Alpine Ear, Nose, and Throat, a healthcare provider, experienced a data breach that began on November 19, 2024. The incident, involving an external system breach (hacking), was confirmed by the company after a forensic investigation found unauthorized access to and exfiltration of personal information. The BianLian ransomware group claimed responsibility for the cyberattack.
The breach affected 65,648 individuals in the United States, including 10 Maine residents. Exposed data types include names, demographic information, dates of birth, medical information, health insurance information, financial account information, credit card numbers, and Social Security numbers. While the company stated that there was no known fraudulent misuse of the data at the time of notification, the full extent of potential harm remains unclear.
Notices were mailed to affected individuals starting January 26, 2026, offering 12 to 24 months of complimentary credit monitoring and identity theft restoration services through IDX. The company also published a substitute notice on its website. Details about data breaches can emerge over time, and affected individuals may experience delayed notifications.