Cerner Corporation, now operating as Oracle Health, identified unauthorized access to its legacy Cerner systems as early as January 22, 2025. This breach continued to expand its impact and notification efforts into 2026. The incident is a vendor breach, meaning the issue originated with Cerner's systems, not the individual hospitals that utilize its services.
The breach affected at least 62.2 million individuals globally, making it one of the largest healthcare data breaches on record. Exposed data types include names, Social Security Numbers (SSNs), and Protected Health Information (PHI) such as medical record numbers, doctor information, diagnoses, medicines, test results, images, and care and treatment details. Financial data was not explicitly cited as compromised, but credit monitoring services are being offered to affected individuals. The breach led to notifications for patients of various healthcare providers, including Cabell Huntington Hospital and Baptist Health.
Data breach details can continue to emerge and change over time. Notification efforts to affected individuals may also be delayed.