Cookeville Regional Medical Center (CRMC) has suffered a data breach and continues battling the aftermath of a ransomware attack.

The Rhysida cybercriminal group posted the Tennessee hospital on their dark web leak site, demanding 10 Bitcoin (approximately $1.15 million) within days.
The medical facility serves 250,000 patients annually across 14 counties in Tennessee and Kentucky. With over 2,500 employees and 175 physicians, CRMC offers more than 40 medical specialties throughout the Upper Cumberland region.
Patient Data Exposed in Breach
Rhysida posted sample documents showing stolen patient files, driver’s licenses, employee tax records, and financial documents dating back to 2018. The cybercriminals gave the hospital roughly four days to pay before auctioning the data publicly.

Despite evidence posted by the attackers, hospital officials haven’t confirmed whether patient health information was compromised. If patient data wasn’t compromised you would think the hospital would reassure that to the public?
Chief Information Officer Tim McDermott stated their security team works around the clock to restore affected systems. You can find their message right on the website’s home page:
‘Cookeville Regional Medical Center (CRMC) is currently responding to a network security incident that has disrupted some of the medical center’s computer systems. CRMC’s Information System (IS) Security Team is working around the clock to restore the affected systems and services.’Â

TROYPOINT Tip: Never worry about identity theft again by using Aura which is TROYPOINT’s recommended identity theft protection!
Hide Your Digital Fingerprint
Aura Identity Theft Protection Review
Mixed Reports on Patient Care
CEO Buffy Key claimed patient care remained largely unaffected, though technology and scheduling systems experienced slowdowns. However, patients report conflicting experiences on social media.

Some patients waited over eight hours for test results, while others experienced canceled appointments and surgical delays. One patient criticized the hospital’s communication as “terrible,” while another praised the staff’s care quality.
Rhysida Gang is Responsible
The Russian-affiliated Rhysida group has claimed over 200 victims since May 2023, nearly doubling their targets in the past year. The gang typically uses phishing attacks to gain initial network access.
Previous high-profile victims include Seattle-Tacoma International Airport ($11 million demand), Columbus, Ohio, and the British Library. The group targets healthcare, education, manufacturing, and government sectors.
Final Thoughts
This attack highlights the growing threat ransomware groups pose to healthcare facilities. While CRMC works to restore systems, patients face ongoing disruptions to critical medical services.
The incident serves as a reminder for all healthcare organizations to strengthen their cybersecurity measures and prepare incident response plans.
For more details on this story, refer to the CRMC website and the report from Cybernews.
We want to know your thoughts. What do you think about this story? Let us know in the comment section below!
Exclusive Surfshark Discount
Your online activity is currently monitored by your ISP, app/addon/IPTV developers, government agencies, and the websites you visit.
- Become 100% anonymous while streaming and downloading.
- Use on Unlimited Devices & share 1 account with the entire family.
- Save 85% with the 24-Month Plan + Get 3 FREE Months.
Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.




