HackingHealthcareTechnologyHealthcareCapture Stored DataData ExfiltratedCustomer Data InvolvedDelayed DiscoveryDOJ-Delayed FilingSupply Chain (3P Vendor)PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICMediumContained
Cerner Corporation
bd_28ee1e6c3dffc490 · schema v1 · pii pii-v1
Full breach record for Cerner Corporation →Unauthorized third party gained access to legacy Cerner EHR systems beginning at least January 22, 2025, obtaining patient personal information including names, Social Security numbers, medical record numbers, diagnoses, medications, and test results. A healthcare provider (the reporting entity's client) was notified on March 7, 2025. Federal law enforcement requested a delay in patient notification pending investigation. Notices were sent July 25, 2025.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_84ee1229a46c91d3Oregon State AGfiled 2025-07-25Verified
- bd_d595530ba42639aeWashington State AGfiled 2025-07-25Verified
- bd_eb522228bcaccfaaSouth Carolina State AGfiled 2025-07-25Verified
- bd_80ec506162e7d579Texas State AGfiled 2025-07-28(3d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-606163
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 25, 2025
- Raw hash
- 69a1b6fcdfe6b991eb3ef2650b5f65033ef178eb2bf294fb6ca9a21f7862215c
Reporting entity
- Name
- Cerner Corporationnorm: cerner
- Domain
- cerner.com
Victim entity
- Name
- Cerner Corporationnorm: cerner
- Domain
- cerner.com
- Industry
- HealthcarellmTechnologyllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Jul 25, 2025
- Affected individuals
- Not disclosed
- Data types
- PIIPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated CollectionT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Federal law enforcement asked to delay patient notification as they continued their investigation
- Third party
- via Cerner Corporation
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.