Cybersecurity

Oracle Health Breach May Have Put Data of Approximately 20 Million People at Risk

Data from the Texas Attorney General’s Office indicates that a breach of Oracle Health’s legacy Cerner systems may have affected nearly 20 million people, a figure exceeding estimates that appeared in earlier notifications. The potentially exposed data included personal information and medical records, while Oracle has not publicly confirmed the figure.

2026-10-08
3 min read
6 views
certi.news
Oracle Health Breach May Have Put Data of Approximately 20 Million People at Risk

A cyberattack targeting Oracle Health’s legacy health-record systems may have exposed the personal and medical data of approximately 20 million people, according to Bloomberg, citing a report from the Texas Attorney General’s Office. This figure is significantly higher than the numbers that appeared in previous patient notifications and regulatory filings.

Oracle has not issued a public statement confirming the number of people affected, and declined to comment on the figure when asked by Bloomberg. If the total of nearly 20 million people is confirmed, the incident would become one of the largest healthcare data breaches recorded in the United States.

How Did the Breach Occur?

Oracle informed its customers in March 2025 that there had been unauthorized access to some Cerner data stored on a legacy server that had not yet been migrated to Oracle Cloud. The company said available evidence indicated that the attacker used stolen credentials belonging to one customer to access the server sometime after January 22, 2025, and then copied the data to a remote server.

Regulatory filings in Oregon indicate that the breach period extended from January 22 to April 1, 2025, while the incident was discovered on February 20 of the same year.

What Type of Data May Have Been Affected?

A sample of a notification letter that Cerner submitted to regulators in California shows that the potentially affected information included people’s names and Social Security numbers, as well as data contained in medical records, such as medical record numbers, doctors’ names, diagnoses, medications, test results, images, and care and treatment information.

Notifications published so far reveal significant variation in the scale of the impact among states. The Texas attorney general’s portal listed 2,992,244 affected people, while notifications in South Carolina and Washington indicated approximately 283,000 and 69,000, respectively.

Why Does This Matter?

The significance of the incident lies not only in the potential number of people affected, but also in the nature of the targeted data. Access to medical records combined with identifying information and Social Security numbers may increase the risks of fraud and privacy violations beyond those associated with the exposure of ordinary contact data. The incident also highlights the operational risks that may persist in legacy systems even as organizations transition to newer cloud infrastructures.

Sources said at the time that extortion attempts against the affected hospitals were attributed to an individual threat actor known as “Andrew,” without announcing any connection to a known extortion gang or ransomware group. The attacker demanded millions of dollars in cryptocurrency and created public websites to pressure victims and prevent the data from being published or sold.

Oracle acquired Cerner in June 2022 in a deal valued at approximately $28.3 billion, and the company has operated under the name Oracle Health since then. The larger comparison is the 2024 ransomware attack on Change Healthcare, which affected 192.7 million people according to the figures announced. Oracle Health’s final total remains uncertain until the company or regulators release a comprehensive and verified figure.

News source
c
Author

certi.news

Explore this story

Related topics and entities

In the same category

You may also like

View all news