DisclosureLens
HackingHealthcareTechnologyHealthcareData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIdentity (basic)Government IDHealth (basic)HighActive

Cerner Corporation

bd_15fce9bcc4fb243c · schema v1 · pii pii-v1

Severity

High

Discovered

Feb 20, 2025

Filed

Dec 19, 2025

To disclose

43 weeks

Affected

58,823state residents only

Confidence

65%
Full breach record for Cerner Corporation4 incidents on file

Cerner Corporation notified the New Hampshire Attorney General of a security incident involving unauthorized access to PHI on legacy systems. The breach affected approximately 58,823 NH residents, exposing names, SSNs, and medical records. Access occurred as early as Jan 22, 2025; discovered Feb 20, 2025. Notifications began June 13, 2025. Law enforcement requested notification delays. Cerner engaged forensic specialists, reset credentials, and implemented network isolation. Affected individuals received credit monitoring and identity restoration services.

Incident timeline

undetected · 29 days
discovery → filing · 43 weeks / 302 days

Jan 22, 2025

Begins

Feb 20, 2025

Discovered

Dec 19, 2025

Filed

vs. sector median

+31 wks slower

Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed58,823 affectedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.