Cerner Corporation
ent_019e0cf13acfbf79b64dbc130fdd0294
Disclosures
14
State AG · HHS OCR · 10 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
18,565,730
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Cerner Corporation
- Normalized
- cerner— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300L4UJ40IEVVI304
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- cerner.com
- Corporate parent
- ORACLE CORPORATION— per GLEIF relationship records
Disclosure history (14)newest first
- Texas State AGas victim2026-07-07
Cerner Corporation based in Kansas City, Missouri, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-02-20 and reported on 2026-07-07. 2,658,388 Texas residents were affected. 18,565,730 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information. Consumers were notified via U.S. Mail.
- Oregon State AGas victim2026-07-06
Cerner Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2026-07-06. The breach occurred during 1/22/2025 - 4/1/2025. The breach was discovered on 2/20/2025. 8,329 individuals were affected. Notice was sent on 6/22/2026.
- New Hampshire State AGas victim2026-06-22
Cerner Corporation submitted a supplemental breach notification to the New Hampshire Attorney General on June 22, 2026, updating the count of affected individuals to 60,247 NH residents. The incident involved unauthorized access to legacy Cerner systems starting January 22, 2025, discovered on March 7, 2025. Affected data included names, SSNs, and PHI. Notification letters were mailed starting July 25, 2025, offering 24 months of credit monitoring.
- Illinois State AGas victim2026-06-01
CERNER CORPORATION filed a data-breach notice with the Illinois Attorney General in June 2026 (case 26-06-1283). The register records the breach as discovered on February 20, 2025. Personal information types reported: medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- New Hampshire State AGas victim2025-12-19
Cerner Corporation notified the New Hampshire Attorney General of a security incident involving unauthorized access to PHI on legacy systems. The breach affected approximately 58,823 NH residents, exposing names, SSNs, and medical records. Access occurred as early as Jan 22, 2025; discovered Feb 20, 2025. Notifications began June 13, 2025. Law enforcement requested notification delays. Cerner engaged forensic specialists, reset credentials, and implemented network isolation. Affected individuals received credit monitoring and identity restoration services.
- Illinois State AGas victim2025-08-01
CERNER CORPORATION filed a data-breach notice with the Illinois Attorney General in August 2025 (case 25-08-346). The register records the breach as discovered on February 20, 2025. Personal information types reported: biometric data, drivers license, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Texas State AGas victim2025-07-28
Cerner Corporation based in Kansas City, Missouri, a healthcare – medical provider entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-02-20 and reported on 2025-07-28. 4,082 Texas residents were affected. 1,970,332 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information. Consumers were notified via U.S. Mail.
- California State AGas victim2025-07-25
Unauthorized third party gained access to legacy Cerner EHR systems beginning at least January 22, 2025, obtaining patient personal information including names, Social Security numbers, medical record numbers, diagnoses, medications, and test results. A healthcare provider (the reporting entity's client) was notified on March 7, 2025. Federal law enforcement requested a delay in patient notification pending investigation. Notices were sent July 25, 2025.
- Nebraska State AGas victim2025-07-25
Cerner Corporation, an EHR vendor, disclosed a data breach affecting patient information. Unauthorized access occurred on or around January 22, 2025, discovered by Cerner on March 7, 2025. Affected data included names, SSNs, and PHI. Federal law enforcement requested a notification delay. Cerner engaged forensic specialists and law enforcement, offering 24 months of credit monitoring to affected individuals. Notifications were sent in July 2025.
- Oregon State AGas victim2025-07-25
Cerner Corporation reported a data breach to the Oregon Attorney General. The breach was reported on 2025-07-25. The breach occurred during 1/22/2025 - 4/1/2025. The breach was discovered on 2/20/2025. 1,970,332 individuals were affected. Notice was sent on 7/25/2025.
- Massachusetts State AGas victim2025-07-25
Cerner Corporation reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-07-25. 15,059 Massachusetts residents were affected.
- Washington State AGas victim2025-07-25
Cerner Corporation, an EHR vendor, experienced unauthorized access to legacy systems starting Jan 22, 2025. The reporting entity, Anytown Health System, learned of the breach on March 7, 2025. Federal law enforcement requested a delay in notification. Data exposed included names, SSNs, and PHI. 802 Washington residents affected. Notification sent July 25, 2025.
- South Carolina State AGas victim2025-07-25
Cerner Corporation reported an unauthorized third-party access to legacy EHR systems starting Jan 22, 2025, discovered March 7, 2025. Data included names, SSNs, and PHI. Federal law enforcement delayed notification. Cerner engaged forensic specialists and offered 24 months of credit monitoring.
- MISSOURIHHS OCRas victim2025-06-17
Cerner Corporation (MO), a Business Associate now operating as part of Oracle Corporation following a 2022 acquisition, reported to HHS OCR on 2025-06-17 a Hacking/IT Incident affecting 501 individuals. Breached information was located on a Network Server. The investigation has since closed as Cerner is no longer a covered entity. PHI of 501 individuals was compromised.