Media Notice: Notice of Data Security Incident
Cardiovascular Institute of New England (“CINE”) is issuing this notice about a data security incident that may have resulted in unauthorized access to certain personal and protected health information of its employees and patients. Please know that CINE moved swiftly to investigate and remediate the incident. Information about the incident, CINE’s response, and the steps consumers may take to help protect their information are detailed below.
Importantly, CINE does not have any reason to believe that there has been any identity theft, fraud or misuse of information in connection with this incident.
What Happened? On or around February 12, 2026, CINE observed unusual activity in its email environment (the “Incident”). In response, CINE began an investigation with the assistance of third-party cybersecurity specialists to determine the nature and scope of the activity. While there is no indication that personal information was targeted or misused, out of an abundance of caution, CINE is notifying certain individuals whose personal information was in the impacted email account and may have been subject to unauthorized access.
CINE prioritized the containment and remediation of the Incident, an effort which has since completed. In addition to conducting a thorough forensic investigation of the Incident, CINE undertook a comprehensive review of the impacted data to determine what information was impacted. The review process, which was completed on or around July 14, 2026, determined that personal information may have been subject to unauthorized access. Based on CINE’s investigation and remediation efforts, there is no evidence that the impacted information has been misused as a result of this incident.








