Skip to main content
Jump to a category page

Federal law gives a healthcare provider 60 days to tell patients about a data breach. Cameron Regional Medical Center posted its notice on exactly the sixtieth day, and patients still have not received individual letters more than two weeks later.

Cameron Regional Medical Center, a 60-bed acute care hospital and specialty clinic system serving rural northwest Missouri, was hit by a ransomware attack that encrypted files on its network on June 18, 2026. On August 3, 2026, the Anubis ransomware group posted Cameron Regional to its dark web leak site and published a sample of stolen data, including patient information, claiming to have exfiltrated roughly 500 gigabytes. Cameron Regional posted a substitute notice to its own website on August 17, 2026, confirming the ransomware attack and stating that individual letters would be mailed once its data review concluded.

As of this writing, more than two and a half months after the attack was discovered, Cameron Regional has not confirmed that individual notice letters have been sent.

A 60-Day Deadline Met on the Last Possible Day, Then Missed Anyway

Federal law is specific here. Under 45 C.F.R. § 164.404(b), a healthcare provider covered by HIPAA must provide individual notice of a breach without unreasonable delay and in no case later than 60 calendar days after discovery. Cameron Regional discovered the attack on June 18, 2026, when its files were encrypted, a discovery date that is not in dispute because ransomware announces itself. Sixty days from that date fell on August 17, 2026, the same day Cameron Regional posted its substitute website notice rather than sending individual letters. A website posting can satisfy HIPAA’s substitute notice provision only under specific conditions, and it does not fulfill the requirement to individually notify patients whose information was involved.

The timing is made worse by what happened in between. Anubis published a sample of Cameron Regional’s stolen patient data on its leak site on August 3, 2026, two weeks before the hospital said anything publicly. Patient names, Social Security numbers, and driver’s license numbers were sitting on a criminal website while the people they belonged to had no idea anything was wrong.

What Information Was Exposed?

Cameron Regional’s own notice affirmatively confirms the following categories of information were involved, rather than listing them as merely possible:

  • Name
  • Home address
  • Date of birth
  • Social Security number
  • Driver’s license number
  • Financial account information
  • Medical diagnosis and treatment information
  • Dates of medical treatment
  • Medical provider names
  • Patient ID numbers
  • Agency-assigned identification numbers
  • Treatment cost information
  • Health insurance information
  • Electronic and digital signatures
  • Employer-assigned identification numbers

The inclusion of electronic and digital signatures is worth noting on its own. A stored signature image can be used directly for document forgery in a way a Social Security number cannot, and it is not something credit monitoring can fix.

What Is Cameron Regional Offering?

Cameron Regional has not disclosed a population figure or a credit monitoring or identity protection offer as of this writing. The hospital’s data review remains ongoing, and it has said only that individual letters will follow once that review concludes.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Healthcare providers are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

The information involved in this incident also qualifies as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Do You Have Legal Options?

Healthcare providers have a legal duty to safeguard patient information and to notify patients within the timeframe federal law requires. Cameron Regional’s own website notice states its investigation is ongoing and that letters have not yet gone out, more than 60 days after the hospital discovered the attack. Patients affected by this breach may have rights and remedies under Missouri and federal law, including claims based on negligence and breach of implied contract tied to the hospital’s delay.

If you are a current or former patient of Cameron Regional Medical Center and believe your information was affected, contact the Data Breach Attorneys at Emery | Reddy for a Free Case Review.

Frequently Asked Questions

How many people were affected by the Cameron Regional data breach?

Cameron Regional has not disclosed a population figure. The hospital states its data review is still in progress and that the number of affected individuals has not yet been determined, even internally.

Did Cameron Regional meet the HIPAA notification deadline?

Cameron Regional discovered the ransomware attack on June 18, 2026. The 60-day deadline under 45 C.F.R. § 164.404(b) fell on August 17, 2026, the same day the hospital posted a substitute notice to its website rather than sending individual patient letters. As of this writing, individual notice still has not been confirmed as sent.

Who is behind the attack?

The ransomware group Anubis publicly claimed responsibility, posting Cameron Regional to its dark web leak site on August 3, 2026 and publishing a sample of stolen data, including patient information, as proof of the attack. Anubis claims to have exfiltrated approximately 500 gigabytes of data.

Is Cameron Regional offering credit monitoring?

Cameron Regional has not announced a credit monitoring or identity protection offer as of this writing.

What should I do if I am a current or former Cameron Regional patient?

Watch your financial accounts, insurance statements, and credit reports for unfamiliar activity, particularly since Social Security numbers and driver’s license numbers were published on a leak site. Consider placing a fraud alert or credit freeze on your credit file. Keep records of your care at Cameron Regional, and consider speaking with a data breach attorney about your options even before individual notice letters arrive.

Do I have a legal claim?

You may. Healthcare providers are required by law to protect patient information and to notify patients within HIPAA’s required timeframe. Contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now