Munson Healthcare·Healthcare·
Patient personal data was compromised.
The Michigan Attorney General described a 2025 Cerner-linked incident compromising Munson patient information. The exact technical root cause is not established in the attached record.
Report freshness and timeline
- First publicly reported
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Regulator confirmed
- Mechanism
- Entry path: Third-party access
- Consequence
- Confirmed: Patient personal data was compromised.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Munson Healthcare
- Industry
- Healthcare
- Disclosed
- Entry path
- Third-party access
- Third party
- Cerner
- Affected asset
- Legacy Cerner systems containing Munson patient health information
- Product / vendor
- Electronic health record vendor
- Country
- US
- Data involved
- Health Data · Personal data
- Documented impact
- Data exposure
- Attached evidence
- 4 independent domains · 4 sources
2)Evidence-backed incident path
- 01
Entry path
Initial access involved third-party access.
ConfidenceSecondaryExact excerpt
E1“unauthorized access through a third-party electronic health record vendor, Cerner”
michigan.gov · Jan 23 - 02
Third party
Cerner
ConfidenceSecondaryExact excerpt
E2“third-party electronic health record vendor, Cerner”
michigan.gov · Jan 23 - 03
Affected product
Electronic health record vendor
ConfidenceSecondaryExact excerpt
E3“third-party electronic health record vendor, Cerner”
michigan.gov · Jan 23 - 04
Reached
Legacy Cerner systems containing Munson patient health information
ConfidenceSecondaryExact excerpt
E4“personal health information on legacy Cerner systems that Munson Healthcare uses”
9and10news.com · Date not established - 05
Observed
Patient personal data was compromised.
ConfidenceConfirmedExact excerpt
E5“The incident compromised personal data”
michigan.gov · Jan 23
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Not publicly established
No qualifying public evidence in the attached record.
- The exact technical root cause
- The initial access mechanism is not established
- That a Defence review would have prevented this incident
4)Relevance to your product
Third-party access can inherit more reach than the product team intended.
This pattern applies when…
- Products that use external electronic health-record vendors.
- Teams that review vendor access to patient information.
Diagnostic questions
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
This incident does not establish your product's risk.
5)Sector context — Healthcare
- 1 incident threads
- 1 incident threads
- 0 incident threads
- 1 incident threads
- 24 incident threads
- 18 incident threads
- 32 incident threads
- 26 incident threads
- 27 incident threads
- 74 incident threads
- 61 incident threads
- 28 incident threads
- Same incident family
- 78 Data breach / intrusion
- Confirmed share
- 60% 177 confirmed · 116 reported
- Display family
- Data breach Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Healthcare in Radar →6)Defence control mapping
What Defence can test
Third-party integration review
- Can an integration reach production secrets or customer data?
- Are scopes narrower than the vendor's full workspace access?
- Can tokens be isolated and revoked without breaking the product?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
7)Public evidence ledger
4 attached sources across 4 independent domains. At least one primary source is attached.
- E1, E2, E3, E5michigan.govAG Nessel Reissues Consumer Alert on Data Breaches Following Cyber Incident Compromising Information of Northern Michigan Healthcare PatientsRegulator record · Jan 23 · PrimaryRegulator recordPrimary
Exact excerpt
“patient names, Social Security numbers”
- E49and10news.comMunson Healthcare confirms data breach involving patient informationEstablished press · Date not established · CitedEstablished pressCited
Exact excerpt
“gained access to and obtained data maintained by electronic health record vendor Cerner”
Does this integration boundary exist in your product?
A bounded review can test the authorized web/API path without assuming this incident predicts your risk.