Cookeville Regional Medical Center in Tennessee disclosed that a ransomware attack tied to the Rhysida gang exposed the personal, financial, and protected health information of 337,917 individuals. The hospital said an unauthorized party accessed its network between July 11 and July 14, 2025, and a forensic investigation later determined that files may have been viewed or stolen during that period. Exposed data varied by individual and could include names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account details, medical information, medical record numbers, and health insurance information.
Rhysida claimed responsibility for the intrusion, saying it exfiltrated about 538 GB of data and later listed the medical center on its dark web leak site, where it said 70% of the data had been leaked. The breach was initially reported to HHS with a placeholder figure before a full file review was completed in March 2026, after which the hospital began broader notifications. Cookeville Regional said it has not found evidence of misuse so far, urged affected people to monitor accounts and explanation-of-benefits statements, and offered 12 months of credit monitoring and identity theft protection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
After completing the forensic review, Cookeville Regional Medical Center disclosed the breach, began notifying affected people, advised them to monitor accounts and benefits statements, and offered 12 months of credit monitoring and identity theft protection.
On 2026-03-16, the organization finished its review of the compromised files and determined that 337,917 individuals were affected.
Cookeville Regional Medical Center initially reported the breach to the HHS Office for Civil Rights in August 2025 using a placeholder estimate of 500 affected individuals.
In August 2025, the Rhysida ransomware group claimed responsibility for the attack, said it stole about 538 GB of data, and listed the medical center on its dark web leak site, indicating that much of the data had been leaked.
The medical center detected the incident on 2025-07-14 and launched a forensic investigation into the compromise.
Cookeville Regional Medical Center said an unauthorized party had access to its network between 2025-07-11 and 2025-07-14, 2025, potentially viewing or acquiring files containing personal, financial, and medical information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcesecurityaffairs.com
Open sourcehipaajournal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.