
California-based healthcare service provider Madera Community Hospital reported that a data security incident last year exposed the sensitive personal information of over 150,000 individuals.
Madera Community Hospital is a nonprofit acute care hospital serving Madera County, California. It provides emergency, inpatient, outpatient, surgical, and diagnostic healthcare services with a focus on compassionate, patient-centered care.
In a data security incident notice published on its website, Madera Community Hospital said that on May 29, 2025, it identified unauthorised access to its internal network. The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected network and notified relevant law enforcement authorities about the incident.
“In June 2025, the forensic investigation found that an unauthorised third party gained access to our computer network for two days in late May 2025. That investigation, however, did not identify any files that were taken from our network.
“Based on subsequent developments, we have reason to believe that a third party acquired files from a portion of our network,” the healthcare provider said.
The compromised data included names, birthdates, contact information, login credentials, government identification numbers including Social Security numbers, financial account details, limited medical information including treatment and health insurance details and biometric information.
In a filing with the U.S. Department of Health and Human Services, Madera Community Hospital said that it has identified at least 150,810 individuals affected by the incident.
While Madera Community Hospital found no evidence of the compromised information being misused, it advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
While no known hacker group claimed responsibility for the cyberattack on Madera Community Hospital, the healthcare provider said that the group behind the attack withdrew its extortion demand after learning that the target was a hospital. According to the provider, the group said it did not want to harm patients.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543