{"@context":"https://certreports.com/llms.txt","vendor":{"slug":"cerner","name":"Cerner","domain":"cerner.com","category":"EHR and practice management","one_liner":"Oracle Health, formerly known as Cerner Corporation before it was acquired by Oracle, is an American multinational provider of health","trust_center_url":null,"security_page_url":null,"url":"https://certreports.com/vendors/cerner/security","last_verified_at":"2026-09-17T00:00:00.000Z","claimed":false,"verified_profile":false},"attestations":[{"framework":"pci-dss","framework_name":"PCI DSS","state":"verified_registry","state_label":"Verified","sentence":"Listed in the Visa Global Registry of Service Providers as of 17 Sep 2026.","kind":"attestation","status_text":"Listed on the Visa Global Registry as PCI DSS validated through 2026-10-31","issued_at":"2024-08-19","expires_at":"2026-10-31","period_start":null,"period_end":null,"auditor":"Schellman Compliance, LLC.","impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"visa_grsp","url":"https://certreports.com/vendors/cerner/pci-dss","evidence":[{"source_type":"registry","source_name":"Visa Global Registry of Service Providers","url":"https://www.visa.com/splisting/","fetched_at":"2026-09-17 15:57:23.088866+00","content_hash":"1b61009e57d66a133b575015786508ee41eea68f8012da9acb88385732324beb","wayback_url":null,"quote":"Cerner Corporation: PCI DSS, assessor Schellman Compliance, LLC., valid through 2026-10-31","confidence":1}]},{"framework":"dpf","framework_name":"EU-US Data Privacy Framework","state":"expired","state_label":"Expired","sentence":"Certificate expiry unknown date passed; no renewal found as of 17 Sep 2026.","kind":"listing","status_text":"Inactive","issued_at":null,"expires_at":null,"period_start":null,"period_end":null,"auditor":null,"impact_level":null,"as_of":"2026-09-17","under_review":false,"source":"dpf","url":"https://certreports.com/vendors/cerner/security","evidence":[{"source_type":"registry","source_name":"Data Privacy Framework list","url":"https://www.dataprivacyframework.gov/participant/4434","fetched_at":"2026-09-17 15:48:29.718028+00","content_hash":"0ea63eb613db4d80ec5cf2a6ffbfab483b8e3942bde71834563fa262fe5e94b6","wayback_url":null,"quote":"Cerner Corporation: Inactive","confidence":1}]}],"brief":null,"legal_docs":[],"subprocessors":[],"disclaimer":"CertReports indexes public evidence. A missing framework means no public evidence was found at the last check, not that the vendor is non-compliant. SOC 2 is a report, not a certification; HIPAA has no certification.","generated_at":"2026-09-19T02:21:03.774Z"}