LeMaitre Vascular, a Burlington, Massachusetts maker of vascular surgery devices, notified state regulators on September 18, 2026 of what its own letter called a recent data security incident. The notification named no cause, no date of intrusion, and no date of discovery. State filings put the toll at more than 1,047 people, including 955 Massachusetts residents, 92 in New Hampshire, and 2 in Vermont, with other affected states not yet disclosed.

The exposed data spans names, Social Security numbers, driver's license numbers, USCIS Alien Registration numbers, financial account numbers, and medical records, according to the company's breach letters. LeMaitre is offering 24 months of TransUnion identity protection, including credit monitoring, dark web monitoring, and up to $1 million in fraud reimbursement. Enrollment closes December 18, 2026.

LeMaitre's letter gives no incident date, no discovery date, and no stated cause. That gap usually means the forensics were not finished when Vermont's 45-day disclosure clock, and similar deadlines in other states, forced the letters out the door. Plaintiffs' firms have already opened investigations into the breach, the standard signal that follows a device maker's data incident regardless of how the intrusion happened.