Nacogdoches Memorial Hospital confirmed a ransomware event in October 2025 affecting approximately 2.5 million patient records. The breach triggered mandatory HHS OCR notification and Texas AG disclosure.
Initial access via unpatched VPN appliance (CVE class: remote code execution on perimeter device). Lateral movement across flat hospital network enabled rapid propagation to all clinical systems within 36 hours. Credential harvesting preceded payload detonation.
Sentinel ($89/ep/mo) — 24/7 SOC + SIEM. Fortress ($109/ep/mo) — Sentinel + EDR management + vulnerability management. Command ($129/ep/mo) — Fortress + vCISO + compliance mapping + IR plan. See full tier comparison →
| Regime | Standard / Citation | Gap Identified |
|---|---|---|
| HIPAA | 45 CFR §164.312(a)(1) | Access control — no network segmentation between clinical and administrative systems |
| HIPAA | 45 CFR §164.308(a)(5) | Security awareness — no phishing simulation or tabletop exercise documented in 18 months |
| TDPA | Tex. B&C Code §521.053 | Breach notification — 60-day AG notice requirement triggered for 2.5M TX residents |
CoreRecon cites verifiable public sources only. No speculation on unverified attribution is published. Threat actor attribution appears only where publicly confirmed by law enforcement or the organization.
Free $2,500 security posture assessment for Texas organizations. We map your gaps against the same attack vectors used in this incident. No contract, no commitment.