Madera Community Hospital Breach: 150,000 People's Medical and Financial Data Stolen
A California hospital spent nearly a year reviewing stolen files before telling patients their Social Security numbers, health records, and bank details had been taken. The criminal group that attacked them eventually dropped its ransom demand.

Key points
- Hackers broke into Madera Community Hospital's computer network in May 2025 and spent two days copying files containing personal, medical, and financial data.
- Exactly 150,810 people are confirmed affected, according to a filing the hospital made with the US Department of Health and Human Services.
- Stolen data includes Social Security numbers, bank account details, health insurance records, and limited biometric information (such as fingerprint or facial recognition data).
- The hospital did not begin notifying victims until mid-July 2026, more than a year after the break-in occurred.
- The criminal group behind the attack dropped its ransom demand, saying it did not want to harm patients.
Madera Community Hospital, a not-for-profit hospital serving Madera County in California's Central Valley, is sending breach notices to roughly 150,000 people after criminals broke into its network, spent two days copying files, and then disappeared.
The hospital confirmed the intrusion happened in May 2025. It took until April 2026 for a specialist data-review firm to finish identifying exactly which records had been taken. Notifications to victims began in mid-July 2026.
What information was stolen?
The stolen records cover a wide range of personal details. Names, addresses, and dates of birth were exposed. So were Social Security numbers, which criminals use to open fraudulent credit accounts or file false tax returns. Financial account information and account login credentials (usernames and passwords) were also taken, along with health insurance details, treatment records, and some biometric data.
Not every person lost every category. The hospital says it has found no evidence the stolen data has been posted publicly or sold.
| Data type | Confirmed stolen |
|---|---|
| Names and contact details | Yes |
| Dates of birth | Yes |
| Social Security numbers | Yes |
| Financial account information | Yes |
| Account login credentials | Yes |
| Health and insurance records | Yes |
| Biometric data | Limited amount |
Why did it take over a year to tell people?
This is the part that will feature prominently in any post-mortem. The breach happened in May 2025. The hospital only received the data-review results in April 2026 and spent the following months tracking down accurate contact details for victims. The gap between incident and notification is about 14 months.
In practice, a delay like this is partly procedural: forensic firms take time, address databases for patients go stale, and legal teams get cautious. The failure mode here is that the people most at risk spent over a year unaware they needed to freeze their credit or change their passwords.
SecurityWeek first reported the details of the HHS filing.
Should patients do anything right now?
Yes, a few straightforward things. If you received a notice from Madera Community Hospital, treat it seriously.
First, place a free credit freeze with the three main US credit bureaus (Equifax, Experian, and TransUnion). A credit freeze stops criminals from opening new accounts in your name, even if they have your Social Security number. Second, change any passwords that might match what you use for accounts linked to the hospital. Third, watch your bank and insurance statements for charges or claims you do not recognise.
The hospital says it has set up a dedicated helpline for affected individuals, referenced in its official notice.
One operational takeaway: if your organisation holds medical records, the clock on breach notification should start the moment exfiltration is suspected, not after a year-long data review.



