HIGH SEVERITYMedical

Madison Healthcare Services Data Breach

Madison Healthcare Services Long-Term Care Breach (2025): Patient SSN & Home Address Exposed

Regional healthcare organization offering clinic, senior, and specialty services.

Verified by ObscureIQ Intelligence

7.5Severity
24KRecords
5Fields
2025Year

ObscureIQ Breach Intelligence Scores
25.2
Breach Risk Index
27
Data Value
60
Market Recency
124
days
Since Breach

Risk Interpretation

High sensitivity. Exposure enables identity theft, medical fraud, and exploitation of elderly or dependent residents and their families. Long-term care records can also reveal disability or vulnerability status.

🎯 Impact & Downstream Threats

The institutional impact on Madison Healthcare Services is substantial relative to the organization's size and the vulnerability of its patient population. Federal HIPAA notification obligations, an Office for Civil Rights review, Minnesota attorney-general filings, and active class-action litigation discussions are all underway. The vulnerability of MHS patients, particularly elderly residents in senior services and rehabilitation programs, increases regulatory and litigation exposure because s

Primary downstream threats:
  • Identity theft and synthetic identity construction using government-issued IDs
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure

🔓 Threat Vectors

Phishing, credential stuffing & account takeover
Name-based social engineering
SIM swapping, vishing & SMS phishing
Physical stalking, mail fraud & identity verification
Home targeting, stalking & physical threat
Full identity theft & synthetic identity fraud

📋 Breach Intelligence

EntityMadison Healthcare Services
OrganizationHealthcare Provider • USA
Breach Date2025-09-23
DBC Added2025-12-24
Added Date2025-12-24
Records~24K (24,435 records)
Attack VectorUnknown
Threat ActorWorldLeaks
SourceDataBreach.com / ObscureIQ
SensitivityStandard
Breach ID832.0
StatusConfirmed

📝 Executive Summary

Madison Healthcare Services, a regional healthcare organization based in Madison, Minnesota offering family medicine, primary care, behavioral health, senior services, and specialty care, suffered a data exfiltration attack between July 2025 and August 2025. MHS identified suspicious network activity, engaged outside cybersecurity specialists, and confirmed unauthorized access through forensic investigation. The WorldLeaks ransomware group claimed responsibility on September 23, 2025 by listing MHS on its Tor-based leak site. MHS posted a public notice on December 1, 2025 and filed with HHS on December 2, 2025 using a 500-individual placeholder figure pending file review.

The breach affected approximately 24,000 individuals based on records indexed by breach-tracking services. Compromised fields included names, email addresses, phone numbers, home addresses, and Social Security numbers. As an integrated rural healthcare organization with senior and rehabilitation services, the underlying records exfiltrated by the attackers also include patient and resident identity, insurance, billing, clinical, and treatment information typical of family medicine, behavioral health, and long-term care operations, beyond the more limited field set surfaced publicly.

For affected patients, residents, and family members, the practical risk profile is unusually severe given the inclusion of senior-care patients. The combination of name, address, and Social Security number is a strong base for synthetic identity fraud and fraudulent credit applications. Inclusion in the dataset confirms a healthcare relationship in a small rural community where individuals may be readily identifiable based on name and address alone. Senior-care residents and their family members are an unusually attractive target for fraud schemes that exploit cognitive vulnerability or family-emergency framings. Affected individuals should freeze credit at all three U.S. bureaus, monitor health-insurance and Medicare statements closely, alert family members of elderly patients to be cautious of unsolicited contact, and treat unsolicited communications referencing MHS, senior services, or behavioral health programs with caution.

🏢 About Madison Healthcare Services

Madison Healthcare Services (MHS) is a regional healthcare organization based in Madison, Minnesota, serving individuals and families across western Minnesota's Lac qui Parle County and surrounding rural communities. The provider offers a broad range of services including family medicine, primary care, behavioral health services, senior services, and specialty providers in dermatology, surgery, and other clinical fields. MHS employs over 200 individuals across its clinic and senior care operations. As a HIPAA-regulated rural healthcare provider, MHS maintains comprehensive protected health information including patient and resident identity, contact, insurance, billing, treatment, and family or guardian records, alongside long-term care and rehabilitation records typical of an integrated rural health system serving a primarily elderly and family patient population.

Healthcare provider | Long-term care and rehabilitation services | Regional care provider | USA
Healthcare ProviderUSAmhsmn.org

🗂 Why They Hold Your Data

Long-term care and rehabilitation providers collect patient or resident identity, contact, insurance, billing, treatment, and family or guardian records across care operations.

📰 Recent Developments

Madison Healthcare Services identified suspicious network activity in late summer 2025 and engaged third-party digital forensics specialists. The forensic investigation confirmed unauthorized access to its network between July 2025 and August 2025. The WorldLeaks ransomware group, an active 2025 threat actor that has also targeted Coalinga Regional Medical Center, Myrtue Medical Center, Family Farm and Home, and Heritage Communities, claimed responsibility on September 23, 2025 by listing MHS on its Tor-based leak site. MHS posted a public notice of the incident on December 1, 2025 and reported the breach to the U.S. Department of Health and Human Services on December 2, 2025 using a placeholder figure of 500 affected individuals pending the file review. Class-action investigations by U.S. plaintiff law firms began organizing in December 2025.

🔍 Data Points Exposed

5 verified field types:
Social Security Number
Email
Phone Number
Name
Home Address

Exposure Categories

CredentialsSSN
LocationPHYS ADDR

Canonical Fields

email_address, full_name, phone_number, physical_address:home, ssn

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~24K records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: madison-healthcare-services-2025

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of Madison Healthcare Services
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

MedicalEmailPhoneAddress

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom