CRMC A.I CyberSecurity Scoring
CRMC
Company Information
Website:http://www.crmchealth.org
Employees number:2,416
Number of followers:5,607
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:crmchealth.org
CRMC Risk Score (AI oriented)
Between 0 and 549
CRMCHospitals and Health Care
Updated:
17/04/2026
17/04/2026
267/1000
Critical
C
CRMC Global Score (TPRM)
xxxx
CRMCHospitals and Health Care
Score locked

CRMCCritical
Current Score
267C (CRITICAL)
01000
4 incidents
-188 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
306
JUNE 2026
294
MAY 2026
283
APRIL 2026
496
Ransomware
16 Apr 2026 • CRMC
Cookeville Regional Medical Center, Florida Lung, Asthma & Sleep Specialists and Heart South Cardiovascular Group: Cookeville Hospital Discloses Rhysida Breach Hitting 337,917
Cookeville Regional Medical Center Hit by Rhysida Ransomware Attack
267
CRITICAL-229
PEAFLOCRM1776443473
Cookeville Regional Medical Center Hit by Rhysida Ransomware Attack, Exposing 337,917 Patients’ Data
Cookeville Regional Medical Center (CRMC), a 309-bed hospital serving 14 counties in Tennessee’s Upper Cumberland region, has notified 337,917 patients that their personal and medical data was compromised in a July 2025 ransomware attack. Breach notification letters were mailed on April 14, 2026 nearly nine months after the intrusion was detected.
The attack, attributed to the Russia-linked Rhysida ransomware-as-a-service group, occurred between July 11 and July 14, 2025. Rhysida claimed responsibility on August 2, 2025, demanding a 10 Bitcoin ransom (approximately $1.15 million at the time) and publishing sample files on its dark web leak site. It remains unclear whether CRMC paid the ransom.
Exposed data may include names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account details, medical record numbers, treatment information, and health insurance data. In response, CRMC is offering affected individuals 12 months of free identity theft protection through Experian.
The incident ranks as the eighth-largest U.S. healthcare ransomware breach of 2025 by records compromised. Comparitech, which tracked 134 confirmed attacks on U.S. healthcare providers last year, reported that these breaches exposed 11.7 million records. Rhysida alone claimed 91 attacks across all sectors in 2025, with 23 confirmed and an average ransom demand of $1.2 million.
Other recent Rhysida healthcare victims include Florida Lung, Asthma & Sleep Specialists ($639,000 demand), MedStar Health ($3.09 million), Spindletop Center ($1.65 million), MACT Health Board ($662,000), and Heart South Cardiovascular Group ($630,000).
Rebecca Moody, head of data research at Comparitech, noted that the extended investigation timeline reflects the complexity of forensic analysis following hospital ransomware attacks. She also highlighted that delayed or vague breach notifications can increase risks of identity theft and phishing for affected individuals.
CRMC has since implemented additional security measures in the wake of the attack. Ransomware incidents at U.S. hospitals frequently result in prolonged downtime, canceled appointments, and patient diversions, even when clinical systems remain operational.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
493
FEBRUARY 2026
486
JANUARY 2026
479
DECEMBER 2025
472
NOVEMBER 2025
464
OCTOBER 2025
457
SEPTEMBER 2025
449
AUGUST 2025
580
Ransomware
02 Aug 2025 • CRMC
Cookeville Regional Medical Center
Cookeville Regional Medical Center Data Breach and Ransomware Attack
433
CRITICAL-147
CRM1202412092025
Cookeville Regional Medical Center, a 269-bed city-owned hospital in Tennessee and a key healthcare provider in the Upper Cumberland region, suffered a ransomware attack by the RHYSIDA group on August 2, 2025. The attackers claimed to have exfiltrated sensitive personally identifiable information (PII) of patients, employees (including ~200 physicians), and other individuals who provided data to the hospital. The stolen data was threatened for publication on the dark web, with the breach formally reported to the U.S. Department of Health and Human Services (HHS) on September 12, 2025.The incident exposes affected individuals to risks such as identity theft, financial fraud, and legal liabilities, with potential long-term consequences for the hospital’s reputation, operational integrity, and financial stability. The breach disrupts a major healthcare provider serving as an economic cornerstone for the region, with 2,450+ staff impacted. Legal investigations are underway, with affected parties eligible for compensation, credit monitoring, and identity theft protection under federal/state laws. The attack’s scale and targeting of healthcare data elevate its severity due to the critical nature of medical information and the hospital’s role in public health.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2025
768
Breach
11 Jul 2025 • CRMC
Cookeville Regional Medical Center: Cookeville Regional Medical CenterData Breach
Cookeville Regional Medical Center Data Breach Exposes Sensitive Patient Information
578
CRITICAL-190
CRM1776292293
Cookeville Regional Medical Center Data Breach Exposes Sensitive Patient Information
On March 16, 2026, Cookeville Regional Medical Center in Cookeville, Tennessee, concluded its investigation into a data breach that compromised highly sensitive patient information. The incident, detected on July 14, 2025, revealed that an unauthorized party accessed and potentially exfiltrated files containing personal and medical data between July 11 and July 14 of that year.
The exposed records included names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account details, medical treatment information, medical record numbers, and health insurance policy details. The hospital partnered with a forensic security firm to confirm the breach and assess its scope.
Cookeville Regional has since begun notifying affected individuals, though legal professionals are also investigating the possibility of a class action lawsuit on behalf of those impacted. The breach raises concerns about potential financial fraud, identity theft, and long-term privacy risks for patients. No further details on the attackers’ identity or motives have been disclosed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Ransomware
11 Jul 2025 • CRMC
Cookeville Regional Medical Center and Southern Illinois Dermatology: Cookeville Regional Medical Center warns 338,000 people of data breach
Cookeville Regional Medical Center Hit by Rhysida Ransomware Attack
578
CRITICAL-190
SOUCRM1776271390
Cookeville Regional Medical Center Hit by Rhysida Ransomware Attack, Exposing 337K Patients’ Data
Cookeville Regional Medical Center (CRMC), a 289-bed hospital in Tennessee, confirmed a July 2025 ransomware attack that compromised the personal and medical data of 337,917 individuals. The breach, detected on July 14, 2025, exposed sensitive information, including names, Social Security numbers, financial account details, medical records, health insurance data, driver’s license numbers, dates of birth, and addresses.
The cybercriminal group Rhysida claimed responsibility for the attack on August 2, 2025, demanding a 10 bitcoin ransom (approximately $1.15 million) in exchange for the stolen data. CRMC has not confirmed whether it paid the ransom or how the attackers breached its network. A forensic investigation revealed unauthorized access occurred between July 11 and July 14, 2025, with systems disrupted by ransomware on July 15.
As part of its response, CRMC is offering affected individuals one year of free identity theft protection through Experian.
### Rhysida’s Growing Threat to Healthcare
Rhysida, a ransomware-as-a-service (RaaS) group that emerged in May 2023, has rapidly escalated its attacks, particularly against healthcare providers. In 2025 alone, the group claimed 91 ransomware incidents, with 23 confirmed by targeted organizations. Its average ransom demand is $1.2 million, and it has been linked to six confirmed healthcare breaches in 2025, including:
- Florida Lung, Asthma, & Sleep Specialists (10,000 records, $639K ransom)
- MedStar Health (MD) (undisclosed records, $3.09M ransom)
- Spindletop Center (TX) (88,863 records, $1.65M ransom)
- MACT Health Board (CA) (undisclosed records, $662K ransom)
- Heart South Cardiovascular Group (AL) (46,666 records, $630K ransom)
Rhysida remains active in 2026, with six additional attack claims one of which has been confirmed.
### Broader Impact on U.S. Healthcare
The CRMC breach ranks as the eighth-largest healthcare data compromise in 2025, part of a surge in ransomware attacks targeting the sector. Researchers recorded 134 confirmed ransomware incidents against U.S. hospitals, clinics, and providers in 2025, exposing 11.7 million patient records.
Recent attacks include:
- Signature Healthcare (MA) – Attack claimed by Anubis (January 2026)
- Rocky Mountain Associated Physicians (UT) – 50,640 records exposed (October 2025, claimed by PEAR)
- Southern Illinois Dermatology – Breach claimed by Insomnia (November 2025)
- Aroostook Mental Health Services (ME) – Breach claimed by Qilin (December 2025)
Ransomware attacks on healthcare facilities disrupt critical operations, forcing hospitals to cancel appointments, divert patients, and revert to manual record-keeping, while exposing sensitive data to potential misuse.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for CRMC ??
What was CRMC's A.I Rankiteo Cyber Score in June 2026 ??
What was CRMC's A.I Rankiteo Cyber Score in May 2026 ??
What was CRMC's A.I Rankiteo Cyber Score in April 2026 ??
What was CRMC's A.I Rankiteo Cyber Score in March 2026 ??
What was CRMC's A.I Rankiteo Cyber Score in February 2026 ??
What was CRMC's A.I Rankiteo Cyber Score in January 2026 ??
What was CRMC's A.I Rankiteo Cyber Score in December 2025 ??
What was CRMC's A.I Rankiteo Cyber Score in November 2025 ??
What was CRMC's A.I Rankiteo Cyber Score in October 2025 ??
What was CRMC's A.I Rankiteo Cyber Score in September 2025 ??
What was CRMC's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on CRMC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with CRMC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view CRMC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?