[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3jy1vPJHmGKKX4xff4bKdED8DCjZrrPYCcSKizWclwU":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":17,"pwnCount":18,"totalRecords":19,"dataClasses":20,"description":29,"source":30,"isVerified":4,"isSpamList":31,"isSensitive":4,"severity":32,"processingStatus":33,"logoUrl":34,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a670bd8f2ee442f57b8afdd","PenobscotValleyHospital2026","Penobscot Valley Hospital 2026 Data Breach","penobscot-valley-hospital-2026","pvhme.org",{"name":12,"sector":13,"country":14,"website":10},"Penobscot Valley Hospital","Healthcare","United States","2026-01-28T00:00:00.000Z","2026-07-27T07:42:16.331Z","2026-07-27T09:30:00.000Z",0,null,[21,22,23,24,25,26,27,28],"Personal information","Protected health information","Names","Addresses","Dates of birth","Social Security numbers","Medical information related to hospital visits","Financial information","\u003Cp>\u003Cstrong>The Penobscot Valley Hospital 2026 data breach\u003C\u002Fstrong> was a confirmed personal and health-data security event identified through suspicious activity in the information-technology environment of a critical-access hospital in Maine. According to the hospital's official statement, it received the alert on January 28, 2026, and the investigation found on February 12 that an unauthorized individual may have accessed certain files and folders.\u003C\u002Fp>\n\u003Cp>Penobscot Valley Hospital determined on June 4 that the affected files may have contained personal information and protected health information. Public sources do not disclose a deduplicated nationwide total. LeakData does not invent a count: pwnCount and totalRecords are zero, importedRecordCount is zero, and no patient or employee rows were imported.\u003C\u002Fp>\n\u003Ch2>How Was the Penobscot Valley Hospital Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is the “Post-Incident Media Notice” on the hospital's own website. It directly states the January 28 alert, incident response, forensic specialists, law-enforcement notification, February 12 access assessment, June 4 data finding, confirmed information classes, and post-incident safeguards.\u003C\u002Fp>\n\u003Cp>The Vermont Attorney General security-breach notice archive provides an official state notification route for the event. Claim Depot links the organization statement and state disclosure and independently summarizes the timeline and data categories. The sources align on the existence of the event, hospital identity, and core dates.\u003C\u002Fp>\n\u003Ch2>What Happened Between January 28 and June 4?\u003C\u002Fh2>\n\u003Cp>The hospital learned of suspicious activity in its IT environment on January 28, activated incident-response procedures, secured systems, engaged third-party forensic specialists, and notified law enforcement. The public statement does not identify the initial entry method behind the suspicious activity or the actor.\u003C\u002Fp>\n\u003Cp>On February 12, the investigation determined that an unauthorized individual may have accessed certain files and folders. On June 4, the data review found that those files may have contained PII and PHI. The source does not definitively say files were copied, downloaded, or published, and LeakData does not add that inference.\u003C\u002Fp>\n\u003Ch2>What Identity Information May Have Been Affected?\u003C\u002Fh2>\n\u003Cp>The information varied by person but may include names together with addresses, dates of birth, and Social Security numbers. That combination may raise risks of fraudulent credit applications, tax-identity fraud, targeted phishing, and account-takeover attempts. The same fields cannot be assumed to apply to every potentially affected person.\u003C\u002Fp>\n\u003Cp>The official hospital statement does not expressly list email addresses, phone numbers, passwords, driver's licenses, passports, or other government identifiers. Documents referenced in general protective guidance should not be treated as incident-confirmed data. LeakData records only the identity categories directly named by the primary source.\u003C\u002Fp>\n\u003Ch2>What Health and Financial Information Was Involved?\u003C\u002Fh2>\n\u003Cp>The official text identifies medical information related to visits to Penobscot Valley Hospital and financial information as two broad categories. Those fields may connect a patient with a care relationship or increase exposure to financial fraud. The statement does not specify the clinical or financial subfields present.\u003C\u002Fp>\n\u003Cp>The source does not expressly confirm diagnoses, treatments, prescriptions, medical-record numbers, health-insurance numbers, dates of service, bank accounts, payment cards, or financial-account codes. More granular examples in secondary summaries do not replace the primary statement. LeakData preserves the health and financial categories at the breadth published by the source.\u003C\u002Fp>\n\u003Ch2>How Did the Hospital Respond?\u003C\u002Fh2>\n\u003Cp>Penobscot Valley Hospital secured systems, conducted forensic work, notified law enforcement, and said it implemented additional safeguards and technical security measures to better protect and monitor its systems. The organization reaffirmed its commitment to confidentiality and security and began notifying identified patients and employees.\u003C\u002Fp>\n\u003Cp>Complimentary identity-monitoring services were offered to people whose information may have been involved. Because the public statement does not name the provider, service duration, or a general enrollment deadline, LeakData does not guess those details. A call center was established at 1-833-319-8871 on weekdays from 8:00 a.m. to 8:00 p.m. Eastern Time.\u003C\u002Fp>\n\u003Ch2>What Should Affected People Do?\u003C\u002Fh2>\n\u003Cp>Notified patients and employees should review credit reports, account activity, healthcare-provider statements, and insurance explanation-of-benefits statements for unfamiliar accounts, transactions, or services. If an SSN was involved, a credit freeze, fraud alert, and IRS Identity Protection PIN may be appropriate safeguards.\u003C\u002Fp>\n\u003Cp>SSNs, dates of birth, health information, verification codes, or payments should not be provided in unexpected email, messages, or calls claiming to represent Penobscot Valley Hospital. Service eligibility should be confirmed only through the official call center. LeakData does not host, distribute, or make searchable the incident files, patient or employee information, or person records.\u003C\u002Fp>","Official Penobscot Valley Hospital notice confirming possible unauthorized access to files containing PII and PHI",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fpvhme_org.png"]