---
title: "Cerner legacy systems data incident"
description: "Evidence-backed account of Cerner legacy systems data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/cerner-legacy-systems-data-incident-2025"
markdown_url: "https://www.ally.security/incidents/cerner-legacy-systems-data-incident-2025.md"
stix_url: "https://www.ally.security/incidents/cerner-legacy-systems-data-incident-2025/stix.json"
---

# Cerner legacy systems data incident

Unauthorized access to data maintained on legacy Cerner systems, with activity reported from January 22 through April 1, 2025. Personal identifiers and medical-record information obtained from legacy Cerner systems.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to data maintained on legacy [Cerner](https://www.cerner.com/) systems, with activity reported from January 22 through April 1, 2025. [1](#source-1) [2](#source-2)

## Impact

Personal identifiers and medical-record information obtained from legacy Cerner systems. [1](#source-1) [2](#source-2)

Documented data types include:

- Social Security numbers — Social Security numbers; fields varied by individual and organization. [1](#source-1)
- Clinical information — Doctors, diagnoses, medicines, test results, images, care, and treatment; fields varied by individual and organization. [1](#source-1)
- Names — Patient names; fields varied by individual and organization. [1](#source-1)
- Patient account numbers — Medical record numbers; fields varied by individual and organization. [1](#source-1)

A cited record reports 2,658,388 individuals (Texas residents reported in BR-0005159; a subset of the overall count and not additive; as of 2026-07-07). [1](#source-1) [2](#source-2)

A cited record reports 18,565,730 individuals (Overall individuals affected as reported in Texas Attorney General report BR-0005159; regulator-reported and not independently verified; as of 2026-07-07). [1](#source-1) [2](#source-2)

Munson Healthcare said an unauthorized third party gained access to and obtained personal health information maintained on legacy Cerner systems. [1](#source-1)

## Timeline

### January 22, 2025 — Activity began

Earliest date in the regulator-reported activity range and the date Munson said Cerner's investigation identified as at least the start of access. [1](#source-1)

### February 20, 2025 — Discovery

Discovery date reported in Texas Attorney General report BR-0005159. [2](#source-2)

### April 1, 2025 — Documented activity ended

End of the activity range reported in Texas Attorney General report BR-0005159. [2](#source-2)

### July 25, 2025 — Public disclosure

Publication date of the California Attorney General's Cerner sample incident-notification page. [3](#source-3)

### July 7, 2026 — Public disclosure

Publication date of Texas Attorney General report BR-0005159, which carried materially larger affected counts. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Munson Healthcare and Cerner offered affected patients 24 months of Experian credit monitoring and identity-restoration services. Munson Healthcare said Cerner secured the system and engaged law enforcement and cybersecurity specialists. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/cerner-legacy-systems-data-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Cerner Incident

official · Munson Healthcare

<https://www.munsonhealthcare.org/about-the-system/cerner-incident>

<a id="source-2"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-3"></a>

### Submitted Breach Notification Sample — Cerner Corporation

regulatory · California Department of Justice, Office of the Attorney General · Jul 25, 2025

<https://oag.ca.gov/ecrime/databreach/reports/sb24-606163>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Individual Count · 100% confidence · current**  
   Cerner-hosted patient-data exposure: 2,658,388 individual
2. **Resulted In · 100% confidence · current**  
   2025 Cerner legacy-systems intrusion: Munson Healthcare said an unauthorized third party gained access to and obtained personal health information maintained on legacy Cerner systems.
3. **Exposed Data Category · 100% confidence · current**  
   Cerner-hosted patient-data exposure: Social Security numbers
4. **Affected Organization · 100% confidence · current**  
   2025 Cerner legacy-systems intrusion: Cerner Corporation
5. **Affected Organization · 100% confidence · current**  
   2025 Cerner legacy-systems intrusion: Munson Healthcare
6. **Affected Individual Count · 100% confidence · current**  
   Cerner-hosted patient-data exposure: 18,565,730 individual
7. **Ended At · 100% confidence · current**  
   2025 Cerner legacy-systems intrusion: 2025-04-01
8. **Discovered At · 100% confidence · current**  
   2025 Cerner legacy-systems intrusion: 2025-02-20
9. **Resulted In · 100% confidence · current**  
   2025 Cerner legacy-systems intrusion: Cerner-hosted patient-data exposure
10. **Affected Organization · 100% confidence · current**  
   Cerner-hosted patient-data exposure: Munson Healthcare
11. **Exposed Data Category · 100% confidence · current**  
   Cerner-hosted patient-data exposure: Clinical information
12. **Exposed Data Category · 100% confidence · current**  
   Cerner-hosted patient-data exposure: Names
13. **Resulted In · 100% confidence · current**  
   Cerner breach notifications and regulator updates: Munson Healthcare and Cerner offered affected patients 24 months of Experian credit monitoring and identity-restoration services.
14. **Disclosed At · 100% confidence · current**  
   Cerner breach notifications and regulator updates: 2025-07-25
15. **Began At · 100% confidence · current**  
   2025 Cerner legacy-systems intrusion: 2025-01-22
16. **Disclosed At · 100% confidence · current**  
   Cerner breach notifications and regulator updates: 2026-07-07
17. **Resulted In · 100% confidence · current**  
   2025 Cerner legacy-systems intrusion: Cerner breach notifications and regulator updates
18. **Exposed Data Category · 100% confidence · current**  
   Cerner-hosted patient-data exposure: Patient account numbers
19. **Resulted In · 100% confidence · current**  
   2025 Cerner legacy-systems intrusion: Munson Healthcare said Cerner secured the system and engaged law enforcement and cybersecurity specialists.
20. **Processor For · 100% confidence · current**  
   Cerner Corporation: Munson Healthcare

</details>
