Cerner Corporation
bd_28ee1e6c3dffc490 · schema v1 · pii pii-v1
Full breach record for Cerner Corporation →4 incidents on fileUnauthorized third party gained access to legacy Cerner EHR systems beginning at least January 22, 2025, obtaining patient personal information including names, Social Security numbers, medical record numbers, diagnoses, medications, and test results. A healthcare provider (the reporting entity's client) was notified on March 7, 2025. Federal law enforcement requested a delay in patient notification pending investigation. Notices were sent July 25, 2025.
J jump to incidentP pin to compareR raw source
Incident timeline
Jan 22, 2025
Begins
Jul 25, 2025
Filed
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Nebraska State AGbd_3a23d77e3f28adfc2025-07-25Verified
- Oregon State AGbd_84ee1229a46c91d32025-07-25Verified
- Massachusetts State AGbd_9d89cbf05f39075c2025-07-25Verified
- Washington State AGbd_d595530ba42639ae2025-07-25Verified
Show 3 more filings ↓Show fewer ↑up to 7d gap
- South Carolina State AGbd_eb522228bcaccfaa2025-07-25Verified
- Texas State AGbd_80ec506162e7d5792025-07-28 · +3dVerified
- Illinois State AGbd_f238b85559dc3dac2025-08-01 · +7dVerified
Filing propagation · 8 filings · 8 states
View merged incident ↗Pattern: first filing Jul 25 (NE), last Aug 1 (IL) — a 7-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.