Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Cookeville Regional Medical Center

Cookeville Regional Medical Center Vendor Cyber Rating & Cyber Score

crmchealth.org

At Cookeville Regional Medical Center, we are dedicated to providing the highest quality care to our patients and making a positive impact on our community. With a rich history dating back to 1921, our state-of-the-art medical center has grown into a leading facility with over 2,400 employees and 200 medical staff members serving the Upper Cumberland region. We offer a collaborative and supportive work environment where employees from different backgrounds and areas of expertise come together to provide essential care to those in need. Our hospital is a place where you can grow and develop your career, with opportunities to specialize, advance your skills, and take on new responsibilities. In addition to making a difference in people's


CRMC A.I CyberSecurity Scoring

CRMC
Company Information
Website:http://www.crmchealth.org
Employees number:2,416
Number of followers:5,607
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:crmchealth.org
CRMC Risk Score (AI oriented)
Between 0 and 549
logo
CRMCHospitals and Health Care
Updated:
17/04/2026
267/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CRMC Global Score (TPRM)
xxxx
logo
CRMCHospitals and Health Care
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CRMC
CRMCCritical
Current Score
267C (CRITICAL)
01000
4 incidents
-188 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
306Before Incident
JUNE 2026
294Before Incident
MAY 2026
283Before Incident
APRIL 2026
496Before Incident
Ransomware
16 Apr 2026CRMC
Cookeville Regional Medical Center, Florida Lung, Asthma & Sleep Specialists and Heart South Cardiovascular Group: Cookeville Hospital Discloses Rhysida Breach Hitting 337,917

Cookeville Regional Medical Center Hit by Rhysida Ransomware Attack

267After Incident
CRITICAL-229
PEAFLOCRM1776443473
Cookeville Regional Medical Center Hit by Rhysida Ransomware Attack, Exposing 337,917 Patients’ Data Cookeville Regional Medical Center (CRMC), a 309-bed hospital serving 14 counties in Tennessee’s Upper Cumberland region, has notified 337,917 patients that their personal and medical data was compromised in a July 2025 ransomware attack. Breach notification letters were mailed on April 14, 2026 nearly nine months after the intrusion was detected. The attack, attributed to the Russia-linked Rhysida ransomware-as-a-service group, occurred between July 11 and July 14, 2025. Rhysida claimed responsibility on August 2, 2025, demanding a 10 Bitcoin ransom (approximately $1.15 million at the time) and publishing sample files on its dark web leak site. It remains unclear whether CRMC paid the ransom. Exposed data may include names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account details, medical record numbers, treatment information, and health insurance data. In response, CRMC is offering affected individuals 12 months of free identity theft protection through Experian. The incident ranks as the eighth-largest U.S. healthcare ransomware breach of 2025 by records compromised. Comparitech, which tracked 134 confirmed attacks on U.S. healthcare providers last year, reported that these breaches exposed 11.7 million records. Rhysida alone claimed 91 attacks across all sectors in 2025, with 23 confirmed and an average ransom demand of $1.2 million. Other recent Rhysida healthcare victims include Florida Lung, Asthma & Sleep Specialists ($639,000 demand), MedStar Health ($3.09 million), Spindletop Center ($1.65 million), MACT Health Board ($662,000), and Heart South Cardiovascular Group ($630,000). Rebecca Moody, head of data research at Comparitech, noted that the extended investigation timeline reflects the complexity of forensic analysis following hospital ransomware attacks. She also highlighted that delayed or vague breach notifications can increase risks of identity theft and phishing for affected individuals. CRMC has since implemented additional security measures in the wake of the attack. Ransomware incidents at U.S. hospitals frequently result in prolonged downtime, canceled appointments, and patient diversions, even when clinical systems remain operational.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 337,917 recordsOperational Impact: Prolonged downtime, canceled appointments, and patient diversionsIdentity Theft Risk: Increased risk of identity theft and phishingPayment Information Risk: Financial account details exposed
DATA BREACH
Personal dataMedical dataNumber Of Records Exposed: 337,917Sensitivity Of Data: HighData Exfiltration: Sample files published on dark web leak siteData Encryption: Yes (ransomware encryption)NamesAddressesDates of birthSocial Security numbersDriver’s license numbersFinancial account detailsMedical record numbersTreatment informationHealth insurance data
MARCH 2026
493Before Incident
FEBRUARY 2026
486Before Incident
JANUARY 2026
479Before Incident
DECEMBER 2025
472Before Incident
NOVEMBER 2025
464Before Incident
OCTOBER 2025
457Before Incident
SEPTEMBER 2025
449Before Incident
AUGUST 2025
580Before Incident
Ransomware
02 Aug 2025CRMC
Cookeville Regional Medical Center

Cookeville Regional Medical Center Data Breach and Ransomware Attack

433After Incident
CRITICAL-147
CRM1202412092025
Cookeville Regional Medical Center, a 269-bed city-owned hospital in Tennessee and a key healthcare provider in the Upper Cumberland region, suffered a ransomware attack by the RHYSIDA group on August 2, 2025. The attackers claimed to have exfiltrated sensitive personally identifiable information (PII) of patients, employees (including ~200 physicians), and other individuals who provided data to the hospital. The stolen data was threatened for publication on the dark web, with the breach formally reported to the U.S. Department of Health and Human Services (HHS) on September 12, 2025.The incident exposes affected individuals to risks such as identity theft, financial fraud, and legal liabilities, with potential long-term consequences for the hospital’s reputation, operational integrity, and financial stability. The breach disrupts a major healthcare provider serving as an economic cornerstone for the region, with 2,450+ staff impacted. Legal investigations are underway, with affected parties eligible for compensation, credit monitoring, and identity theft protection under federal/state laws. The attack’s scale and targeting of healthcare data elevate its severity due to the critical nature of medical information and the hospital’s role in public health.
INCIDENT DETAILS -
TYPE
data breachransomware attack
MOTIVATION
Financial (ransom demand), data exfiltration for dark web publication
IMPACT
Data Compromised: sensitive personally identifiable information (PII)Brand Reputation Impact: High (potential loss of trust in a major regional healthcare provider)Legal Liabilities: Potential (under investigation for compensation claims and regulatory violations)Identity Theft Risk: High (PII exposed)
DATA BREACH
Type Of Data Compromised: personally identifiable information (PII)Sensitivity Of Data: High (sensitive PII)Data Exfiltration: Yes (threatened publication on dark web)Personally Identifiable Information: Yes
JULY 2025
768Before Incident
Breach
11 Jul 2025CRMC
Cookeville Regional Medical Center: Cookeville Regional Medical CenterData Breach

Cookeville Regional Medical Center Data Breach Exposes Sensitive Patient Information

578After Incident
CRITICAL-190
CRM1776292293
Cookeville Regional Medical Center Data Breach Exposes Sensitive Patient Information On March 16, 2026, Cookeville Regional Medical Center in Cookeville, Tennessee, concluded its investigation into a data breach that compromised highly sensitive patient information. The incident, detected on July 14, 2025, revealed that an unauthorized party accessed and potentially exfiltrated files containing personal and medical data between July 11 and July 14 of that year. The exposed records included names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account details, medical treatment information, medical record numbers, and health insurance policy details. The hospital partnered with a forensic security firm to confirm the breach and assess its scope. Cookeville Regional has since begun notifying affected individuals, though legal professionals are also investigating the possibility of a class action lawsuit on behalf of those impacted. The breach raises concerns about potential financial fraud, identity theft, and long-term privacy risks for patients. No further details on the attackers’ identity or motives have been disclosed.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Personal and medical data, including names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account details, medical treatment information, medical record numbers, and health insurance policy detailsBrand Reputation Impact: Raises concerns about potential financial fraud, identity theft, and long-term privacy risks for patientsLegal Liabilities: Investigation into the possibility of a class action lawsuitIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Personal dataMedical dataSensitivity Of Data: Highly sensitiveData Exfiltration: Potentially exfiltratedNamesAddressesDates of birthSocial Security numbersDriver’s license numbersFinancial account detailsMedical treatment informationMedical record numbersHealth insurance policy details
Ransomware
11 Jul 2025CRMC
Cookeville Regional Medical Center and Southern Illinois Dermatology: Cookeville Regional Medical Center warns 338,000 people of data breach

Cookeville Regional Medical Center Hit by Rhysida Ransomware Attack

578After Incident
CRITICAL-190
SOUCRM1776271390
Cookeville Regional Medical Center Hit by Rhysida Ransomware Attack, Exposing 337K Patients’ Data Cookeville Regional Medical Center (CRMC), a 289-bed hospital in Tennessee, confirmed a July 2025 ransomware attack that compromised the personal and medical data of 337,917 individuals. The breach, detected on July 14, 2025, exposed sensitive information, including names, Social Security numbers, financial account details, medical records, health insurance data, driver’s license numbers, dates of birth, and addresses. The cybercriminal group Rhysida claimed responsibility for the attack on August 2, 2025, demanding a 10 bitcoin ransom (approximately $1.15 million) in exchange for the stolen data. CRMC has not confirmed whether it paid the ransom or how the attackers breached its network. A forensic investigation revealed unauthorized access occurred between July 11 and July 14, 2025, with systems disrupted by ransomware on July 15. As part of its response, CRMC is offering affected individuals one year of free identity theft protection through Experian. ### Rhysida’s Growing Threat to Healthcare Rhysida, a ransomware-as-a-service (RaaS) group that emerged in May 2023, has rapidly escalated its attacks, particularly against healthcare providers. In 2025 alone, the group claimed 91 ransomware incidents, with 23 confirmed by targeted organizations. Its average ransom demand is $1.2 million, and it has been linked to six confirmed healthcare breaches in 2025, including: - Florida Lung, Asthma, & Sleep Specialists (10,000 records, $639K ransom) - MedStar Health (MD) (undisclosed records, $3.09M ransom) - Spindletop Center (TX) (88,863 records, $1.65M ransom) - MACT Health Board (CA) (undisclosed records, $662K ransom) - Heart South Cardiovascular Group (AL) (46,666 records, $630K ransom) Rhysida remains active in 2026, with six additional attack claims one of which has been confirmed. ### Broader Impact on U.S. Healthcare The CRMC breach ranks as the eighth-largest healthcare data compromise in 2025, part of a surge in ransomware attacks targeting the sector. Researchers recorded 134 confirmed ransomware incidents against U.S. hospitals, clinics, and providers in 2025, exposing 11.7 million patient records. Recent attacks include: - Signature Healthcare (MA) – Attack claimed by Anubis (January 2026) - Rocky Mountain Associated Physicians (UT)50,640 records exposed (October 2025, claimed by PEAR) - Southern Illinois Dermatology – Breach claimed by Insomnia (November 2025) - Aroostook Mental Health Services (ME) – Breach claimed by Qilin (December 2025) Ransomware attacks on healthcare facilities disrupt critical operations, forcing hospitals to cancel appointments, divert patients, and revert to manual record-keeping, while exposing sensitive data to potential misuse.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial gain
IMPACT
Data Compromised: 337,917 recordsOperational Impact: Disrupted systems, potential cancellation of appointments and diversion of patientsBrand Reputation Impact: YesIdentity Theft Risk: YesPayment Information Risk: Yes
DATA BREACH
NamesSocial Security numbersFinancial account detailsMedical recordsHealth insurance dataDriver’s license numbersDates of birthAddressesNumber Of Records Exposed: 337,917Sensitivity Of Data: HighData Exfiltration: YesData Encryption: Yes (ransomware encryption)Personally Identifiable Information: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CRMC ?
?
What was CRMC's A.I Rankiteo Cyber Score in June 2026 ?
?
What was CRMC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CRMC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CRMC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CRMC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CRMC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CRMC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CRMC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CRMC's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CRMC's A.I Rankiteo Cyber Score in September 2025 ?
?
What was CRMC's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on CRMC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CRMC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CRMC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?