TL;DR: Cookeville Regional Medical Center in Tennessee was hit by the Rhysida ransomware group between July 11-14, 2025. The attackers stole 538GB of patient data: names, Social Security numbers, medical records, insurance information, financial details, and driver's licenses. When nobody paid the ransom, Rhysida dumped everything on the dark web for free. The hospital started notifying 337,917 affected patients in April 2026, nine months after the breach. If you've been treated at Cookeville Regional, your most sensitive data is already public.
538 Gigabytes. Four Days. Nine Months of Silence.
Here's the timeline. On July 14, 2025, Cookeville Regional Medical Center noticed "suspicious activity" on its network. An investigation found that an unauthorized third party had been inside the system since July 11: four days of unrestricted access to patient records [1].
By August 2025, the Rhysida ransomware group posted the hospital on its dark web leak site, claiming 538GB of stolen data. Nobody bought it. So Rhysida did what ransomware groups do when they can't get paid: they published everything for free [2].
The hospital says it completed its "file review" on March 16, 2026 (eight months after the breach) and started mailing notification letters in April [3]. That's nine months between "we got hacked" and "hey, your SSN is on the dark web."
Nine months. Long enough to have a baby. Long enough for criminals to use your stolen identity six ways to Sunday before you even know it happened.
What Rhysida Got: Everything
The stolen data reads like a checklist of everything you'd need to ruin someone's financial and medical life:
- Social Security numbers
- Dates of birth
- Driver's license numbers
- Financial account information
- Medical treatment records
- Medical record numbers
- Health insurance policy information
- Names and addresses
That's not just identity theft material. Medical records contain diagnoses, prescriptions, mental health notes, substance abuse treatment records. Information people don't even share with their families.
And it's all sitting on the dark web. For free. Because Rhysida couldn't find a buyer and decided spite was the next best business model.
Rhysida: The Ransomware Gang That Won't Stop Hitting Hospitals
Rhysida isn't new. The Russia-linked ransomware-as-a-service operation has been active since May 2023, and healthcare is one of its favorite targets [4].
Their greatest hits include:
- Prospect Medical Holdings (August 2023): disrupted 16 hospitals across four states
- Lurie Children's Hospital (January 2024): attacked a pediatric hospital in Chicago
- Singing River Health System: nearly 900,000 patients affected
- Sunflower Medical Group (January 2025): 221,000 patients in Kansas
- Spindletop Center (September 2025): Texas mental health facility, 15 bitcoin ransom demanded
Rhysida claimed 91 attacks across all sectors in 2025 alone, with an average ransom demand of $1.2 million [5]. The group's playbook is consistent: get in, steal everything, encrypt systems, demand payment. When victims refuse to pay, the data gets dumped publicly. No negotiations. No mercy. No exceptions for the fact that they're stealing children's medical records.
The FBI and CISA issued a joint advisory about Rhysida in November 2023 specifically warning about healthcare targeting. Two and a half years later, hospitals are still falling.
Why Did It Take Nine Months to Tell Patients?
Cookeville Regional says the delay was because it took until March 16, 2026 to complete its "comprehensive review of the affected files" [3]. In other words: they knew they were breached in July. They knew Rhysida published the data in August. But it took until March to figure out exactly whose records were in the 538GB dump.
That's the standard excuse in healthcare breaches, and it's maddening every time.
HIPAA requires covered entities to notify affected individuals "without unreasonable delay" and no later than 60 days after discovering the breach. Cookeville's notification clock started running in July 2025. The letters went out in April 2026, roughly 270 days later.
During those nine months, Rhysida's data dump was sitting on the dark web. Anyone who wanted it could download it. And the 337,917 people whose SSNs, medical records, and financial data were in that dump had no idea.
No idea to freeze their credit. No idea to watch for fraudulent medical claims. No idea that their mental health records, substance abuse treatment, or STI test results were available to anyone with a Tor browser.
What to Do if You're Affected
Freeze Your Credit, Today
Don't wait for the hospital's free credit monitoring to arrive. Go to annualcreditreport.com and freeze your credit at all three bureaus (Equifax, Experian, TransUnion). It's free and takes 15 minutes. Your SSN has been public for nine months already.
Monitor for Medical Identity Theft
Request your medical records from Cookeville Regional and review them for treatments you didn't receive. Stolen medical identities get used for fraudulent insurance claims and prescription drug fraud. Check your Explanation of Benefits (EOB) statements for unfamiliar charges.
Accept the Free Identity Protection
Cookeville Regional is offering free identity theft protection services. Sign up. It's the bare minimum, but it's something. Set up alerts for any new accounts opened in your name.
File an IRS Identity Protection PIN
With your SSN and date of birth exposed, tax fraud is a real risk. Go to IRS.gov and get an Identity Protection PIN. This prevents anyone from filing a tax return using your SSN.
Healthcare's Ransomware Crisis Isn't Getting Better
In 2025, ransomware groups hit 47 healthcare organizations in a single 30-day stretch [6]. It's part of a wider healthcare ransomware epidemic. The healthcare sector reported over 301 million records breached through HIPAA-reported incidents in just the first quarter of 2026.
The reasons are painfully simple:
- Hospitals can't go offline. They pay ransoms because lives depend on uptime.
- Medical data is worth more than credit cards. A stolen credit card sells for $5-$10 on the dark web. A medical record goes for $250-$1,000 because it contains everything needed for identity theft, insurance fraud, and prescription schemes.
- Healthcare IT is chronically underfunded. The average hospital spends about 6% of its IT budget on cybersecurity, compared to 10-15% in financial services.
- Legacy systems everywhere. Many hospitals run software from the early 2000s that can't be patched without breaking clinical workflows.
Rhysida and groups like it know all this. That's why they keep coming back.
Lawsuits Are Already Coming
At least two law firms (Edelson Lechtzin LLP and Migliaccio & Rathod LLP) have announced investigations into the Cookeville breach, with potential class action lawsuits on the horizon [7][8]. The claims will likely center on:
- Negligent data security: failure to implement adequate protections
- Delayed notification: nine months between breach and patient notice
- HIPAA violations: potential failure to meet the 60-day notification requirement
Class action settlements in healthcare data breaches have been growing. Advocate Health paid $5.55 million in 2016 for a 4 million-record breach. Community Health Systems paid $4.5 million for 4.5 million records. With nearly 338,000 victims and a nine-month notification delay, Cookeville Regional's legal exposure is significant.
References
- SecurityWeek - Data Breach at Tennessee Hospital Affects 337,000 (April 17, 2026)
- Security Affairs - Cookeville Regional Medical Center hospital data breach impacts 337,917 people (April 2026)
- Comparitech - Cookeville Regional Medical Center warns 338,000 people of data breach (April 2026)
- Ransom-DB - Rhysida Ransomware Group Profile 2026 Analysis
- Comparitech - Healthcare Ransomware Roundup: 2025 stats on attacks, ransoms, and data breaches
- Breached.Company - Healthcare Under Siege: 47 Ransomware Victims in 30 Days (2026)
- Edelson Lechtzin LLP - Investigates Cookeville Regional Medical Center Data Breach (April 17, 2026)
- Migliaccio & Rathod LLP - Cookeville Regional Medical Center Data Breach Investigation (April 15, 2026)