← BACK TO FEED
data breachhealthcareransomwarepatient dataCalifornia

Madera Community Hospital Took a Year to Tell 150,000 People Their Data Was Stolen

Madera Community Hospital in California has notified over 150,000 individuals that their personal, financial, and medical information was compromised in a cyberattack that occurred in May 2025. Hackers accessed the hospital's network for two days and likely exfiltrated files containing sensitive data, including Social Security numbers, health insurance details, and biometric information, though the hospital found no evidence the data was publicly released. The extortion group behind the attack ultimately withdrew its ransom demand, claiming it did not want to harm patients.

A California community hospital is only now getting around to telling 150,810 people that hackers were inside its network back in May 2025, making off with a fairly comprehensive haul of personal, financial, and medical data.

Madera Community Hospital, a not-for-profit serving Madera County and surrounding areas, says attackers had access to its systems for two days before the hospital detected the intrusion. The usual suspects in terms of stolen data are all present: names, addresses, dates of birth, Social Security numbers, financial account details, login credentials, health insurance information, treatment records, and some biometric data.

Not everyone had every category compromised, the hospital is careful to point out, and it says it has found no evidence the data was published or sold anywhere.

The timeline here is worth sitting with for a moment. The breach happened in May 2025. The hospital hired a data-review firm to work through the exfiltrated files. Results came back in April 2026. Notifications to affected individuals started in mid-July 2026. So people whose Social Security numbers and medical records were potentially stolen had to wait over a year to find out.

One mildly curious footnote: the ransomware group responsible apparently withdrew its extortion demand, claiming it had no interest in harming patients. Whether that reflects genuine principle or a PR calculation is anyone's guess. Either way, the hospital still had its data taken and still faces the same notification headache.

Madera says it brought in third-party security specialists, notified law enforcement, and has since tightened up its systems. The standard post-breach checklist, in other words.

The US Department of Health and Human Services has been formally notified of the 150,810 figure, which puts this firmly in the category of significant healthcare breaches for 2025.

READ NEXT
3.8 Million Patient Records Exposed in Ohio Healthcare Software BreachRansomware Surges While Everyone's Busy Watching the AI ShowRiver Bank Paid Ransomware Crew to Delete Stolen Data. Trust Them on That.