Madera Community Hospital Took a Year to Tell 150,000 People Their Data Was Stolen
A California community hospital is only now getting around to telling 150,810 people that hackers were inside its network back in May 2025, making off with a fairly comprehensive haul of personal, financial, and medical data.
Madera Community Hospital, a not-for-profit serving Madera County and surrounding areas, says attackers had access to its systems for two days before the hospital detected the intrusion. The usual suspects in terms of stolen data are all present: names, addresses, dates of birth, Social Security numbers, financial account details, login credentials, health insurance information, treatment records, and some biometric data.
Not everyone had every category compromised, the hospital is careful to point out, and it says it has found no evidence the data was published or sold anywhere.
The timeline here is worth sitting with for a moment. The breach happened in May 2025. The hospital hired a data-review firm to work through the exfiltrated files. Results came back in April 2026. Notifications to affected individuals started in mid-July 2026. So people whose Social Security numbers and medical records were potentially stolen had to wait over a year to find out.
One mildly curious footnote: the ransomware group responsible apparently withdrew its extortion demand, claiming it had no interest in harming patients. Whether that reflects genuine principle or a PR calculation is anyone's guess. Either way, the hospital still had its data taken and still faces the same notification headache.
Madera says it brought in third-party security specialists, notified law enforcement, and has since tightened up its systems. The standard post-breach checklist, in other words.
The US Department of Health and Human Services has been formally notified of the 150,810 figure, which puts this firmly in the category of significant healthcare breaches for 2025.