Madison Healthcare Services Data Breach
Madison Healthcare Services Long-Term Care Breach (2025): Patient SSN & Home Address Exposed
Regional healthcare organization offering clinic, senior, and specialty services.
Risk Interpretation
High sensitivity. Exposure enables identity theft, medical fraud, and exploitation of elderly or dependent residents and their families. Long-term care records can also reveal disability or vulnerability status.
Impact & Downstream Threats
The institutional impact on Madison Healthcare Services is substantial relative to the organization's size and the vulnerability of its patient population. Federal HIPAA notification obligations, an Office for Civil Rights review, Minnesota attorney-general filings, and active class-action litigation discussions are all underway. The vulnerability of MHS patients, particularly elderly residents in senior services and rehabilitation programs, increases regulatory and litigation exposure because s
- Identity theft and synthetic identity construction using government-issued IDs
- SIM swap attacks where phone numbers are present
- Targeted phishing campaigns using exposed email addresses
- Doxxing risk from physical address exposure
Threat Vectors
Breach Intelligence
Executive Summary
Madison Healthcare Services, a regional healthcare organization based in Madison, Minnesota offering family medicine, primary care, behavioral health, senior services, and specialty care, suffered a data exfiltration attack between July 2025 and August 2025. MHS identified suspicious network activity, engaged outside cybersecurity specialists, and confirmed unauthorized access through forensic investigation. The WorldLeaks ransomware group claimed responsibility on September 23, 2025 by listing MHS on its Tor-based leak site. MHS posted a public notice on December 1, 2025 and filed with HHS on December 2, 2025 using a 500-individual placeholder figure pending file review.
The breach affected approximately 24,000 individuals based on records indexed by breach-tracking services. Compromised fields included names, email addresses, phone numbers, home addresses, and Social Security numbers. As an integrated rural healthcare organization with senior and rehabilitation services, the underlying records exfiltrated by the attackers also include patient and resident identity, insurance, billing, clinical, and treatment information typical of family medicine, behavioral health, and long-term care operations, beyond the more limited field set surfaced publicly.
For affected patients, residents, and family members, the practical risk profile is unusually severe given the inclusion of senior-care patients. The combination of name, address, and Social Security number is a strong base for synthetic identity fraud and fraudulent credit applications. Inclusion in the dataset confirms a healthcare relationship in a small rural community where individuals may be readily identifiable based on name and address alone. Senior-care residents and their family members are an unusually attractive target for fraud schemes that exploit cognitive vulnerability or family-emergency framings. Affected individuals should freeze credit at all three U.S. bureaus, monitor health-insurance and Medicare statements closely, alert family members of elderly patients to be cautious of unsolicited contact, and treat unsolicited communications referencing MHS, senior services, or behavioral health programs with caution.
About Madison Healthcare Services
Madison Healthcare Services (MHS) is a regional healthcare organization based in Madison, Minnesota, serving individuals and families across western Minnesota's Lac qui Parle County and surrounding rural communities. The provider offers a broad range of services including family medicine, primary care, behavioral health services, senior services, and specialty providers in dermatology, surgery, and other clinical fields. MHS employs over 200 individuals across its clinic and senior care operations. As a HIPAA-regulated rural healthcare provider, MHS maintains comprehensive protected health information including patient and resident identity, contact, insurance, billing, treatment, and family or guardian records, alongside long-term care and rehabilitation records typical of an integrated rural health system serving a primarily elderly and family patient population.
Why They Hold Your Data
Long-term care and rehabilitation providers collect patient or resident identity, contact, insurance, billing, treatment, and family or guardian records across care operations.
Recent Developments
Madison Healthcare Services identified suspicious network activity in late summer 2025 and engaged third-party digital forensics specialists. The forensic investigation confirmed unauthorized access to its network between July 2025 and August 2025. The WorldLeaks ransomware group, an active 2025 threat actor that has also targeted Coalinga Regional Medical Center, Myrtue Medical Center, Family Farm and Home, and Heritage Communities, claimed responsibility on September 23, 2025 by listing MHS on its Tor-based leak site. MHS posted a public notice of the incident on December 1, 2025 and reported the breach to the U.S. Department of Health and Human Services on December 2, 2025 using a placeholder figure of 500 affected individuals pending the file review. Class-action investigations by U.S. plaintiff law firms began organizing in December 2025.
Data Points Exposed
Exposure Categories
Canonical Fields
email_address, full_name, phone_number, physical_address:home, ssn
Dark Web Verification
- Dataset containing ~24K records identified in breach intelligence sources
- Data indexed and searchable across breach notification platforms
- Source: madison-healthcare-services-2025
Recommended Actions
⚠️ Do not assume this is low sensitivity.
Protect Yourself
Check If You’re Affected
Enter your email to check if your data appears in this breach.
Get Free Breach Alerts
Be the first to know when new breaches are disclosed.
High-Risk? Get an Exposure Audit
Full-spectrum exposure audits for executives and public figures.
ObscureIQ Advisory
We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.
- A public-facing individual
- A high-profile executive
- A customer of Madison Healthcare Services
- Or concerned about credential reuse
Powered by the ObscureIQ Breach Intelligence Database
© 2026 ObscureIQ · All Rights Reserved · Data Licensing
Latest from ObscureIQ
What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.
Sextortion Spam
