As Northern Light Health announced on Monday, some patient information may have been stolen by malicious actors.

The Brewer-based organization said some confidential patient health information was likely stolen by hackers during a ransomware against Blackbaud, a South Carolina company that provides cloud data storage and other services primarily to nonprofits. The attack, which began in February and was detected by Blackbaud in May, affected thousands of organizations, including nonprofits in Maine.
Among the organizations affected were Northern Light Health Foundation, LifeFlight of Maine, The Opportunity Alliance , and the Maine Cancer Foundation. data was stolen by malicious actors, and some of it is suspected to have been used for illegal activities.
According to the organizations, the stolen data contained some contact information for donors, but no banking or financial information.

Blackbaud said it was able to thwart the attack once it was discovered, but was ultimately forced to pay the ransom to avoid selling the stolen data. According to the company, the hackers assured it that they would destroy the data once the ransom was received, and both it and law enforcement officials said they believe they did so, as none of the information in question was found on the dark web.
Northern Light Health said its investigation indicates that patient names, addresses, phone numbers, email addresses, dates of birth, the hospital where they were treated, the date of treatment and possibly the department where they were treated may have been stolen in the Blackbaud attack. Northern Light's notification, however, said no credit card information was stolen.
The organization said patients should be aware of possible attempts at identity theft or fraud, so they should be especially wary of the messages they receive and the pages they may be directed to.
