LeMaitre Vascular, a publicly traded medical device manufacturer, discovered a network disruption in January 2026. It took until mid-September to finish reviewing what was taken and notify the people affected — 251 days later.
LeMaitre Vascular, Inc. (NASDAQ: LMAT), a medical device manufacturer headquartered in Burlington, Massachusetts, has notified residents in multiple states of a data breach. According to the company’s own notification letter, LeMaitre discovered a network disruption on or around January 10, 2026, and immediately engaged independent cybersecurity experts to investigate. The company states its data review didn’t conclude until on or about September 14, 2026, with written notice following four days later, on September 18, 2026.
Source: LeMaitre Vascular, Inc.’s New Hampshire Department of Justice notification letter, dated 09/18/2026 (signed by Alyssa R. Watzman of Constangy, Brooks, Smith & Prophete); Massachusetts Office of Consumer Affairs and Business Regulation annual report filing 2026-1579, reported 09/18/2026; Vermont Attorney General’s Office security breach notice, reported 09/18/2026.
How Many People Are Affected?
LeMaitre’s filings confirm at least the following, across three states:
- 955 Massachusetts residents — the largest confirmed state count
- Approximately 92 New Hampshire residents
- 2 Vermont residents
That’s at least 1,049 confirmed individuals across just three states. LeMaitre has not disclosed a national total, and as a publicly traded company selling medical devices nationwide, the true number affected is likely higher.
What Information Was Exposed?
According to LeMaitre’s own New Hampshire notification letter — the most detailed source reviewed — the exposed information includes:
- Full name
- Social Security number
- USCIS Alien Registration number
- Financial account number
The inclusion of USCIS Alien Registration numbers is notable and unusual — it suggests the exposed records may include immigration-status documentation for employees or other individuals connected to the company, not just standard consumer or patient data.
Massachusetts’s own annual breach report codes this filing differently, marking medical information and driver’s license numbers as involved — categories the New Hampshire letter does not support. We’re treating LeMaitre’s own notification letter as the more reliable source and flagging the discrepancy rather than picking one version silently. If medical information was in fact involved, that would meaningfully change the picture, and we’ll update this post if that’s confirmed.
Why the 251-Day Delay Matters
LeMaitre’s own letter describes the review as “complex and time-consuming” — but that explanation is worth weighing against the size of the confirmed affected group. Enumerating 955 Massachusetts residents and 92 New Hampshire residents is not obviously the kind of task that requires eight months. LeMaitre detected the disruption promptly and brought in outside experts right away, so this isn’t a story about slow detection — the delay sits entirely in the review and notification process that followed.
Do You Have Legal Options?
Companies that collect and store Social Security numbers, immigration documentation, and financial account information have a legal duty to secure that data and to notify affected individuals without unreasonable delay.
If you received a notice letter from LeMaitre Vascular, Inc., contact Emery | Reddy today for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
FAQ
Who is affected by the LeMaitre Vascular data breach?
LeMaitre’s own regulatory filings confirm at least 955 Massachusetts residents, approximately 92 New Hampshire residents, and 2 Vermont residents — a combined total of at least 1,049 people across three states. No national total has been disclosed.
What information was exposed?
According to LeMaitre’s New Hampshire notification letter, the exposed data includes full name, Social Security number, USCIS Alien Registration number, and financial account number. A separate Massachusetts filing suggests medical information and driver’s license numbers may also be involved, though this isn’t confirmed by the company’s own letter.
Why did it take 251 days to notify people?
LeMaitre discovered the network disruption around January 10, 2026, and immediately brought in outside cybersecurity experts. The company says its review of the affected data didn’t conclude until around September 14, 2026, and notice followed four days later — a total gap of 251 days that the company describes only as reflecting a ‘complex and time-consuming’ review.
What is a USCIS Alien Registration number, and why does it matter here?
It’s the identification number the U.S. government assigns to noncitizens through immigration processes. Its presence in this breach suggests immigration-status records were exposed, which is an unusually sensitive category that goes beyond typical financial identity-theft risk.
Do I have a legal claim?
Companies that collect and store Social Security numbers, immigration documentation, and financial account information have a legal duty to secure that data and to notify affected individuals without unreasonable delay. If you received a notice letter from LeMaitre Vascular, Inc., contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.