{"id":45497,"date":"2026-04-17T04:28:55","date_gmt":"2026-04-16T20:28:55","guid":{"rendered":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/17\/cookeville-hospital-discloses-rhysida-breach-hitting-337917-infosecurity-magazine\/"},"modified":"2026-04-17T04:28:55","modified_gmt":"2026-04-16T20:28:55","slug":"cookeville-hospital-discloses-rhysida-breach-hitting-337917-infosecurity-magazine","status":"publish","type":"post","link":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/2026\/04\/17\/cookeville-hospital-discloses-rhysida-breach-hitting-337917-infosecurity-magazine\/","title":{"rendered":"Cookeville Hospital Discloses Rhysida Breach Hitting 337,917 &#8211; Infosecurity Magazine"},"content":{"rendered":"<p>More than 337,000 patients of Cookeville Regional Medical Center (CRMC) in Tennessee have been notified that their personal and medical data was compromised in a July 2025 ransomware attack, the hospital confirmed this week.<\/p>\n<p>The 309-bed facility began mailing breach notification letters on April 14, 2026, roughly nine months after the intrusion was detected.<\/p>\n<p>Files were accessed or acquired by an unathorized party between July 11 and July 14, 2025, according to a<a href=\"https:\/\/www.maine.gov\/agviewer\/content\/ag\/985235c7-cb95-4be2-8792-a1252b4f8318\/fb04ea66-92bb-4a15-b02c-8d1a9f783461.html\" style=\"text-decoration:none;\" target=\"_blank\"> filing<\/a> with the Maine Attorney General&#39;s Office. A total of&nbsp;337,917 individuals have been affected.&nbsp;<\/p>\n<h2><strong>Inside the Rhysida Attack on CRMC<\/strong><\/h2>\n<p>Rhysida, a ransomware-as-a-service operation linked to Russia and<a href=\"https:\/\/www.infosecurity-magazine.com\/news\/rhysida-vice-society-connection\/\" style=\"text-decoration:none;\" target=\"_blank\"> active since May 2023<\/a>, claimed responsibility on August 2, 2025. The gang demanded a ransom of 10 Bitcoin, worth roughly $1.15m at the time, and posted sample files on its dark web leak site. It is unclear whether any ransom was paid.<\/p>\n<p>Information accessed may include names, addresses, dates of birth, Social Security numbers, driver&#39;s license numbers, financial account details, medical record numbers, treatment information and health insurance data.<\/p>\n<p>CRMC, which serves around 250,000 patients annually across 14 counties in the Upper Cumberland region, is offering 12 months of free identity theft protection through Experian.<\/p>\n<p><em><a href=\"https:\/\/www.infosecurity-magazine.com\/news\/rhysida-vice-society-connection\/\" style=\"text-decoration:none;\" target=\"_blank\">Read more on Rhysida&#39;s healthcare targeting: Rhysida Ransomware Analysis Reveals Vice Society Connection<\/a><\/em><\/p>\n<h2><strong>A Year of Pressure on US Healthcare<\/strong><\/h2>\n<p>The CRMC incident ranks as the eighth-largest US healthcare ransomware breach of 2025 by records compromised, according to<a href=\"https:\/\/www.comparitech.com\/news\/cookeville-regional-medical-center-warns-338000-people-of-data-breach\/\" style=\"text-decoration:none;\" target=\"_blank\"> Comparitech<\/a>, which logged 134 confirmed attacks on US healthcare providers last year, exposing 11.7 million records.<\/p>\n<p>Rhysida alone claimed 91 attacks across all sectors in 2025, with 23 confirmed and an average demand of $1.2m.<\/p>\n<p>Other recent Rhysida healthcare victims include:<\/p>\n<ul>\n<li>Florida Lung, Asthma &amp; Sleep Specialists (FL), May 2025, $639,000 demand<\/li>\n<li>MedStar Health (MD), September 2025, $3.09m demand<\/li>\n<li>Spindletop Center (TX), September 2025, $1.65m demand<\/li>\n<li>MACT Health Board (CA), November 2025, $662,000 demand<\/li>\n<li>Heart South Cardiovascular Group (AL), November 2025, $630,000 demand<\/li>\n<\/ul>\n<p>Rebecca Moody, head of data research at Comparitech, said the lengthy investigation timeline reflects the scale of forensic work required after a hospital ransomware hit.<\/p>\n<p>&quot;It can take a considerable amount of time for organizations to investigate what data has been impacted in these breaches,&quot; Moody explained.<\/p>\n<p>&quot;While some organizations avoid using the word &#39;ransomware&#39; and don&#39;t issue any form of data breach notification for months,&quot; she added, &quot;this lack of clarity and confirmation can leave those affected open to identity theft and phishing campaigns.&quot;<\/p>\n<p>Ransomware incidents at US hospitals routinely<a href=\"https:\/\/www.infosecurity-magazine.com\/news\/university-mississippi-medical\/\" style=\"text-decoration:none;\" target=\"_blank\"> force extended downtime<\/a>,<a href=\"https:\/\/www.infosecurity-magazine.com\/news\/london-ransomware1500-cancelled\/\" style=\"text-decoration:none;\" target=\"_blank\"> canceled appointments<\/a> and<a href=\"https:\/\/www.infosecurity-magazine.com\/news\/ransomware-forces-umc-divert\/\" style=\"text-decoration:none;\" target=\"_blank\"> patient diversions<\/a> even where clinical systems hold up. CRMC said it has put additional security measures in place since the attack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>More than 337,000 patients of Cookeville Regional Medic [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-45497","post","type-post","status-publish","format-standard","hentry","category--infosecurity-magazine"],"_links":{"self":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45497","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/comments?post=45497"}],"version-history":[{"count":0,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/posts\/45497\/revisions"}],"wp:attachment":[{"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/media?parent=45497"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/categories?post=45497"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nuoya.nuoyayasuo.top\/index.php\/wp-json\/wp\/v2\/tags?post=45497"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}