The Wayne Memorial Hospital 2024 data breach was a ransomware event in which the Georgia hospital determined June 3, 2024 that a third party had entered its network, encrypted some data, and left a ransom note. A forensic investigation confirmed that the unauthorized person accessed a limited number of systems between May 30 and June 3.
A later filing with the Maine Attorney General reports 163,440 affected people nationwide. The earlier HHS/OCR row dated August 2, 2024 lists 2,500 before the comprehensive file review was complete. Those figures are not additive; LeakData uses the later total, and importedRecordCount is zero because no raw person-level data was imported.
How Was the Wayne Memorial Hospital Breach Confirmed?
The primary source is the Notice of Data Security Incident PDF on the hospital's own domain. It directly confirms ransomware detection, the May 30–June 3 access window, network disconnection, restoration from backups, file review, August 27, 2025 notification letters, and the disclosed identity, financial, and health fields.
The second source is the official Maine Attorney General filing, which gives a nationwide total of 163,440 after the completed review. The 2,500-person network-server hacking/IT incident row in the HHS Office for Civil Rights portal represents an earlier stage. Matching dates and entity identity show evolving scopes of one event, not separate breaches.
What Happened Between May 30 and June 3, 2024?
Wayne Memorial Hospital discovered June 3 that an unauthorized third party had entered the network, encrypted some data, and left a ransom note. The hospital disconnected network access, took certain systems offline, began restoring operations securely from backups, and engaged legal counsel and specialist cybersecurity professionals.
The forensic investigation found evidence that the actor accessed a limited number of WMH systems from May 30 through June 3. The provider posted a public notice on its website and in the Press Sentinel in Jesup, Georgia on August 2, 2024. After completing its person-level file review, it mailed notices August 27, 2025.
What Identity, Account, and Card Information Was Involved?
Identity fields that varied by person were names, dates of birth, Social security numbers, driver's license numbers, and state identification numbers. User ids and passwords, financial account numbers, credit or debit card numbers, card expiration dates, and CVV codes were also potentially involved. The record does not assume every recipient had every field affected.
A person whose password was involved should replace the same or similar password on other accounts with unique values and enable multifactor authentication where available. Someone with card or account fields involved can check unfamiliar transactions and contact changes through a known bank channel and should not sign in through an unexpected link.
What Health and Insurance Information Was Involved?
Health fields were Medicare or medicaid numbers, health-insurance member numbers, healthcare provider numbers, diagnoses, medical histories, treatment information, prescription information, and laboratory test results or images. These can expose patient and provider context and make medical-identity scams more persuasive.
Notice recipients can inspect explanations of benefits, patient-portal sessions, unfamiliar treatments and prescriptions, insurance-member changes, and messages using laboratory results as a lure. Even a communication containing a real diagnosis or result is not automatically legitimate; use a known hospital number or open the portal directly.
Why Do the 163,440 and 2,500 Figures Differ?
The 2,500 people reported to HHS August 2, 2024 reflect an early healthcare scope shortly after the attack. The hospital continued reviewing accessed files person by person, and its August 2025 notifications brought the nationwide population to 163,440. The current regulatory filing supersedes the preliminary scope; the two figures must not be added.
pwnCount and totalRecords are therefore 163,440. importedRecordCount remains zero to show that LeakData does not hold these people's files, user accounts, passwords, or health records. Resident counts reported to individual states are subsets of the nationwide figure and are not added a second time, preventing duplicate counting.
How Did the Hospital Respond and What Should Recipients Do?
WMH said it secured its systems, added new intrusion-detection and response tools, reset all passwords, and made further network-security improvements. It offered free credit monitoring and identity-theft protection to affected people. The official PDF lists the toll-free number 1-833-426-4616 for questions.
A recipient should rely on the fields in their own letter and consider a credit freeze and fraud alert for an SSN or ID number, account changes for a password, transaction monitoring for financial fields, and benefits and patient-record review for health fields. Do not share a password, full SSN, payment, or one-time code in a message using the Wayne Memorial name.