The real risk is not the ransom event. It is the public release of patient records that can be reused for fraud long after the hospital closes the incident. Patching or containment does not undo stolen names, Social Security numbers, driver’s license numbers, and medical data.
Cookeville Regional Medical Center says the July 2025 intrusion affected 337,917 people and may have exposed names, addresses, dates of birth, SSNs, driver’s license numbers, financial account details, medical record numbers, treatment information, and health insurance data. Rhysida claimed the attack, said it stole more than 370,000 files totaling 500 GB, and later made the data available for download after failing to sell it.
That turns a ransomware case into a long-tail identity and medical fraud problem. Even if no misuse has been confirmed yet, the exposure persists because the stolen data is already out of the hospital’s control.