
Bay Cove Human Services said that the data security incident it suffered last year compromised the sensitive personal inflation of close to 25,000 individuals.
Operating in Greater Boston and southeastern Massachusetts, Bay Cove Human Services is a non-profit rehabilitation centre that focuses on mental illness, detoxification, clinical stabilisation, short and long-term residential treatment, behavioural health, and more.
In a data security incident notice, Bay Cove said that on December 30, it detected unusual activity in its internal network. The organisation immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
“The investigation determined that data may have been accessed or downloaded without authorisation from certain Bay Cove systems but could not identify the specific data involved,” the centre said.
The compromised data includes patients’ names, dates of birth, Social Security numbers, diagnosis or treatment information, and other health-related information. In a filing with the Office of Maine Attorney General, Bay Cove said that it has identified at least 24,791 individuals who were impacted by the incident.
The healthcare provider added that the incident did not affect its electronic medical records system. “As soon as it discovered this incident, Bay Cove implemented measures to enhance security and minimise the risk of a similar incident occurring in the future,” it added.
Bay Cove has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and state attorney general. It has also offered one year of complimentary identity protection and credit monitoring services through IDX to all affected individuals.
At the time of publishing, no known hacker group claimed responsibility for the ransomware attack on Bay Cove. The organisation also did not share details on who was behind the cyber attack, how much data was compromised, or whether it has received a ransom demand.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543