Heart South Cardiovascular Group experienced a data breach that began on November 11, 2025. The company discovered the breach on February 12, 2026, and reported it to the Maine Attorney General, notifying affected individuals on April 6, 2026. The incident involved an internal system breach, and a limited amount of data was subsequently posted on the dark web by the Rhysida ransomware group.
The breach confirmed the exposure of names, email addresses, phone numbers, dates of birth, and Social Security numbers for 46,666 individuals. While samples posted by the ransomware group suggested the potential exposure of ID scans and medical records, Heart South's investigation did not confirm unauthorized network access or data theft beyond the dark web posting. Free credit monitoring and identity theft restoration services are being offered to those affected.
More details may emerge as investigations continue, and consumer notices may be delayed.