Cerner legacy systems data incident

Unauthorized access to data maintained on legacy Cerner systems, with activity reported from January 22 through April 1, 2025. Personal identifiers and medical-record information obtained from legacy Cerner systems.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized access to data maintained on legacy Cerner systems, with activity reported from January 22 through April 1, 2025. [1][2]

Impact

Personal identifiers and medical-record information obtained from legacy Cerner systems. [1][2]

Documented data types include:

  • Social Security numbers — Social Security numbers; fields varied by individual and organization. [1]
  • Clinical information — Doctors, diagnoses, medicines, test results, images, care, and treatment; fields varied by individual and organization. [1]
  • Names — Patient names; fields varied by individual and organization. [1]
  • Patient account numbers — Medical record numbers; fields varied by individual and organization. [1]

A cited record reports 2,658,388 individuals (Texas residents reported in BR-0005159; a subset of the overall count and not additive; as of 2026-07-07). [1][2]

A cited record reports 18,565,730 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005159; regulator-reported and not independently verified; as of 2026-07-07). [1][2]

Munson Healthcare said an unauthorized third party gained access to and obtained personal health information maintained on legacy Cerner systems. [1]

Timeline

  1. Activity began

    Earliest date in the regulator-reported activity range and the date Munson said Cerner’s investigation identified as at least the start of access.

    [1]
  2. Discovery

    Discovery date reported in Texas Attorney General report BR-0005159.

    [2]
  3. Documented activity ended

    End of the activity range reported in Texas Attorney General report BR-0005159.

    [2]
  4. Public disclosure

    Publication date of the California Attorney General’s Cerner sample incident-notification page.

    [3]
  5. Public disclosure

    Publication date of Texas Attorney General report BR-0005159, which carried materially larger affected counts.

    [2]
  6. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Munson Healthcare and Cerner offered affected patients 24 months of Experian credit monitoring and identity-restoration services. Munson Healthcare said Cerner secured the system and engaged law enforcement and cybersecurity specialists. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1]