The cybersecurity breach impacting Oracle Health has resulted in the exposure of personal and medical information for nearly 20 million individuals. This incident involves legacy Cerner systems, which were compromised in early 2025, according to a report cited by Bloomberg from the Texas attorney general.
Details of the Cyberattack
The number of affected individuals is significantly higher than initial estimates, which were based on preliminary filings and notifications to patients. Oracle has yet to publicly address the total number of those impacted and declined a request for comment from Bloomberg.
Cerner, a key electronic health record (EHR) provider, was integrated into Oracle in June 2022 following a substantial acquisition valued at approximately $28.3 billion. Subsequently, the entity operates under the Oracle Health banner.
Oracle’s Response and Investigation
In March 2025, Oracle began informing healthcare clients about the breach. The notification highlighted that unauthorized access to Cerner data on a legacy server was detected around February 20, 2025. The breach occurred as the data had not yet transitioned to Oracle Cloud infrastructure.
Oracle’s investigation revealed that the breach involved stolen customer credentials, and the unauthorized access likely started after January 22, 2025. The attacker is believed to have transferred data to an external server.
Impact and Implications
Reports from BleepingComputer indicated that the threat actor, identified as ‘Andrew’, demanded a significant cryptocurrency ransom to prevent the data from being leaked or sold. The actor did not associate with any known ransomware groups.
The breach affected a significant number of Texans, with the Texas attorney general’s portal listing nearly 3 million affected individuals. Additional notifications in South Carolina and Washington reported around 283,000 and 69,000 affected residents respectively. Oregon filings indicate the breach spanned from January 22 to April 1, 2025, with the discovery date marked as February 20, 2025.
In a sample notification to California regulators, Cerner detailed that compromised data could include names, Social Security numbers, and various medical records, including patient diagnoses and treatments.
If confirmed, this incident ranks among the largest healthcare data breaches in U.S. history, surpassed only by a few cases like the 2024 Change Healthcare attack affecting over 192 million people.
