HackingStolen CredentialsData ExfiltratedDelayed DiscoveryIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHIMediumActive
Cerner Corporation
bd_eb522228bcaccfaa · schema v1 · pii pii-v1
Full breach record for Cerner Corporation →Cerner Corporation reported an unauthorized third-party access to legacy EHR systems starting Jan 22, 2025, discovered March 7, 2025. Data included names, SSNs, and PHI. Federal law enforcement delayed notification. Cerner engaged forensic specialists and offered 24 months of credit monitoring.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_28ee1e6c3dffc490California State AGfiled 2025-07-25Candidate
- bd_84ee1229a46c91d3Oregon State AGfiled 2025-07-25Verified
- bd_d595530ba42639aeWashington State AGfiled 2025-07-25Verified
- bd_80ec506162e7d579Texas State AGfiled 2025-07-28(3d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Security%20Breach%20Notices/2025/20250725%20Notice%20LF%20K.%20Nahra%20to%20SC%20AG%20-%20Consumer%20Notice.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 25, 2025
- Raw hash
- 10f8dee7a07fa7a29edd9fbea39f554cdccffc2f2f9e160feca7f6bdf2496ae3
Reporting entity
- Name
- Cerner Corporationnorm: cerner
- Domain
- cerner.com
Victim entity
- Name
- Cerner Corporationnorm: cerner
- Domain
- cerner.com
Incident
- Discovered
- Mar 7, 2025
- Materiality determined
- —
- Notification sent
- Jul 25, 2025
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICPHI
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- federal law enforcement asked to delay patient notification
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 20 weeks(140 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.