ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Madera Community Hospital data breach exposes records of more than 150,000 patients

Madera Community Hospital is notifying 150,810 patients that their personal, financial and medical records were exposed after intruders broke into the hospital’s computer network in May 2025. The nonprofit facility, which serves Madera County and the surrounding region with emergency care, surgical services, acute care, diagnostic imaging and specialized medical programs, disclosed the breach to patients starting in mid-July and reported the total to the U.S. Department of Health and Human Services on July 13, 2026.


The hospital first detected unusual activity on its network on May 29, 2025, and brought in a cybersecurity firm to investigate. That investigation determined that an unauthorized party had been inside the network for two days beginning May 26, 2025, and had likely copied files during that window. HHS has classified the case as a hacking or IT incident.


Records pulled from the network included patients’ names, dates of birth, contact details, Social Security numbers, account login credentials, financial account information, treatment and health insurance records, and a limited amount of biometric data. The hospital said the exposure varied by individual, with not every patient affected by every category of data, and said it has found no indication that any of the stolen information has surfaced publicly or been shared further.


Determining the scope of the breach took nearly a year. After isolating the files that may have been taken, the hospital brought in outside specialists and a data-review firm to comb through them, a process that did not yield results until April 2026. The hospital said the months since then were spent confirming current contact information for everyone who needed to be notified.


The break-in was tied to an extortion attempt. According to the hospital, the group behind the attack initially demanded a ransom payment but dropped that demand after learning the target was a hospital, saying it did not want to cause harm to patients.


The hospital said it worked with outside experts to investigate the intrusion, tightened security across its systems and alerted law enforcement to the incident.


Patients who were notified are being urged to monitor their financial accounts and pull free credit reports for signs of identity theft, and to consider placing a fraud alert or a security freeze on their credit files as a precaution.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543