Maine Law Mandates Cybersecurity Plans for Hospitals to Mitigate Cyber Risks
A new law in Maine requires all licensed hospitals to develop and maintain cybersecurity plans in compliance with federal standards starting next year. This legislation, signed by the governor in April, aims to reduce clinical risks and ensure hospital operations can continue during cyber incidents. The law was introduced following cyberattacks on Maine hospitals in May and June 2025, which affected communications, lifesaving equipment, and vital tools, impacting at least one-third of the state's residents. The outages led to missed routine care and canceled complex treatments. The law mandates annual cybersecurity training, penetration testing, and incident planning audits. It also requires hospitals to report incidents dating back to 2024 to build future resilience.