[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fyy96l11zkn8m":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":18,"affectedCount":18,"affectedCountStatus":19,"affectedCountLowerBound":20,"affectedCountUnit":21,"hasEnglishDescription":4,"severity":22,"dataClasses":23,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":4,"isSpamList":38,"isMalware":38,"company":39},"6a715114c9b985b446a05e06","CookevilleRegionalMedicalCenter2025","Cookeville Regional Medical Center 2025 Data Breach","cookeville-regional-medical-center-2025","crmchealth.org","2025-07-11T00:00:00.000Z","2026-08-04T02:40:20.198Z","Cookeville Regional Medical Center, Texas Attorney General, and SecurityWeek","https:\u002F\u002Fcrmchealth.org\u002Fcrmc-experiencing-a-network-security-incident\u002F",[14,16,17],"https:\u002F\u002Foag.my.site.com\u002Fdatasecuritybreachreport\u002Fapex\u002FDataSecurityReportsPage","https:\u002F\u002Fwww.securityweek.com\u002Fdata-breach-at-tennessee-hospital-affects-337000\u002F",337917,"known",null,"people","High",[24,25,26,27,28,29,30,31,32],"Names","Dates of birth","Physical addresses","Social security numbers","Driver's license numbers","Government issued IDs","Financial account information","Medical information","Health insurance information","\u003Cp>\u003Cstrong>The 2025 Cookeville Regional Medical Center data breach\u003C\u002Fstrong> was a ransomware incident in which an unauthorized party accessed the Tennessee healthcare provider's network and took certain files. The Texas Attorney General record reports 337,917 affected people nationwide.\u003C\u002Fp>\u003Cp>Cookeville Regional Medical Center (CRMC) provides healthcare through its hospital and outpatient locations. The affected files could contain identity, financial, medical, and insurance information.\u003C\u002Fp>\u003Ch2>When did the Cookeville Regional Medical Center data breach occur?\u003C\u002Fh2>\u003Cp>The Texas regulator record gives an unauthorized-access period of July 11–14, 2025. According to CRMC's official statement, the ransomware attack occurred on July 13, and the organization detected the network disruption and intrusion on July 14.\u003C\u002Fp>\u003Cp>The Texas record contains March 16, 2026 in a separate discovery field. Because CRMC explicitly identified its initial detection in July 2025, the later date is treated as a subsequent data-review milestone and is not used as the first discovery date.\u003C\u002Fp>\u003Ch2>How did the incident happen?\u003C\u002Fh2>\u003Cp>CRMC confirmed that the event was a ransomware attack. Its investigation found that the unauthorized party accessed and took certain files from the network; the technical means of access was not publicly disclosed.\u003C\u002Fp>\u003Cp>SecurityWeek links the incident to the Rhysida ransomware group. CRMC did not name the group in its own statement, so the attribution is represented as an independent publication's finding.\u003C\u002Fp>\u003Ch2>What information may have been affected?\u003C\u002Fh2>\u003Cp>The official records and incident notice list names, dates of birth, addresses, Social Security numbers, driver's-license or other government identification numbers, financial account information, medical treatment information, and health-insurance policy information.\u003C\u002Fp>\u003Cp>The affected data varied by individual. This does not mean every listed field was present in every person's files.\u003C\u002Fp>\u003Ch2>How many people were affected?\u003C\u002Fh2>\u003Cp>The Texas Attorney General reports 337,917 affected people nationwide, including 529 Texas residents. These are nationwide and state subsets of the same event and were not added together.\u003C\u002Fp>\u003Ch2>What risks can this information create?\u003C\u002Fh2>\u003Cp>Social Security numbers, government IDs, and financial account information can support identity theft, fraudulent account applications, or payment fraud. Medical and insurance details can also make targeted messages appear to refer to a genuine treatment or billing relationship.\u003C\u002Fp>\u003Cp>For an unexpected message claiming to come from CRMC, a clinic, an insurer, or a bank, use the organization's official contact channel instead of following a supplied link. Accurate health details do not prove the sender is authorized.\u003C\u002Fp>\u003Ch2>How did CRMC respond?\u003C\u002Fh2>\u003Cp>CRMC said it engaged forensic specialists, notified law enforcement, and strengthened technical safeguards. It offered identity-protection services to eligible people whose Social Security or driver's-license numbers were affected.\u003C\u002Fp>\u003Ch2>What should affected people do?\u003C\u002Fh2>\u003Cp>Notice recipients can enroll in the offered protection service within the period stated in their letter and review credit reports, financial accounts, and health-insurance explanations for unfamiliar activity.\u003C\u002Fp>\u003Cp>If an unfamiliar transaction, new account, or healthcare service appears, contact the relevant organization directly. Do not share a password, verification code, or payment information in response to an unexpected call or message.\u003C\u002Fp>","","Cookeville Regional Medical Center Data Breach","The Cookeville Regional Medical Center data breach affected 337,917 people and may have exposed identity, financial, and medical information.","\u002Fuploads\u002Flogo\u002Fcookeville-regional-medical-center.png",false,{"name":40,"sector":41,"country":42,"website":43,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":20},"Cookeville Regional Medical Center","Healthcare","United States","https:\u002F\u002Fcrmchealth.org\u002F"]