
Madera Community Hospital is notifying 150,810 patients that their personal, financial and medical records were exposed after intruders broke into the hospital’s computer network in May 2025. The nonprofit facility, which serves Madera County and the surrounding region with emergency care, surgical services, acute care, diagnostic imaging and specialized medical programs, disclosed the breach to patients starting in mid-July and reported the total to the U.S. Department of Health and Human Services on July 13, 2026.
The hospital first detected unusual activity on its network on May 29, 2025, and brought in a cybersecurity firm to investigate. That investigation determined that an unauthorized party had been inside the network for two days beginning May 26, 2025, and had likely copied files during that window. HHS has classified the case as a hacking or IT incident.
Records pulled from the network included patients’ names, dates of birth, contact details, Social Security numbers, account login credentials, financial account information, treatment and health insurance records, and a limited amount of biometric data. The hospital said the exposure varied by individual, with not every patient affected by every category of data, and said it has found no indication that any of the stolen information has surfaced publicly or been shared further.
Determining the scope of the breach took nearly a year. After isolating the files that may have been taken, the hospital brought in outside specialists and a data-review firm to comb through them, a process that did not yield results until April 2026. The hospital said the months since then were spent confirming current contact information for everyone who needed to be notified.
The break-in was tied to an extortion attempt. According to the hospital, the group behind the attack initially demanded a ransom payment but dropped that demand after learning the target was a hospital, saying it did not want to cause harm to patients.
The hospital said it worked with outside experts to investigate the intrusion, tightened security across its systems and alerted law enforcement to the incident.
Patients who were notified are being urged to monitor their financial accounts and pull free credit reports for signs of identity theft, and to consider placing a fraud alert or a security freeze on their credit files as a precaution.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543