LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Cerner Corporation Data Breach Notice (Oregon Attorney General)

HIGH severityConfirmedHow we verify

Cerner Corporation Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·July 25, 2025
Cerner Corporation Data Breach Notice (Oregon Attorney General)

Occurred January 22, 2025 · publicly disclosed July 25, 2025. Approximately 1970332 people affected.

HIGH
Severity
1970332
People affected
1
Data types exposed
July 25, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Cerner Corporation disclosed a data breach on July 25, 2025, affecting 1,970,332 individuals. The breach occurred on January 22, 2025, and exposed personal information; affected individuals should review the notice and take steps to protect their data.

Severity & verification
HIGH severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
1970332 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

When a large health-technology firm reports that personal information belonging to nearly two million people may have been involved in a security incident, the practical question for those people is straightforward: what was taken, and what should they do next. Cerner Corporation notified Oregon residents of a data breach in a filing with the Oregon Department of Justice dated July 25, 2025. That filing places the incident itself on January 22, 2025, and states that 1,970,332 people were affected. The notice describes the exposed material only as personal information. Public detail beyond those figures and dates remains limited, so anyone who has used Cerner-related systems or whose records may sit in Cerner-managed environments has reason to treat the notice as a prompt for careful monitoring rather than as a full account of what occurred.

This article sets out what the official notice establishes, how incidents of this general type typically unfold, why a breach at an organisation like Cerner carries weight, and the concrete steps people can take if they believe they may be among those affected.

What happened

According to the breach notice filed with the Oregon Attorney General’s office and reported on July 25, 2025, Cerner Corporation experienced a data incident on January 22, 2025. The company informed Oregon residents through that filing. The notice states that 1,970,332 individuals were affected and that the data involved is characterised as personal information. No further breakdown of the incident’s technical method, the systems involved, the duration of unauthorised access, or the precise categories of personal information appears in the disclosed summary. Timing between the January incident date and the July reporting date is a matter of public record in the filing; the reasons for that interval are not explained in the available notice. No threat actor is named or attributed in the disclosure.

How a breach like this happens

Incidents that lead to notices of this kind commonly begin with one of a small set of entry points. Stolen or guessed credentials, phishing that tricks an employee into handing over access, unpatched software flaws, misconfigured cloud storage, or compromised third-party vendors can all give an outsider a foothold. Once inside, the attacker may move laterally, locate databases or file shares that hold personal records, and copy data for later use or sale. In healthcare-related environments the same pattern appears frequently because clinical and administrative systems must exchange large volumes of identifying information and because many organisations rely on complex networks of partners. Detection often lags the initial intrusion; organisations may discover unusual outbound traffic, ransom notes, or alerts from monitoring tools weeks or months later. The Cerner notice does not state which of these pathways applied, so the description above is general background only, not a reconstruction of this specific event.

Cerner Corporation and its sector

Cerner Corporation is a major supplier of electronic health-record and health-information systems used by hospitals, clinics, and other care providers. Companies in this sector routinely process and store demographic details, contact information, insurance identifiers, clinical notes, and related administrative data so that care can be coordinated across facilities. Because those systems sit at the centre of patient administration and billing, a security incident affecting them can reach large numbers of individuals whose records were created or maintained in the course of ordinary medical care. The scale reported in the Oregon filing—nearly two million people—illustrates how concentrated such holdings can become. A breach notice from a firm of this type therefore carries consequences both for the people whose data may have been copied and for the healthcare organisations that rely on the same platforms.

What was likely exposed

The Oregon filing names the exposed material only as “personal information.” It does not list Social Security numbers, medical record numbers, diagnoses, financial account details, or any other specific field. Organisations that operate electronic health-record platforms typically hold names, addresses, dates of birth, contact details, insurance information, and clinical or billing identifiers. Whether any or all of those elements were involved in the January 22, 2025 incident is unconfirmed in the public notice. Readers should therefore treat the exact contents as undisclosed rather than assume any particular data element was or was not taken.

What's at stake

For affected individuals the primary risks are identity theft, targeted phishing, and the quiet reuse of personal details in fraudulent applications for credit, benefits, or medical services. Even limited demographic data can help an attacker craft convincing messages or open new accounts. For Cerner and the healthcare providers that use its systems, the stakes include regulatory scrutiny, contractual obligations to notify patients, potential civil claims, and the operational cost of investigation and remediation. Trust in shared clinical platforms can also erode when large-scale notices appear, even when the technical cause remains undisclosed. None of these outcomes is automatic; they depend on what was actually copied and how it is later misused. The notice itself does not quantify financial loss or confirm downstream fraud.

What to do if you're exposed

If you believe your information may have been involved, practical first steps are limited but useful:

Public detail on this incident remains confined to the dates, the affected-person count, and the broad label “personal information” contained in the Oregon filing. Further clarity, if it becomes available, will come from additional official notices rather than from speculation. Staying attentive to your own accounts and documents is the most direct response available while that clarity is pending.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyCerner Corporation security record
28/100
DoxxScan™ · High doxx risk
D- 44Very poor record

4 reported incidents on record.

See Cerner Corporation’s full breach history →
RelatedMore incidents at Cerner Corporation

More recent breaches

Decisely Insurance Services Data Breach Notice (Oregon Attorney General)December 30, 2025Apro, LLC d/ Data Breach Notice (Oregon Attorney General)December 29, 2025Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)December 29, 2025CareOregon Data Breach Notice (Oregon Attorney General)December 26, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Cerner Corporation Data Breach Notice (Oregon Attorney General) →

Source: Oregon Department of Justice breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram