Skip to main content
Jump to a category page

A ransomware attack hit Minidoka Memorial Hospital on Easter morning, disrupting patient imaging and forcing transfers to another hospital. It took roughly four months before the Idaho hospital determined that patient data had been compromised.

Minidoka Memorial Hospital, a county-district hospital serving Minidoka and Cassia Counties, Idaho, detected malicious ransomware activity in its network on or around April 7, 2026. Public reporting on the incident places the attack on Easter morning, April 5, 2026, and describes the hospital transferring some emergency patients to Intermountain Health Cassia Regional Hospital after losing access to its medical imaging systems; imaging access was restored April 19, 2026. A threat group calling itself Blackwater claimed responsibility and threatened to leak stolen data, though Minidoka has not confirmed that specific claim.

Source: letter submitted to the Idaho Attorney General’s Office (08/06/2026); HIPAA Journal and Becker’s Hospital Review reporting on the incident.

Four Months Between Detection and Determining Patients Were Affected

Minidoka detected the ransomware activity around April 7, 2026, but did not determine that individuals’ information was potentially impacted until August 5, 2026 — roughly four months later. The hospital submitted its breach letter to the Idaho Attorney General’s Office the very next day, August 6, 2026, so the regulatory filing itself followed promptly once the determination was made. The four-month gap between detection and determining patients were affected is the harder question.

What Information Was Exposed?

According to the letter Minidoka submitted to Idaho regulators, the exposed information includes:

  • Name
  • Address
  • Social Security number

How Many People Are Affected?

Minidoka has not disclosed a total number of affected individuals. No corresponding filing has yet appeared on the federal HHS breach portal, which would typically include a population figure once submitted.

What Is Minidoka Offering Affected Individuals?

Minidoka has not publicly disclosed whether it is offering credit monitoring or identity protection services. Anyone who received a notice letter should review it directly for enrollment instructions or contact information specific to the offer made to them.

Your Information Is at Risk

A Social Security number combined with a name and address is enough to attempt new-account fraud, tax fraud, and other forms of identity theft. Affected individuals should monitor financial accounts and credit reports closely for unfamiliar activity.

Do You Have Legal Options, and a Deadline to Watch

Healthcare providers have a legal duty to secure patient information and to notify affected individuals without unreasonable delay. Because Minidoka Memorial Hospital operates as a public county hospital district, claims against it may be subject to a shorter notice deadline under Idaho law than claims against a private company — one more reason not to wait if you believe your information was affected.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice letter from Minidoka Memorial Hospital.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

FAQ

Who is affected by the Minidoka Memorial Hospital data breach?

Minidoka has not disclosed a total number of affected individuals. The hospital serves patients in Minidoka and Cassia Counties, Idaho.

What information was exposed?

Name, address, and Social Security number, according to the letter Minidoka submitted to the Idaho Attorney General’s Office.

What happened?

Minidoka detected ransomware activity in its network around April 7, 2026 (reported elsewhere as occurring on Easter morning, April 5). A threat group calling itself Blackwater claimed responsibility, though the hospital has not confirmed that claim. The attack disrupted the hospital’s medical imaging systems, leading to some patient transfers to another facility.

Why did it take so long to notify patients?

Minidoka detected the ransomware activity around April 7, 2026 but did not determine that patient information was potentially affected until August 5, 2026 — about four months later. The hospital filed with Idaho regulators the following day.

Is there a deadline to act if I want to pursue a claim?

Because Minidoka is a public hospital district, claims against it may be governed by a shorter notice-of-claim deadline under Idaho law than claims against a private company. If you believe your information was affected, it’s worth contacting us promptly rather than waiting.

Do I have a legal claim?

Healthcare providers have a legal duty to secure patient information and to notify affected individuals without unreasonable delay. If you received a notice letter from Minidoka Memorial Hospital, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now