Cedar County Memorial Hospital recently disclosed that it was hit by a ransomware attack that disabled certain operations for about two weeks.

 

What happened

On August 23rd, 2026, Cedar County Memorial Hospital (CCMH) in Missouri disclosed that it was facing a large cyberattack. CCMH operates a hospital and three clinics with varying specialties.

The attack, which began on August 14th, disrupted its IT systems and CCMH chose to take the impacted computers offline while they worked to resolve the situation. Network access was also paused as the hospital worked to contain the incident. Ultimately, both the patient portal and electronic health record (EHR) system were down for about two weeks. The EHR outage also affected the Medical Mall Clinic, CCMH’s general clinic. As a result, the emergency department had to be placed on partial diversion since medical imaging systems could not transmit critical medical images to radiologists.

 

Going deeper

On August 28th, 2026, CCMH confirmed that the hospital was now back to routine operations after internal and external system reviews and safety checks had been completed. CCMH also said they were in the process of transferring manually recorded information into the EHR. During the outage, patients had been told to bring paper orders and current medication lists. Patients were also told to expect longer wait times. Lastly, during the outage, the hospital also stopped accepting card payments.

CCMH provided another update on September 10th, 2026, sharing that data had been stolen in the cyberattack and that the hospital was working toward completing an investigation and review of what had been exposed. At this time, they do not yet know how many individuals were impacted or what data may have been involved. CCMH plans to notify patients as soon as they have more information.

 

In the know

A fairly new ransomware group called Wallstreet has claimed responsibility for the attack. The group added CCMH to its dark web data leak site in August, threatening to publish data stolen in the attack. Little is known about the organization, which emerged in early 2026, but it’s believed the organization originates from Russia and currently has approximately 17 victims, a large number considering they’ve been active for a short time.

 

The big picture

Despite the disruption, CCMH continued to treat patients, helping approximately 170 emergency patients, admitting 12 individuals, and seeing over 300 clinic patients and over 200 specialty-clinic patients. The hospital also completed 15 surgical procedures and 286 radiology scans.

While the hospital and clinics continued to treat patients, it’s important to note that CCMH is Cedar County’s only hospital, making it a bedrock for residents. According to one Paubox article, rural hospitals can be particularly vulnerable to cyberattacks, with studies showing that these hospitals tend to operate on tighter budgets, which can have a direct impact on the ability to invest in cybersecurity infrastructure. With tighter margins, care disruptions can also have an outsized impact on revenue during downed time. The report noted that in some cases, a cyberattack can even lead to an organization permanently shutting their doors, as is the case for now-defunct St. Margaret’s Health in Spring Valley, Illinois. The hospital closed in 2023, two years after they faced a large cyberattack, which was listed as one of the reasons for the closure. Residents in the area called the closure “devastating.”

Despite the challenges, some rural hospitals are turning to solutions like Paubox, which offer a critical layer of email security that is priced depending on the number of users, meaning that smaller hospitals pay a far different amount than their larger counterparts, making the software significantly more accessible.

 

FAQs

Why would CCMH choose to take their computers and systems offline?

The choice to power down these systems is not one taken lightly. CCMH likely opted to do this to prevent more data from being stolen and to fully assess the situation. While it’s rare for organizations to make this choice, it shows that CCMH was proceeding very cautiously, which could have helped prevent the spread of the breach.

 

Is it confirmed that the Wallstreet ransom gang is responsible for the attack?

The Wallstreet gang has claimed the attack and alleges that they have the data, but we won’t know if it’s true unless the data is published. It’s always possible that organizations could be dishonest, which is why it’s important for healthcare companies to not engage with ransomware groups without assistance from the FBI or other law enforcement.