Legacy Cerner Breach Spreads Across…Legacy Cerner Breach Spreads Across HospitalsCoverage from Paubox, DistilINFO, and others
00/00/0000
DailyWeekly
An unauthorized third party accessed data held on legacy Cerner systems beginning in January 2025, prompting hospitals across the United States to notify potentially affected patients.
The exposed information may include names, Social Security numbers, medical record details, diagnoses, treatments, test results and images, while hospitals generally state that their own systems were not compromised. The incident is unfolding through staggered disclosures and patient notifications, raising questions about vendor responsibility, notification timing and protection of historical health records.
Looking Back
456 Day Timeline
Articles published over time. Hover any bar for the period and its article count.
May '25
Aug '25
Oct '25
Jan '26
Mar '26
Jun '26
Aug '26
History
09/09/2026
The reported scope has widened from at least 17 affected health systems to a later account citing 28 hospitals or systems, although the incident’s core facts and implications remain unchanged.
08/24/2026
The story has crystallized into a specific legacy Cerner incident that began in January 2025 and potentially affected at least 17 health systems. Consolidated lawsuits and delayed notifications add legal pressure and sharpen questions about Oracle Health's responsibility for retained patient data.
Huntsville Hospital Health System faces a proposed class action after Oracle Health and Cerner notified unauthorized access to legacy systems beginning January 22, 2025.
7/15/2026 • Data Breaches & Exposure Events • General
Oracle Health faced lawsuits and potential regulatory scrutiny after a 2025 breach affected at least 17 hospitals using legacy Cerner systems and allegedly delayed patient notification.
7/9/2026 • Data Breaches & Exposure Events • General
Huntsville Hospital Health System notified patients in 2025 after Cerner reported unauthorized access to vendor-maintained health record data beginning Jan. 22, 2025.
6/25/2026 • Data Breaches & Exposure Events • General
Huntsville Hospital Health System notified patients in 2025 about a Cerner vendor breach that exposed electronic health record data and delayed notification at law enforcement direction.
6/25/2026 • Data Breaches & Exposure Events • General
Atrium Health Navicent disclosed February 2025 notification of a Cerner security incident with possible access to legacy patient records since Jan. 22, 2025.
5/19/2026 • Data Breaches & Exposure Events • General
Oracle Health confirmed a January 2025 hacking incident of legacy Cerner servers affecting up to 80 US hospitals, prompting patient notifications and CISA security guidance.
12/30/2025 • Data Breaches & Exposure Events • General
U.S. District Judge Beth Phillips consolidated three federal lawsuits in Missouri over unauthorized access to Cerner systems that exposed Huntsville Hospital patient data beginning in January 2025.
8/22/2026 • Regulation, Law & Enforcement • General
Huntsville Hospital Health System patients filed Alabama and Missouri lawsuits in 2026 over a Cerner-linked breach involving personal and medical information.
8/21/2026 • Data Breaches & Exposure Events • General
Huntsville Hospital Health System notified patients after Cerner reported a Jan. 22, 2025 vendor breach revealed patient data, with law-enforcement-directed delay.
6/25/2026 • Data Breaches & Exposure Events • General
The Oncology Institute received May 2026 notification from Kroll and filed an SEC Form 8-K on May 22, 2026 about unauthorized access to patient-data systems via a vendor.
5/26/2026 • Data Breaches & Exposure Events • General
TriZetto Provider Solutions data breach exposes patient records nationwide from November 2024 to October 2, 2025, with notification beginning in December 2025.
2/18/2026 • Data Breaches & Exposure Events • General
Cerner data breach potentially exposed patient data at Jupiter Medical Center in Florida in January 2025, with notification delayed by law enforcement.
1/21/2026 • Data Breaches & Exposure Events • General
Blue Shield of California disclosed a Google Analytics misconfiguration found in February 2025 that exposed member protected health information to Google Ads from 2021 to 2024.
5/30/2026 • Data Breaches & Exposure Events • General
TriZetto Provider Solutions, a Cognizant subsidiary, disclosed a 2024-2025 portal breach in which exposed protected health information and identifiers prompted Tennessee-focused class action filings alleging HIPAA notice delays.
5/14/2026 • Data Breaches & Exposure Events • General
Oracle Health's legacy Cerner breach affected 28 hospitals and health systems in the United States as patient notifications continued during the investigation.
8/27/2026 • Data Breaches & Exposure Events • General
Oracle Health reported an expanded list of 25 hospital and health system victims from a legacy Cerner breach identified across the United States in July.
7/30/2026 • Data Breaches & Exposure Events • General
Becker's Hospital Review / Giles Bruce and Naomi Diaz59
Dozens of U.S. hospitals reported patient data compromise after a January 22, 2025 Oracle Health Cerner breach, as Oracle Health sought delayed notification.
7/14/2026 • Data Breaches & Exposure Events • General
Pennsylvania requires certain organizations to report data breaches to the Attorney General using a form that collects incident details, affected data types, and breach timelines.
7/2/2026 • Regulation, Law & Enforcement • General
A lawsuit filed in Huntsville, Alabama alleges Huntsville Hospital Health System failed to protect patient data during a cyberattack tied to Cerner legacy systems.
7/1/2026 • Data Breaches & Exposure Events • General
Erlanger Western Carolina Hospital announced patient notifications in 2026 after possible disclosure of anesthesia-related protected health information sent to a billing partner.
6/30/2026 • Data Breaches & Exposure Events • General
Omega Systems reports most healthcare practices experienced vendor-linked disruptions, with limited supply-chain monitoring and recovery-plan gaps increasing breach and EHR downtime risk.
6/30/2026 • Cybersecurity Tech (Privacy-Relevant) • General
Omega Systems reported in a healthcare cybersecurity study that 85% of medical practices faced vendor-linked disruptions alongside weak supply-chain monitoring of EHR-related security.
6/30/2026 • Cybersecurity Tech (Privacy-Relevant) • General
Huntsville Hospital Health Systems notified patients in Alabama after Cerner, now part of Oracle Health, reported unauthorized access to legacy health records.
6/26/2026 • Data Breaches & Exposure Events • General
Cerner Corporation reports a data-breach affecting legacy Cerner systems on January 22, 2025, with Jupiter Medical Center in Florida notifying potentially affected patients.
1/21/2026 • Data Breaches & Exposure Events • General
UChicago Medicine Medical Group ended its relationship with Nationwide Recovery Services after a July 2024 vendor breach potentially exposed patients' personal information.
5/29/2025 • Data Breaches & Exposure Events • General
Munson Healthcare notified about 100,000 patients in Michigan after a Cerner legacy systems vendor breach exposed personal health information and Social Security numbers, with letters sent in March 2026.
1/24/2026 • Data Breaches & Exposure Events • General
CareCloud reported a March 16 intrusion that disrupted access to one electronic health record environment in its CareCloud Health division for about eight hours.
3/29/2026 • Data Breaches & Exposure Events • General
KLAS Research and EY reported in 2025 that 74% of healthcare organizations experienced third-party data breaches in 24 months due to weak lifecycle oversight after vendor onboarding.
6/9/2026 • Cybersecurity Tech (Privacy-Relevant) • General