HackingHealthcareHealthcareDelayed DiscoveryCustomer Data InvolvedHigh
Cookeville Regional Medical Center
bd_276e5eca9296aab3 · schema v1 · pii pii-v1
Full breach record for Cookeville Regional Medical Center →Cookeville Regional Medical Center (Cookeville, TN) reported an external system breach (hacking) to the Maine Attorney General. The incident occurred on 07/11/2025 and was discovered on 03/16/2026. A total of 337,917 individuals were affected, including 22 Maine residents. Written consumer notifications were sent on 04/14/2026, and 12 months of Experian identity theft protection services were offered. Notification was filed by Alexander Boyd of Polsinelli PC. The filing did not enumerate which specific data elements were acquired.
Leak gap clock✗ Leak >180d29 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
A leak claim by rhysida about this victim predates this filing by 275 days.View originating leak claim
Linked disclosures
Why this link?Ransomware claims (2)
- bd_de82a746a3abaa1bLeak Siterhysidafiled 2025-08-02(255d gap)Verified
- bd_0f974ae893d48768Leak Siterhysidafiled 2025-07-13(275d gap)Verified
Source provenance
- Source URL
- https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/fb04ea66-92bb-4a15-b02c-8d1a9f783461.html
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 14, 2026
- Raw hash
- 96d8ebb62461d7a7c9cc78c44be932b38149794fb6903292e437786c378bb9ea
Reporting entity
- Name
- Polsinelli PCnorm: polsinelli
Victim entity
- Name
- Cookeville Regional Medical Centernorm: cookeville regional medical center
- Industry
- Healthcare
- Industry
- Healthcarellm
Incident
- Discovered
- Mar 16, 2026
- Materiality determined
- —
- Notification sent
- Apr 14, 2026
- Affected individuals
- 337,917
- Data types
- —
- Attack vector
- Unauthorized Access
- Threat actor
- External
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- Leak >180dME AG ≤30d · 29d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status Maine Discovered: Mar 16, 2026→ Filed with AG: Apr 14, 202629d 30 days ME AG ≤30d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.