DEFENCE / RADAR

Public snapshot

Munson Healthcare·Healthcare·

Patient personal data was compromised.

The Michigan Attorney General described a 2025 Cerner-linked incident compromising Munson patient information. The exact technical root cause is not established in the attached record.

Report freshness and timeline

First publicly reported
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Regulator confirmed
Mechanism
Entry path: Third-party access
Consequence
Confirmed: Patient personal data was compromised.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Munson Healthcare
Industry
Healthcare
Disclosed
Entry path
Third-party access
Third party
Cerner
Affected asset
Legacy Cerner systems containing Munson patient health information
Product / vendor
Electronic health record vendor
Country
US
Data involved
Health Data · Personal data
Documented impact
Data exposure
Attached evidence
4 independent domains · 4 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved third-party access.

    ConfidenceSecondary
    Exact excerpt

    unauthorized access through a third-party electronic health record vendor, Cerner

    michigan.gov · Jan 23
    E1
  2. 02

    Third party

    Cerner

    ConfidenceSecondary
    Exact excerpt

    third-party electronic health record vendor, Cerner

    michigan.gov · Jan 23
    E2
  3. 03

    Affected product

    Electronic health record vendor

    ConfidenceSecondary
    Exact excerpt

    third-party electronic health record vendor, Cerner

    michigan.gov · Jan 23
    E3
  4. 04

    Reached

    Legacy Cerner systems containing Munson patient health information

    ConfidenceSecondary
    Exact excerpt

    personal health information on legacy Cerner systems that Munson Healthcare uses

    9and10news.com · Date not established
    E4
  5. 05

    Observed

    Patient personal data was compromised.

    ConfidenceConfirmed
    Exact excerpt

    The incident compromised personal data

    michigan.gov · Jan 23
    E5

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The exact technical root cause
  • The initial access mechanism is not established
  • That a Defence review would have prevented this incident

4)Relevance to your product

Third-party access can inherit more reach than the product team intended.

This pattern applies when…

  • Products that use external electronic health-record vendors.
  • Teams that review vendor access to patient information.

Diagnostic questions

  1. Can an integration reach production secrets or customer data?
  2. Are scopes narrower than the vendor's full workspace access?
  3. Can tokens be isolated and revoked without breaking the product?

This incident does not establish your product's risk.

5)Sector context — Healthcare

293 incident threads in the 365-day public record
  1. 1 incident threads
  2. 1 incident threads
  3. 0 incident threads
  4. 1 incident threads
  5. 24 incident threads
  6. 18 incident threads
  7. 32 incident threads
  8. 26 incident threads
  9. 27 incident threads
  10. 74 incident threads
  11. 61 incident threads
  12. 28 incident threads
Same incident family
78
Data breach / intrusion
Confirmed share
60%
177 confirmed · 116 reported
Display family
Data breach
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Healthcare in Radar →

6)Defence control mapping

What Defence can test

Third-party integration review

  • Can an integration reach production secrets or customer data?
  • Are scopes narrower than the vendor's full workspace access?
  • Can tokens be isolated and revoked without breaking the product?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.

7)Public evidence ledger

4 attached sources across 4 independent domains. At least one primary source is attached.

  1. E1, E2, E3, E5
    michigan.govAG Nessel Reissues Consumer Alert on Data Breaches Following Cyber Incident Compromising Information of Northern Michigan Healthcare PatientsRegulator record · Jan 23 · Primary
    Regulator recordPrimary
    Exact excerpt
    patient names, Social Security numbers
  2. E4
    9and10news.comMunson Healthcare confirms data breach involving patient informationEstablished press · Date not established · Cited
    Established pressCited
    Exact excerpt
    gained access to and obtained data maintained by electronic health record vendor Cerner
  3. S3
    freep.comAbout 100K Munson Healthcare patients may be affected by data breachOther public report · Jan 24 · Attached
    Other public reportAttached
  4. S4
    hipaajournal.comMore Than 100K Munson Healthcare Patients Affected by Cerner CyberattackSpecialist reporting · Jan 26 · Attached
    Specialist reportingAttached

Does this integration boundary exist in your product?

A bounded review can test the authorized web/API path without assuming this incident predicts your risk.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →