Back to the register

Behavioral Health Center

ArchivedSubmitted 04/21/2017
State
ME
Covered entity type
Healthcare Provider
Individuals affected
4,229
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

Behavioral Health Center of Bangor, Maine, the covered entity (CE) reported that a hacker accessed the CE’s terminal server and obtained the protected health information (PHI) of 4,229 individuals. The CE reported that the PHI was advertised for sale on AlphaBay, a darknet market place on the Tor Network. The types of PHI included names, services provided and clinical information, addresses, dates of birth, social security numbers and phone numbers. The CE provided breach notification to HHS, affected individuals (including providing one year of triple bureau credit monitoring services), and the media. The CE also contacted the FBI, three consumer reporting agencies, and the Maine Attorney General. As a result of the incident, the CE implemented safeguards that addressed vulnerabilities that were exploited in the incident, disabled a remote server, applied audit controls standards, implemented policies and procedures to guard against malicious software, and adopted an Integrity controls policy. Finally, the CE notified OCR that they were closing their office in 2018.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.