Notice of Cerner Data Security Incident
Huntsville Hospital Health System is committed to protecting the confidentiality and security of its patients’ information. Cerner, now part of Oracle Health, a third-party electronic health record (EHR) vendor used by many health care providers nationwide recently notified us that some of our patient information was impacted in a security incident that occurred on Cerner’s systems. For clarity, this incident did not involve access to, nor was it a failure of, Huntsville Hospital Health System.
What Happened?
On August 12, 2025, Cerner (now part of Oracle Health) notified numerous health care clients, including Huntsville Hospital Health System, that an unauthorized third party gained access to and obtained data that was maintained in the electronic health record (EHR) they maintained. For the avoidance of doubt, this incident did not involve the systems maintained by Huntsville Hospital Health Systems. Cerner (now part of Oracle Health) was able to determine through an investigation that at least as early as January 22, 2025, an unauthorized third party gained access to personal health information on their legacy Cerner systems.
The vendor later informed us that law enforcement investigators directed a delay in notifying patients, as well as additional hospital customers, about this incident because it could have impeded their investigation. As a result, we are notifying you as quickly as possible.
What Information Was Involved?
The personal information involved in this incident may have included your name, Social Security number, and information included within patient medical records, such as medical record numbers, doctors, diagnoses, medicines, test results, images, care and treatment.
What Is Being Done?
Cerner began investigating the incident as soon as they learned of it. They engaged with the relevant law enforcement agencies and initiated their critical incident response process to secure the impacted systems. The vendor also began an internal investigation and engaged external cybersecurity specialists to help.
Why Did I Receive a Breach Notification Letter for Someone Who is Deceased?
Privacy regulations require we provide notification when protected health information is affected by certain breaches. These requirements also apply to deceased individuals. Depending on the information available, the notification may be sent to the deceased patient's personal representative or to the patient's last known mailing address. We recognize that receiving this type of letter may be unexpected or upsetting. The notification is intended to inform the appropriate recipient about the incident and the steps being taken in response.
What You Can Do
To help protect your identity Cerner is offering two complimentary services. First, you have access to Experian IdentityWorksSM Credit Plus 3B (for adults) or IdentityWorksM Minor Plus (for minors) which provides credit monitoring for 24 months. Taking advantage of the fraud detection tools, as well as the credit monitoring offering available through Experian IdentityWorksSM requires you to enroll into the service. Second, you have access to Identity Restoration for 24 months from the date of this letter and this does not require any action on your part at this time. The Terms and Conditions for this offer are located at www.ExperianIDWorks.com/restoration. See the appendix included with the notification letter for additional details, including regarding enrollment in IdentityWorksSM.
For More Information
If you have further questions or concerns, or would like an alternative to enrolling online, please call 833-918-1119 toll-free Monday through Friday from 8 a.m. – 8 p.m. Central (excluding major U.S. holidays). Please be prepared to provide your engagement number ENGAGE#.