Skip to main content
Back to overview
High

Union Health System Affected by Oracle Health/Cerner Data Breach

Union Health System, an integrated health system in Indiana, was affected by a security incident at its third-party vendor, Oracle Health/Cerner.

Key points

  • Union Health verified claims of patient data possession on February 24, 2025.
  • Data originated from Oracle Health/Cerner's data migration environment.
  • Oracle Health detected unauthorized access on February 20, 2025, with initial access after January 22, 2025.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

Published
Feb 24, 2025
Updated
Jun 26, 2026
Confidence
High
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Hacking activity

Watch internet-facing systems, credential abuse and exploit activity.

  • Source type: supplier or third-party involvement

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

UnionhealthData DisclosureOracle HealthIndianaCerner. On FebruaryUnion HealthCerner

Quick context

Questions about this signal

What happened in this signal?

Union Health System, an integrated health system in Indiana, was affected by a security incident at its third-party vendor, Oracle Health/Cerner. On February 24, 2025, Union Health verified claims from an unknown party possessing patient data, identifying the information as likely originating from Oracle Health/Cerner's data migration environment. Oracle Health had detected unauthorized access to legacy Cerner servers on February 20, 2025, with initial access occurring after January 22, 2025. The compromised data for 262,831 individuals included names, Social Security numbers, dates of birth, driver's license numbers, treating physicians, dates of service, medication information, health insurance information, and diagnostic/treatment details. Union Health clarified that its internal systems were not compromised and offered credit monitoring services.

When was this signal reported?

Shadow Tier lists Feb 24, 2025 as the signal date.

Which organization is connected to this signal?

Unionhealth is the organization connected to this public signal.

Explore Unionhealth
Which sector context is relevant?

This signal is connected to hospital and health-system cyber incidents.

Explore hospital and health-system cyber incidents