Minidoka Memorial Hospital Data Breach Exposes Social Security Numbers and Medical Records

Healthcare data breach illustration
Breach Discovery: April 2026Breach Notification: August 2026

What Happened in the Minidoka Memorial Hospital Data Breach?

Minidoka Memorial Hospital has confirmed a ransomware incident that put patient records at risk. The hospital found malicious activity inside its computer network in early April 2026. This discovery set off a chain of events that patients are only now learning about in detail.

According to a notification sent to the Idaho Attorney General’s Office, the hospital first noticed the ransomware activity on or about April 2026. Once staff spotted the intrusion, the hospital says it moved quickly. It disconnected affected systems to stop further damage and brought in outside cybersecurity specialists to assess what happened.

The forensic review that followed determined that certain files containing sensitive patient information may have been accessed without permission. Because the potentially affected dataset was so large, the hospital hired a specialized vendor to sort through records and pinpoint exactly whose information was involved. That process alone reportedly carried a price tag near $5 million for the complete dataset.

As a result, the hospital chose a mixed notification approach. It directly notified patients whose records exist in its electronic medical records system. For everyone else whose contact details could not be efficiently retrieved through that expensive data-mining process, the hospital relied on substitute notice, including public announcements. The hospital’s review identified potentially impacted individuals as of early August 2026, and it says its investigation into the full scope is still ongoing.

Who was affected?

The people affected by this incident are patients who received care through Minidoka Memorial Hospital. Because hospital records often include family members and dependents, the exposure could reach a wide range of ages, including minors whose guardians provided their information during treatment.

The hospital has not yet released a specific total count of affected Idaho residents. It has stated that a supplemental report with that figure will follow once the analysis is complete. Therefore, anyone who received treatment at the hospital around or before April 2026 should stay alert for a notification letter, since the full list of affected patients has not been finalized.

What Information Was Potentially Exposed?

The hospital’s investigation identified several categories of sensitive personal and medical data that may have been accessed without authorization during the intrusion. This combination of identifying and clinical details makes the exposure particularly concerning for patients.

  • First and last names
  • Home addresses
  • Social Security numbers
  • Medical or treatment information
  • Healthcare information

Because Social Security numbers were involved, affected patients face a heightened risk of identity theft. Criminals can use a Social Security number combined with a name and address to open credit accounts, file fraudulent tax returns, or apply for loans in someone else’s name. This type of harm can surface months or even years after the original breach becomes public.

The exposure of medical and treatment information adds another layer of risk. Stolen health records can enable medical identity theft, where someone uses a victim’s information to obtain treatment, prescriptions, or insurance benefits. This can result in inaccurate medical histories that affect future care decisions, in addition to unexpected bills and insurance disputes.

What is the company doing?

Once Minidoka Memorial Hospital detected the ransomware activity, it activated its incident response plan. This included taking systems offline to contain the threat and engaging outside forensic experts to investigate the scope of unauthorized access. The hospital reports that it found no evidence that any stolen information has been misused so far.

Beyond the initial containment, the hospital has continued working to identify every affected patient. It has committed to filing a supplemental notification with the Idaho Attorney General’s Office once it completes this identification process. In the meantime, the hospital has begun notifying patients directly through its electronic medical records system, while using public notice for individuals it could not otherwise reach.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Anyone who received a notification letter, or who suspects they may have been treated at Minidoka Memorial Hospital around the time of the breach, should check their credit reports regularly. Look for unfamiliar accounts, inquiries, or changes that you did not authorize.

You can request free credit reports from each of the three major bureaus. Reviewing these reports on a rotating basis throughout the year gives you more consistent visibility into your credit activity than checking once and assuming you are safe.

Consider a Fraud Alert or Credit Freeze

Because Social Security numbers were potentially exposed, placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion is a smart precaution. A freeze makes it much harder for someone to open new credit in your name without your explicit consent.

While a freeze can add an extra step when you apply for credit yourself, this small inconvenience is worth the added protection. You can lift a freeze temporarily whenever you need to apply for a loan or new account.

Watch for Signs of Medical Identity Theft

Because medical and treatment information was involved, patients should watch their insurance statements and medical bills closely. Unexpected charges, unfamiliar providers, or duplicate claims could signal that someone else is using your identity for care.

If you notice anything unusual, contact your insurance provider immediately. Request a copy of your medical records to check for inaccuracies caused by fraudulent activity tied to your identity.

Stay Alert for Phishing Attempts

Scammers often use news of a data breach to trick victims into revealing more personal information. Be cautious of unsolicited calls, texts, or emails that reference this incident or claim to offer help resolving it.

Never click on links or provide personal details to anyone who contacts you unexpectedly. Instead, verify any communication directly with the hospital or your bank before responding.

Report Suspected Misuse and Seek Legal Guidance

If you discover that your information has been misused, file a report with the Federal Trade Commission at IdentityTheft.gov. This creates an official record that can support any future claims you may need to make.

In addition, affected patients may want to speak with a data breach attorney to understand their legal options. Many law firms offer free consultations, so there is little downside to learning whether you qualify for compensation.



Related Data Breaches

See the latest data breaches we're tracking →