Community Health Center, Inc. (CHC), a Connecticut-based federally qualified health center, has disclosed a data breach following a criminal cyberattack on its systems.
The breach potentially exposed the sensitive personal and health information of patients and individuals who received COVID-19 tests or vaccines at CHC clinics.
The organization has issued letters to affected individuals and set up a dedicated website to assist those who may not have received direct communication.
In a regulatory filing with the Maine Attorney General’s Office, CHC reported that the data breach impacted 1,060,936 individuals.
According to CHC report, the breach was detected on January 2, 2025, when unusual activity was identified within its computer systems. Cybersecurity experts were immediately brought in to investigate and secure the network.
It was determined that a skilled hacker had accessed and extracted data but did not delete or lock any information.
CHC stated that the hacker’s access was terminated within hours, and daily operations were not disrupted. The organization believes there is no ongoing threat to its systems.
The type of information involved varies depending on the individual’s relationship with CHC:
CHC has taken immediate steps to enhance its cybersecurity by implementing advanced monitoring software and reinforcing system protections. The organization has assured the public that there is no evidence of misuse of the compromised data at this time.
Mark Masselli, President and CEO of Community Health Center, Inc., expressed regret over the incident: “We sincerely regret any inconvenience resulting from this criminal activity and thank you for your continued support of CHC.”
To support affected individuals, CHC is offering free identity theft protection services through IDX for all patients and COVID-19 service recipients whose SSNs were involved. These services include:
Individuals whose SSNs were not impacted are encouraged to follow recommended steps for additional protection.
CHC advises those who may be impacted to contact IDX at 1-877-229-9277 for assistance or to enroll in the free identity protection services. IDX representatives are available to address questions and provide guidance on safeguarding personal information.
Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN Sandox -> Try 14 Day Free Trial.
A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…
Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…
SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…
OpenAI has launched GPT-5.1-Codex-Max, a specialized coding model designed to handle complex development tasks autonomously. The…
The U.S. Department of the Treasury, Australia, and the United Kingdom have announced coordinated sanctions…
Salesforce has issued a critical security alert identifying "unusual activity" involving Gainsight-published applications connected to…