Custom IT Solutions for All Types of Industries

Data Collaboration Services empowers industry-specific transformation through secure, scalable, and intelligent data solutions.

Cloud Solutions

Finance

Financial institutions in New York are not only bound by national regulations like PCI-DSS, SOX, and GDPR, but also face local regulatory demands, such as those set by the NYDFS.
Data Backup & Recovery

Healthcare

Healthcare providers today face the dual challenge of improving patient care while navigating complex technological and regulatory requirements.

The Vendor Held the Records. The Vendor Got Breached.

A massive healthcare data breach tied to Oracle Health has exposed sensitive patient information, including Social Security numbers, diagnoses, medications, and medical images. Aultman Health System says the incident may have affected data across as many as 80 hospitals.

Published

What Happened

The hospital was never hacked. Its records were.

Aultman Health System the parent of Aultman Hospital, Aultman Alliance Community Hospital, and Aultman Orrville Hospital in northeast Ohio has begun notifying patients that their sensitive personal and medical information was exposed in a data breach. The catch: the breach did not happen inside Aultman. It happened at Oracle Health, the company formerly known as Cerner, that provides and hosts Aultman’s electronic health record (EHR) system.

According to disclosures, an unauthorized third party gained access to legacy Cerner data-migration servers older systems still holding patient records using compromised credentials. The intrusion was traced back to activity detected as early as January 22, 2025. Investigators later determined the attacker had copied files containing patient information belonging to Aultman and, as it turned out, to a long list of other health systems that relied on the same vendor.

There was no encryption event at Aultman and no disruption to patient care. This was a quiet data theft from a third party the kind of breach a hospital cannot see on its own network, cannot detect with its own tools, and cannot stop, because the compromised systems belonged to someone else. Yet under federal law, Aultman still owns the obligation to notify every patient whose data was taken.

By the Numbers

The scale of a breach a hospital couldn’t see

80
Hospitals and health systems reportedly caught in the Oracle Health / Cerner breach
Jan 2025
When unauthorized access was first detected
~1 yr
Delay before Aultman patients were notified
3
Aultman hospitals whose legacy patient records were exposed
SSNs + PHI
Data types stolen identity and health records together
$7.42M
Average cost of a U.S. healthcare breach highest of any industry
Key Facts

What was taken

The data at risk in the Aultman / Oracle Health breach

  • Full names, addresses, and dates of birth
  • Social Security numbers the master key for identity theft
  • Medical record numbers and treating physicians
  • Diagnoses, medications, and test results
  • Medical images and details about care and treatment
  • The records lived on legacy Cerner migration servers old data that had never been fully retired
  • Access was gained through compromised credentials, not malware or ransomware
  • Aultman is one of as many as 80 health systems reportedly affected by the same vendor breach

Stolen health data is uniquely dangerous because it cannot be reset. A breached credit card is cancelled in minutes; your Social Security number, birth date, and medical history are permanent. Criminals combine them to open credit lines, file fraudulent tax returns, and commit medical identity theft using a victim’s identity to obtain care or drugs, which corrupts the victim’s own medical record in ways that can take years to unwind.

The Cascade

One vendor, eighty front doors

This is what supply-chain risk looks like in healthcare. Aultman did nothing to invite the intrusion it simply used a mainstream EHR platform, as nearly every hospital in America does. But when that single vendor was compromised, the breach did not stay contained to one hospital. It fanned out to as many as 80 health systems at once, each of which now has to notify its own patients, field its own lawsuits, and answer to its own regulators.

The specific weak point matters, too: the stolen data sat on legacy migration servers leftover systems from an older platform that were still holding live patient records long after they should have been decommissioned. Attackers love forgotten infrastructure. It rarely gets patched, rarely gets monitored, and rarely appears on anyone’s security checklist, yet it often holds the exact same sensitive data as the production systems everyone guards.

The lesson generalizes far beyond hospitals. Every business hands sensitive data to outside vendors a cloud EHR, a billing service, a practice-management platform, a document host. When you do, you inherit their security posture and their forgotten servers, whether you ever see them or not. A medical practice, a law firm, or an accounting office is only as secure as the least-guarded vendor holding its clients’ records.

Legal & Regulatory Fallout

Class actions and a year-long silence

Patients have already filed a class-action lawsuit against Aultman, and multiple plaintiffs’ firms have announced investigations. The central grievance is not just that the data was taken it’s the delay. The complaint alleges patients were not notified until nearly a year after the unauthorized access was known, leaving them exposed to fraud for months without any chance to protect themselves.

That delay is where healthcare breaches turn legally toxic. HIPAA’s Breach Notification Rule generally requires that affected individuals be notified without unreasonable delay and no later than 60 days after discovery. When notification stretches to nearly a year even when law enforcement requests a hold during an active investigation regulators and juries ask hard questions about who knew what, and when. The U.S. Department of Health and Human Services has repeatedly pursued settlements over exactly these failures.

And here is the part every business owner should sit with: the breach happened at the vendor, but the lawsuit names the hospital. Outsourcing where your data lives does not outsource your liability for it. When a third party loses your clients’ records, you keep the notification deadlines, the regulators, and the courtroom.

Action Steps

What your practice should do this week

  1. Map every vendor that touches your patient or client data. Your EHR, billing service, imaging host, backup provider, and cloud storage all hold sensitive records. You can’t protect data you can’t see start with a written inventory of who holds what.
  2. Demand security proof from each vendor in writing. Require a signed Business Associate Agreement, confirmation of MFA and encryption, breach-notification terms with hard deadlines, and evidence of independent security testing. If a vendor can’t produce it, treat that as a finding, not a formality.
  3. Hunt down and retire legacy systems. This breach lived on old migration servers nobody had decommissioned. Identify every retired system, archive, or “temporary” data store still holding records and either fully secure it or destroy the data on it.
  4. Shorten how long you keep data and how fast you’d notify. Set retention rules that purge records you no longer need, and write (and rehearse) a breach-response plan so a real incident triggers notification in days, not months.
  5. Assume credentials will be stolen, and blunt the damage. The attacker used compromised logins. Enforce multi-factor authentication everywhere, kill unused accounts, and monitor for logins to sensitive systems so a stolen password doesn’t become a year-long, invisible breach.
The Bottom Line

Your patients’ trust rides on systems you don’t own.

The Aultman breach is unsettling precisely because the hospital didn’t get anything obviously wrong. It used a leading EHR vendor, ran a normal healthcare operation, and still ended up sending breach letters to its own patients because the company it trusted with those records left them on a forgotten server that someone walked into with a stolen password. The most dangerous gap in your defenses may be one that isn’t on your network at all.

Every practice, firm, and office that hands data to an outside platform should ask the Aultman question now: if our vendor were breached tomorrow, would we even know and how long would our patients wait to find out? The organizations that come through incidents like this intact are the ones that treat vendor risk as their own risk, hunt down the forgotten data before an attacker does, and can prove not just hope that the companies holding their records are protecting them. If you can’t say with confidence where your clients’ records actually live and who is guarding them, that’s the gap to close now before it’s your patients reading the notification letter.

Stay Ahead of Threats

Get weekly insights on the latest vulnerabilities, breach analysis, and defense strategies delivered directly to your inbox.

End-to-end encrypted delivery