Madera Community Hospital Breach: 150,000 People's Medical and Financial Data Stolen
A California hospital spent nearly a year reviewing stolen files before telling patients their Social Security numbers, health records, and bank details had been taken. The criminal group that attacked them eventually dropped its ransom demand.

Key points
- Hackers broke into Madera Community Hospital's network in May 2025 and spent two days copying files containing personal, financial, and medical data.
- Exactly 150,810 people are confirmed affected, per a filing the hospital made with the US Department of Health and Human Services.
- Stolen data includes Social Security numbers, bank account details, health insurance records, and limited biometric information such as fingerprint or facial recognition data.
- Notifications to victims didn't begin until mid-July 2026, more than a year after the intrusion.
- The criminal group behind the attack withdrew its ransom demand, saying it did not want to harm patients.
Madera Community Hospital, a not-for-profit serving Madera County in California's Central Valley, is sending breach notices to roughly 150,000 people after criminals broke into its network, spent two days copying files, and then disappeared.
The intrusion happened in May 2025. It took until April 2026 for a specialist data-review firm to finish identifying exactly which records were taken. Victim notifications began in mid-July 2026.
What information was stolen?
Names, addresses, and dates of birth were exposed, along with Social Security numbers, which criminals use to open fraudulent credit accounts or file false tax returns. Financial account information, login credentials, health insurance details, treatment records, and some biometric data were also taken.
Not every person lost every category. The hospital says it has found no evidence the stolen data has been posted publicly or sold.
| Data type | Confirmed stolen |
|---|---|
| Names and contact details | Yes |
| Dates of birth | Yes |
| Social Security numbers | Yes |
| Financial account information | Yes |
| Account login credentials | Yes |
| Health and insurance records | Yes |
| Biometric data | Limited amount |
Why did it take over a year to tell people?
The breach happened in May 2025. Data-review results only arrived in April 2026, and the hospital spent the months after that tracking down accurate contact details for victims. Fourteen months between incident and notification.
Forensic firms take time, patient address records go stale, legal teams get cautious. All true. The actual failure is that the people most at risk spent over a year unaware they needed to freeze their credit or change their passwords. We covered a similar delay in the CareCloud breach on 31 July, where hackers spent nearly a week inside cloud storage before anyone noticed.
SecurityWeek first reported the details of the HHS filing.
Should patients do anything right now?
Yes. If you received a notice from Madera Community Hospital, treat it as urgent.
Place a free credit freeze with all three US credit bureaus: Equifax, Experian, TransUnion. A credit freeze stops criminals from opening new accounts in your name even with your Social Security number in hand. Change any passwords that might match credentials linked to the hospital. Watch your bank and insurance statements for charges or claims you don't recognise.
The hospital has set up a dedicated helpline, referenced in its official notice.
If your organisation holds medical records, the notification clock should start the moment exfiltration is suspected, not after a year-long review. That's the lesson here and it keeps not being learned.



