Summary
- Environment: Not publicly identified
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Impact
Personal identifiers and medical-record information obtained from legacy Cerner systems. [1][2]
Documented data types include:
- Social Security numbers — Social Security numbers; fields varied by individual and organization. [1]
- Clinical information — Doctors, diagnoses, medicines, test results, images, care, and treatment; fields varied by individual and organization. [1]
- Names — Patient names; fields varied by individual and organization. [1]
- Patient account numbers — Medical record numbers; fields varied by individual and organization. [1]
A cited record reports 2,658,388 individuals (Texas residents reported in BR-0005159; a subset of the overall count and not additive; as of 2026-07-07). [1][2]
A cited record reports 18,565,730 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005159; regulator-reported and not independently verified; as of 2026-07-07). [1][2]
Munson Healthcare said an unauthorized third party gained access to and obtained personal health information maintained on legacy Cerner systems. [1]
Timeline
Activity began
Earliest date in the regulator-reported activity range and the date Munson said Cerner’s investigation identified as at least the start of access.
[1]Discovery
Discovery date reported in Texas Attorney General report BR-0005159.
[2]Documented activity ended
End of the activity range reported in Texas Attorney General report BR-0005159.
[2]Public disclosure
Publication date of the California Attorney General’s Cerner sample incident-notification page.
[3]Public disclosure
Publication date of Texas Attorney General report BR-0005159, which carried materially larger affected counts.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
Munson Healthcare and Cerner offered affected patients 24 months of Experian credit monitoring and identity-restoration services. Munson Healthcare said Cerner secured the system and engaged law enforcement and cybersecurity specialists. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]
