Madera Community Hospital has confirmed that an unauthorized third party accessed its computer network in May 2025 and likely took files containing patient personal and health information, though the hospital did not begin sending notification letters to patients until roughly a year later.

 

What happened

On May 29, 2025, Madera Community Hospital detected suspicious activity on its computer network and brought in third-party cybersecurity experts to investigate and contain it. By June 2025, the investigation determined that an unauthorized third party had been inside the network for two days in late May 2025. At that point, investigators did not find evidence that any files had been taken.

The hospital later found reason to believe that the third party did acquire files from part of its network. Investigators did not find definitive proof that the files contained personal information or protected health information, and the hospital says it has seen no evidence that any of the potentially affected data was released publicly or shared elsewhere. The hospital identified the potentially affected files, gathered them, and hired a data-review firm to examine their contents. It received the results of that review in April 2026 and spent the following months confirming accurate contact information for the people it needed to notify.

 

Going deeper

Nearly a year passed between the detection of the intrusion in May 2025 and the hospital sending notification letters. The hospital attributes part of that gap to the time needed to review the acquired files and verify contact information for affected patients before notifying them. Madera Community Hospital also appeared on the California Attorney General's data breach reporting site on July 14, 2026, in connection with the incident, though the filing did not specify the number of people affected.

 

What was said

In its notification letter, Madera Community Hospital stated that its investigation "did not find definitive proof that the third party acquired files with personal information or protected health information," and added that it has "seen no evidence that any of the potentially impacted data has been released publicly or otherwise shared."

The hospital also said it notified law enforcement about the incident, and that doing so "did not delay this notice."

 

Why it matters

The nearly year-long gap between detecting the intrusion and notifying patients means affected individuals had no way to watch for misuse of their information during that time. That delay is notable for a healthcare breach, since protected health information can't be changed the way a password or card number can if it's later misused. The hospital's own language also reflects real uncertainty about what happened, it can't rule out that health and personal data were taken, but it also can't confirm it.

Madera Community Hospital isn't alone in taking close to a year to notify patients. Huntsville Hospital sent breach letters to patients in June 2026 for an incident that occurred in January 2025, a roughly ten-month gap, after its records vendor Cerner notified the hospital of the breach in August 2025. That delay resulted in a class-action lawsuit, with the plaintiff's attorney arguing that state law requires notifying people as quickly as possible once a breach is discovered. The Huntsville case shows that a long notification gap isn't just an inconvenience on paper, it becomes the basis for legal action, and it shapes how patients feel about an organization's handling of their data long after the technical incident is resolved.

 

FAQs

When should healthcare organizations notify patients after a healthcare data breach?

Under HIPAA, covered entities generally must notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach.

 

What's the difference between personal information and protected health information?

Personal information refers to identifying details like a name or Social Security number, while protected health information includes data tied to a person's medical history or care.

Learn more: What is the difference between PII and PHI?

 

Can a data breach happen even if no evidence shows the stolen data was misused?

Yes, a breach can be confirmed based on unauthorized access or file acquisition alone, regardless of whether the data later surfaces or is used fraudulently.