Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Covenant Health Data Breach Impacts 478,000 Individuals

The Qilin ransomware group hacked the healthcare organization and stole data from its systems in May 2025. 

Healthcare data breach

Andover, Massachusetts-based Covenant Health, Inc. has informed authorities that a data breach discovered in May 2025 impacts more than 478,000 individuals.

Covenant Health offers healthcare services at over a dozen locations across Massachusetts, Maine, New Hampshire, Pennsylvania, Rhode Island, and Vermont.

The organization is informing customers that their personal and health information may have been compromised as a result of a hacker attack that occurred on May 18, 2025. 

The intrusion was discovered on May 26, and it took until December for Covenant Health to complete its investigation.

Covenant Health first disclosed the data breach to the Maine Attorney General’s Office in July, when it reported that only 7,800 individuals had been impacted.

In an updated notification to the Maine AGO on December 31, the healthcare organization revealed that the number of affected individuals is actually 478,188.

Advertisement. Scroll to continue reading.

It’s not uncommon for healthcare data breaches to impact hundreds of thousands and even millions of individuals.

Covenant Health said the hackers obtained information such as name, date of birth, address, SSN, medical record number, health insurance information, and treatment information.

The Qilin ransomware group took credit for the attack on Covenant Health in June 2025, claiming to have stolen more than 1.3 million files with a total size of 850 GB. 

Data allegedly stolen from the healthcare organization has since been made public by the cybercrime group, which indicates that a ransom has not been paid.

Related: 113,000 Impacted by Data Breach at Virginia Mental Health Authority

Related: 700,000 Records Compromised in Askul Ransomware Attack

Related: Tri-Century Eye Care Data Breach Impacts 200,000 Individuals

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.