Bell Ambulance, the largest ambulance provider in Wisconsin, disclosed a 2025 cyberattack that exposed personal and medical information on 237,830 people. The stolen data included Social Security numbers, driver's license numbers, financial account information, and medical and health insurance records.
What happened
Bell Ambulance, the largest ambulance provider in Wisconsin, discovered a cyberattack on February 13, 2025, and disclosed it that April. Breach filings put the number of affected people at 237,830. The Record initially reported 235,000.
The stolen data included Social Security numbers, driver's license numbers, financial account information, and medical and health insurance records, according to The Record.
Bell operates across the Milwaukee area, with more than 750 employees handling roughly 140,000 calls a year. Public reporting has focused on the patients it transported. Bell has not publicly detailed whether the records of its EMTs and paramedics were also in the stolen data.
How it started
The Medusa ransomware group claimed responsibility, demanded payment, and posted the stolen files after the company did not pay, according to The Record. Ransomware crews often go after healthcare and EMS operators: the records sell, and the pressure to keep ambulances running adds leverage to a ransom demand.
An ambulance company holds two kinds of sensitive records in the same systems. One is patient information for the people it transports. The other is the personnel and payroll data of the EMTs and paramedics it employs. A breach can reach either.
What came after
Bell agreed to a $2 million settlement to resolve a class action over the breach. Affected people can claim up to $5,000 for documented out-of-pocket losses, or a flat $90 with no proof required, plus two years of medical identity monitoring. Claims are due June 29, 2026, and a court weighs final approval at a July 14, 2026 hearing, according to Top Class Actions.
A settlement check does not undo the exposure. Once a Social Security number or home address is out, it circulates. Credit monitoring watches your accounts. It does not pull your address off the data broker sites that publish it.
What this means for you
If you're a Wisconsin EMT or paramedic, no state privacy law gives you a clear right to pull your home address off data broker sites.
Wisconsin's judicial-privacy law (Wis. Stat. § 757.07, from 2023 Wisconsin Act 235) lets judges and court commissioners send a written request that requires data brokers to stop selling their personal information. Their immediate family is covered too. It does not cover EMS workers.
Wisconsin's public-records law does hold some information back. Under Wis. Stat. § 19.36(10) and (11), a government agency will not release the home address, personal phone number, personal email, or Social Security number of a public employee without consent, and EMS staff count as public employees. But it binds only government agencies. It gives you no right to make a data broker take a listing down.
Safe at Home, Wisconsin's address confidentiality program (Wis. Stat. § 165.68), gives a substitute mailing address to people escaping domestic abuse, sexual assault, stalking, or trafficking, or who otherwise fear for their physical safety. It is not a job-based protection for EMS staff.
The layer that reaches you is data broker removal. That is what we handle: locating the listings that carry your home address, filing the removals, and watching for the ones that reappear.
What reduces this risk
An ambulance company holds two kinds of sensitive records in the same systems: patient information for the people it transports, and the personnel and payroll data of the EMTs and paramedics it employs. Bell has more than 750 employees. Wisconsin passed a [Daniel's Law](/laws/daniels-law)-style protection (Wis. Stat. § 757.07, from 2023 Wisconsin Act 235) that lets judges and court commissioners require data brokers to stop selling their personal information, and it covers their immediate family, but it does not cover EMS workers. The state's public-records exemption (Wis. Stat. § 19.36(10) and (11)) keeps an EMS worker's home address out of government files without consent, but it binds only agencies, not data brokers. The layer that reaches EMS workers is data broker removal. We find the listings, file removal requests, and keep checking for records that come back.
Public sources
- 235,000 affected by cyberattack on largest ambulance provider in Wisconsin — The Record from Recorded Future News, 2025-02-15
- February 2025 Cyberattack Affected More Than 230K Bell Ambulance Patients — The HIPAA Journal, 2026-03-10
- $2M Bell Ambulance data breach class action settlement — Top Class Actions, 2026-05-07