← Cameron Regional Medical Center

2026 Cameron Regional Medical Center — Jun 18 ransomware; PHI access/exfil investigation; Anubis claimed

2026 Unknown records affected Share on X

Data compromised

Patient PHI likely including names plus some or all of addresses, DOBs, SSNs, driver’s licenses, financial accounts, diagnosis/treatment, dates of service, provider names, patient/agency IDs, treatment costs, health insurance, electronic signatures, and/or employer IDs (per hospital notice)

Technical writeup

Verified hospital announcement summarized by HIPAA Journal — August 18 / September 3, 2026 update. Cameron Regional Medical Center (60-bed acute care, Cameron, Missouri) said it discovered a sophisticated ransomware attack; files were encrypted June 18, 2026. Initial findings indicate patient PHI was subject to unauthorized access and may have been exfiltrated; individual letters will follow when data review completes. No misuse identified at notice time. Anubis claimed responsibility and leaked sample patient information, alleging ~500 GB stolen — actor volume remains unverified. recordsAffected 0 pending hospital census; companyConfirmed true for the intrusion.

Root cause

Ransomware attack detected June 18, 2026 when files were encrypted; hospital investigation ongoing; Anubis claimed ~500 GB exfiltration

References