Following claims on the dark web, Cameron Regional Medical Center confirmed that it was the victim of a ransomware attack. The hospital discovered the breach on June 18, 2026. The total number of individuals affected has not been disclosed.
Cameron Regional Medical Center was the target of what it described as a “sophisticated ransomware attack.” The hospital has not disclosed additional details about how the attackers gained access to its systems or how long they may have had access before the incident was detected.
On Aug. 3, 2026, a ransomware group known as Anubis claimed responsibility for the attack in a posting on the Tor network, a part of the dark web. The group claimed to have obtained a wide range of data from the hospital.
According to the dark web posting, the compromised data reportedly includes patient records, internal investigations, HIPAA-related documents, employee information, medical records, operational documents and other sensitive healthcare information.
Anubis stated it intended to publish the stolen data within six days of its posting. The group’s claims, if accurate, suggest the scope of the breach extends beyond patient records to include employee data and internal hospital documents.
The hospital’s own investigation into the breach remains ongoing. Based on its findings to date, the hospital stated it believes that protected health information belonging to patients may have been subject to unauthorized access. However, the hospital noted it was “unable to confirm the specific information that may be affected at this time,” according to its notification.
The types of personally identifiable information (PII) potentially exposed include patient names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account information, electronic or digital signatures and employer-assigned identification numbers.
Protected health information (PHI) potentially exposed include medical diagnosis and treatment information, dates of medical treatment, medical provider names, patient identification numbers, agency-assigned identification numbers, treatment cost information and health insurance information. The range of data potentially compromised covers personal, financial and medical records.
The hospital posted a notice about the data incident and stated that affected individuals will receive written notification
Cameron Regional Medical Center’s response
The hospital stated that it has “established existing security measures and facilities which were previously audited,” according to the notification.
At the time of the notice, the hospital said it was “not aware of any evidence to suggest that any information has been fraudulently misused.” However, it also acknowledged that it has “not yet been able to ascertain fraudulent attempts to utilize the aforementioned information,” which indicates the review of potential misuse is still in progress.
Any individuals and accounts determined to be affected will receive additional details from the hospital, according to the notification. The hospital’s notice does not include an offer of free credit monitoring or identity protection services for affected individuals.
Because the potentially exposed data includes highly sensitive information such as Social Security numbers, driver’s license numbers and financial account details, affected individuals may want to take protective action on their own while the investigation continues.
Cameron Regional Medical Center has set up an Incident Response Team to answer questions about the incident. The team can be reached by phone at 816-614-1141 or in writing at 1600 E. Evergreen St., Cameron, MO 64429.
In its notification, the hospital stated: “We take the privacy and security of the information in our care seriously, and sincerely regret any worry or inconvenience this incident may have caused.”
