Company Details
murfreesboro-medical-clinic-surgicenter
263
1,139
621
mmclinic.com
0
MUR_1557075
In-progress


Murfreesboro Medical Clinic & SurgiCenter Vendor Cyber Rating & Cyber Score
mmclinic.comMurfreesboro Medical Clinic & SurgiCenter is a multi-specialty, physician-owned clinic, offering over 20 departments and 100+ physicians. From primary care, surgery and specialty treatments, MMC offers convenience for each individual's healthcare needs. Your health is our mission.
Company Details
murfreesboro-medical-clinic-surgicenter
263
1,139
621
mmclinic.com
0
MUR_1557075
In-progress
Between 550 and 599

MMCS Global Score (TPRM)XXXX

Description: New to ClassAction.org? Read our Newswire Disclaimer Murfreesboro Medical Clinic (MMC) has agreed to settle a class action lawsuit over an April 2023 ransomware attack that allegedly compromised private patient and employee information. Want to stay in the loop on class action lawsuits that matter to you? Sign up for ClassAction.org’s free weekly newsletter. The MMC class action settlement received preliminary approval from the court on September 16, 2025 and covers all individuals whose private information may have been compromised as a result of the April 2023 Murfreesboro Medical Clinic & Surgicenter data breach, and to whom MMC sent a notice about the incident. Per court documents, the information of approximately 559,000 MMC patients and employees was potentially exposed in the incident. The court-approved website for the MMC settlement can be found at https://MMCSettlement.com/. Per the settlement site, MMC settlement class members who submit a valid, timely claim form have multiple options for reimbursement. Class members who submit a valid claim form for reimbursement of documented out-of-pocket expenses are entitled to receive a one-time cash payment of up to $500 to cover losses reasonably incurred as a result of the data breach. The class action settlement agreement details that reimbursable losses covered under this option include those related to identity theft, fees for credit repair services, costs to freeze and/or replace credit cards, and credit monitori


No incidents recorded for Murfreesboro Medical Clinic & SurgiCenter in 2026.
No incidents recorded for Murfreesboro Medical Clinic & SurgiCenter in 2026.
No incidents recorded for Murfreesboro Medical Clinic & SurgiCenter in 2026.
MMCS cyber incidents detection timeline including parent company and subsidiaries

Murfreesboro Medical Clinic & SurgiCenter is a multi-specialty, physician-owned clinic, offering over 20 departments and 100+ physicians. From primary care, surgery and specialty treatments, MMC offers convenience for each individual's healthcare needs. Your health is our mission.


Hamad Medical Corporation (HMC) is the main provider of secondary and tertiary healthcare in Qatar and one of the leading hospital providers in the Middle East. For more than three decades, HMC has been dedicated to delivering the safest, most effective and compassionate care to all its patients.
.png)
Ascension Saint Thomas announced Wednesday that it has received state approval to build a new freestanding emergency department in...
Ascension Saint Thomas received state approval for one of its planned freestanding emergency departments. The hospital system can now build...
Dr. Horwitz makes every patient feel like his only priority. Whether performing complex robotic surgery or providing life-changing breast care,...
MURFREESBORO, TN - A Murfreesboro tradition is lacing up for another year. The 15th Annual Special Kids Race has officially been announced...
MURFEESBORO, TN - Today on the WGNS Action Line, host Scott Walker sits down with Dr. Sarvani Singh of Murfreesboro Medical Clinic's...
Under the terms of the Murfreesboro Medical Clinic settlement, class members can receive up to $500 for out-of-pocket expenses related to the...
agreed to settle a class action lawsuit alleging a ransomware attack in April 2023 exposed the private information of patients and employees.
Murfreesboro Medical Clinic is proud to highlight these medical professionals with the MMC Heart for Healing Award.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Murfreesboro Medical Clinic & SurgiCenter is http://Www.mmclinic.com.
According to Rankiteo, Murfreesboro Medical Clinic & SurgiCenter’s AI-generated cybersecurity score is 598, reflecting their Very Poor security posture.
According to Rankiteo, Murfreesboro Medical Clinic & SurgiCenter currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Murfreesboro Medical Clinic & SurgiCenter has not been affected by any supply chain cyber incidents, and no incident IDs are currently listed for the organization.
According to Rankiteo, Murfreesboro Medical Clinic & SurgiCenter is not certified under SOC 2 Type 1.
According to Rankiteo, Murfreesboro Medical Clinic & SurgiCenter does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Murfreesboro Medical Clinic & SurgiCenter is not listed as GDPR compliant.
According to Rankiteo, Murfreesboro Medical Clinic & SurgiCenter does not currently maintain PCI DSS compliance.
According to Rankiteo, Murfreesboro Medical Clinic & SurgiCenter is not compliant with HIPAA regulations.
According to Rankiteo,Murfreesboro Medical Clinic & SurgiCenter is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Murfreesboro Medical Clinic & SurgiCenter operates primarily in the Medical Practices industry.
Murfreesboro Medical Clinic & SurgiCenter employs approximately 263 people worldwide.
Murfreesboro Medical Clinic & SurgiCenter presently has no subsidiaries across any sectors.
Murfreesboro Medical Clinic & SurgiCenter’s official LinkedIn profile has approximately 1,139 followers.
Murfreesboro Medical Clinic & SurgiCenter is classified under the NAICS code 621, which corresponds to Ambulatory Health Care Services.
No, Murfreesboro Medical Clinic & SurgiCenter does not have a profile on Crunchbase.
Yes, Murfreesboro Medical Clinic & SurgiCenter maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/murfreesboro-medical-clinic-surgicenter.
As of April 03, 2026, Rankiteo reports that Murfreesboro Medical Clinic & SurgiCenter has experienced 1 cybersecurity incidents.
Murfreesboro Medical Clinic & SurgiCenter has an estimated 9,318 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with notice sent to affected individuals, communication strategy with settlement website (https://mmcsettlement.com/)..
Title: Murfreesboro Medical Clinic Ransomware Attack and Data Breach (April 2023)
Description: Murfreesboro Medical Clinic (MMC) experienced a ransomware attack in April 2023 that compromised private patient and employee information, affecting approximately 559,000 individuals. The incident led to a class action lawsuit, which was preliminarily approved for settlement on September 16, 2025. The settlement offers reimbursement of up to $500 for documented out-of-pocket expenses related to identity theft, credit repair, and monitoring services.
Type: ransomware
Common Attack Types: The most common types of attacks the company has faced is Ransomware.
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Patient Information, Employee Information and .

Entity Name: Murfreesboro Medical Clinic & Surgicenter (MMC)
Entity Type: healthcare provider
Industry: healthcare
Location: Murfreesboro, Tennessee, USA
Customers Affected: 559000

Communication Strategy: notice sent to affected individualssettlement website (https://MMCSettlement.com/)

Type of Data Compromised: Patient information, Employee information
Number of Records Exposed: 559000
Sensitivity of Data: high (private/confidential)

Data Exfiltration: True

Legal Actions: class action lawsuit, settlement agreement,
Ensuring Regulatory Compliance: The company ensures compliance with regulatory requirements through class action lawsuit, settlement agreement, .
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: ClassAction.orgUrl: https://MMCSettlement.com/.

Investigation Status: settled (preliminary approval granted on September 16, 2025)
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notice Sent To Affected Individuals and Settlement Website (Https://Mmcsettlement.Com/).

Stakeholder Advisories: Court-Approved Settlement Website, Notice To Affected Individuals.
Customer Advisories: reimbursement for out-of-pocket expenses (up to $500)credit monitoring services
Advisories Provided: The company provides the following advisories to stakeholders and customers following an incident: were Court-Approved Settlement Website, Notice To Affected Individuals, Reimbursement For Out-Of-Pocket Expenses (Up To $500), Credit Monitoring Services and .

High Value Targets: Patient Data, Employee Data,
Data Sold on Dark Web: Patient Data, Employee Data,
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 559.0.
Most Significant Legal Action: The most significant legal action taken for a regulatory violation was class action lawsuit, settlement agreement, .
Most Recent Source: The most recent source of information about an incident is ClassAction.org.
Most Recent URL for Additional Resources: The most recent URL for additional resources on cybersecurity best practices is https://MMCSettlement.com/ .
Current Status of Most Recent Investigation: The current status of the most recent investigation is settled (preliminary approval granted on September 16, 2025).
Most Recent Stakeholder Advisory: The most recent stakeholder advisory issued was court-approved settlement website, notice to affected individuals, .
Most Recent Customer Advisory: The most recent customer advisory issued was an reimbursement for out-of-pocket expenses (up to $500)credit monitoring services.
.png)
Hirschmann EagleSDV version 05.4.01 prior to 05.4.02 contains a denial-of-service vulnerability that causes the device to crash during session establishment when using TLS 1.0 or TLS 1.1. Attackers can trigger a crash by initiating TLS connections with these protocol versions to disrupt service availability.
The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of the encryption credentials.
XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services
Multiple reflected cross-site scripting (XSS) vulnerabilities in the login.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda and red_url parameters.
A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.