Madera Community Hospital in California is informing over 150,000 individuals about a data breach that exposed their personal, financial, and medical information. The hospital, a not-for-profit community healthcare provider, offers various services including emergency and surgical care.
The breach occurred in May 2025, when unauthorized actors accessed the hospital's network for two days and likely exfiltrated files. The hospital engaged experts and a data-review firm for analysis, receiving results in April 2026. Notification to affected individuals began in mid-July, and the US Department of Health and Human Services (HHS) was informed of the 150,810 impacted individuals.
The compromised data includes names, contact information, dates of birth, Social Security numbers, account credentials, financial account information, treatment and health insurance information, and limited biometric information. The hospital stated that not every person had all these elements impacted and found no evidence of the information being publicly shared or released.
The extortion group responsible for the attack initially demanded a ransom payment but later withdrew it, claiming they did not want to harm patients. Madera Community Hospital worked with third-party experts to investigate the unauthorized activity, secure its systems, and notified law enforcement.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Madera Community Hospital is notifying 150,810 individuals that their personal, financial, and medical information was compromised in a data breach that occurred in May 2025. This incident highlights ongoing cybersecurity risks for healthcare providers, impacting patient data security and privacy.