represents individuals notified because of the incident, not a number of files, database rows, medical services, or data fields. One person may have information in several categories.
The sources describe network files as impacted and information as compromised but do not report public release, sale, or attribution to a named actor. The entry preserves the real unauthorized network incident and sensitive-data impact without adding unsupported claims about ransomware, an exfiltration technique, or a threat group.
What Measures Did Mainline Take?
After learning of the incident, the organization notified federal law enforcement and engaged outside cybersecurity professionals who routinely investigate this type of event. File contents were manually reviewed in addition to the technical inquiry. Mainline said it knew of no identity or financial fraud resulting from the incident at notification.
People whose Social security numbers were affected were offered complimentary credit monitoring. Mainline also supplied detailed resources on fraud alerts, security freezes, credit-report review, and protection against medical identity theft. A lack of known misuse does not remove the future risk associated with durable identity and health data.
What Should Affected People Do?
Notice recipients whose Social security numbers were involved should activate the offered monitoring before the stated deadline. Credit reports, financial statements, payment-card activity, and health-insurance explanations of benefits should be checked regularly for unfamiliar accounts, transactions, medical services, prescriptions, or insurance claims.
If account or card details were affected, contact the bank or card issuer through an official channel to determine whether replacement is appropriate. Unknown clinical services should be confirmed with the provider and insurer, and unexpected messages using Mainline's name deserve caution. LeakData does not host affected data; it provides verified incident metadata and practical follow-up guidance.