All Breaches
May 30, 2024 Verified Sensitive Record Healthcare

Wayne Memorial Hospital 2024 Data Breach

The Wayne Memorial Hospital 2024 data breach was a ransomware event in which the Georgia hospital determined June 3, 2024 that a third party had entered its network, encrypted some data, and left a ransom note. A forensic investigation confirmed that the unauthorized person accessed a limited number of systems between May 30 and June 3.

A later filing with the Maine Attorney General reports 163,440 affected people nationwide. The earlier HHS/OCR row dated August 2, 2024 lists 2,500 before the comprehensive file review was complete. Those figures are not additive; LeakData uses the later total, and importedRecordCount is zero because no raw person-level data was imported.

How Was the Wayne Memorial Hospital Breach Confirmed?

The primary source is the Notice of Data Security Incident PDF on the hospital's own domain. It directly confirms ransomware detection, the May 30–June 3 access window, network disconnection, restoration from backups, file review, August 27, 2025 notification letters, and the disclosed identity, financial, and health fields.

The second source is the official Maine Attorney General filing, which gives a nationwide total of 163,440 after the completed review. The 2,500-person network-server hacking/IT incident row in the HHS Office for Civil Rights portal represents an earlier stage. Matching dates and entity identity show evolving scopes of one event, not separate breaches.

What Happened Between May 30 and June 3, 2024?

Wayne Memorial Hospital discovered June 3 that an unauthorized third party had entered the network, encrypted some data, and left a ransom note. The hospital disconnected network access, took certain systems offline, began restoring operations securely from backups, and engaged legal counsel and specialist cybersecurity professionals.

The forensic investigation found evidence that the actor accessed a limited number of WMH systems from May 30 through June 3. The provider posted a public notice on its website and in the Press Sentinel in Jesup, Georgia on August 2, 2024. After completing its person-level file review, it mailed notices August 27, 2025.

What Identity, Account, and Card Information Was Involved?

Identity fields that varied by person were names, dates of birth, Social security numbers, driver's license numbers, and state identification numbers. User ids and passwords, financial account numbers, credit or debit card numbers, card expiration dates, and CVV codes were also potentially involved. The record does not assume every recipient had every field affected.

A person whose password was involved should replace the same or similar password on other accounts with unique values and enable multifactor authentication where available. Someone with card or account fields involved can check unfamiliar transactions and contact changes through a known bank channel and should not sign in through an unexpected link.

What Health and Insurance Information Was Involved?

Health fields were Medicare or medicaid numbers, health-insurance member numbers, healthcare provider numbers, diagnoses, medical histories, treatment information, prescription information, and laboratory test results or images. These can expose patient and provider context and make medical-identity scams more persuasive.

Notice recipients can inspect explanations of benefits, patient-portal sessions, unfamiliar treatments and prescriptions, insurance-member changes, and messages using laboratory results as a lure. Even a communication containing a real diagnosis or result is not automatically legitimate; use a known hospital number or open the portal directly.

Why Do the 163,440 and 2,500 Figures Differ?

The 2,500 people reported to HHS August 2, 2024 reflect an early healthcare scope shortly after the attack. The hospital continued reviewing accessed files person by person, and its August 2025 notifications brought the nationwide population to 163,440. The current regulatory filing supersedes the preliminary scope; the two figures must not be added.

pwnCount and totalRecords are therefore 163,440. importedRecordCount remains zero to show that LeakData does not hold these people's files, user accounts, passwords, or health records. Resident counts reported to individual states are subsets of the nationwide figure and are not added a second time, preventing duplicate counting.

How Did the Hospital Respond and What Should Recipients Do?

WMH said it secured its systems, added new intrusion-detection and response tools, reset all passwords, and made further network-security improvements. It offered free credit monitoring and identity-theft protection to affected people. The official PDF lists the toll-free number 1-833-426-4616 for questions.

A recipient should rely on the fields in their own letter and consider a credit freeze and fraud alert for an SSN or ID number, account changes for a password, transaction monitoring for financial fields, and benefits and patient-record review for health fields. Do not share a password, full SSN, payment, or one-time code in a message using the Wayne Memorial name.

163.4 Thousand
Affected Accounts
17
Data Types
High
Severity
Yes
Verification

Exposed Data Types

17
Names
Dates of birth
Social security numbers
Driver’s license numbers
State identification numbers
User ids and passwords
Financial account numbers
Credit or debit card numbers
Card expiration dates or cvv codes
Medicare or medicaid numbers
Health insurance member numbers
Healthcare provider numbers
Diagnoses
Medical histories
Treatment information
Prescription information
Laboratory test results or images

Additional Information

Added DateJuly 27, 2026
Breach DateMay 30, 2024
Domainwmhweb.com
SourceOfficial Wayne Memorial Hospital ransomware notice, Maine Attorney General filing, and HHS/OCR report
Last Content UpdateJuly 27, 2026

Verification and editorial method

LeakData compares the incident name, date, affected-record count, and exposed data types with accessible sources. Unverified fields are not presented as facts, and records are updated when new evidence becomes available.

Report missing or incorrect information