
Sturgis Hospital, a rural critical access hospital serving the Northern Black Hills in Michigan, has disclosed two security incidents that may have exposed sensitive information belonging to as many as 77,771 patients and employees. The breaches were reported to the U.S. Department of Health and Human Services’ Office for Civil Rights.
The first incident was detected in December 2024 when unauthorized activity was observed within part of the hospital’s computer network. Sturgis engaged third-party cybersecurity experts to investigate, remediate the intrusion, and assess the scope of the breach. Before the review was completed, a second incident involving unauthorized network activity was identified in June 2025, prompting another investigation.
The hospital confirmed that in both incidents, patient and employee information may have been accessed or exfiltrated. Exposed data included names, contact details, government identification numbers such as Social Security numbers, financial account information, health insurance details, and clinical information, including prescriptions and treatment histories. Sturgis said it has worked with cybersecurity specialists to strengthen defenses and has offered affected individuals complimentary credit monitoring and identity theft protection services. Law enforcement was notified of both incidents.
The breaches come amid growing concerns about the vulnerability of rural healthcare providers to cyberattacks. Only weeks earlier, Aspire Rural Health System in Michigan reported a cyber incident impacting 140,000 individuals, while Endless Mountains Health Systems in Pennsylvania disclosed a suspected ransomware attack in March 2025. Many rural hospitals face financial strain, with limited resources for cybersecurity and difficulties recruiting skilled staff.
In response to the mounting pressures, the Department of Health and Human Services recently confirmed a $50 billion grant program to support rural healthcare transformation over the next five years, with improving cybersecurity among its central goals.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543