Skip to content
News

Oracle Health Breach Exposes Data of Nearly 20M People

Oracle Health Breach Exposes Data of Nearly 20M People
Oracle Health breach exposed personal data of nearly 20 million people, including Social Security numbers, addresses and medical records.

Oracle Health has suffered a cyberattack that exposed the personal data of almost 20 million people, according to a report from the Texas attorney general’s office. The breach affected multiple healthcare facilities across several states.

The information obtained by the attacker included Social Security numbers, addresses and medical records, Oracle disclosed to investigators. The cybersecurity breach took place after 22 January 2025, and Oracle notified some customers about it in March of that year.

Oracle Health is a division of Oracle, which acquired the healthcare technology company Cerner for roughly £22.4 billion in June 2022. Oracle told its customers that attackers had targeted older Cerner servers before the data stored on them could be migrated to Oracle’s cloud storage service.

The hacker compromised customer credentials and used them to access two Cerner servers, then copied patient data from those systems. Neither Oracle nor the Texas attorney general specified which hospitals, clinics or other healthcare providers were affected by the data theft.

Who is affected by the Oracle Health breach

Oracle’s healthcare customers include hospitals and clinics in Texas and other states, as well as the Department of Defense and the Department of Veterans Affairs. Of the nearly 20 million people affected, 3 million were Texans.

Christus Health, a nonprofit healthcare system in Texas, and Tri-City Medical Center in California, both affected by the breach, said stolen patient data could include names, Social Security numbers, doctors, diagnoses, medicines and test results. Christus said that patients whose data was compromised would receive letters about the incident and would also be offered a complimentary two-year membership to credit monitoring and identity protection services.

At least 29 hospital and health systems have said they were affected by the breach. The incident illustrates how older infrastructure can remain a material source of third-party risk during cloud migration. Even though Oracle says its cloud infrastructure was unaffected, data held on two legacy servers was sufficient to expose information potentially belonging to millions of patients.

What to do if your data was stolen

Stolen data can be used to make scam attempts far more convincing, particularly if criminals know your name, address or healthcare details. If someone contacts you claiming to be from an insurer or a medical provider and asks for sensitive information or demands payment, security experts advise hanging up and calling your provider back at a number you know belongs to them, such as the one printed on the back of an insurance card.

People whose data was taken in the Oracle breach should establish what information was compromised and make use of any identity or credit monitoring being offered. Of the almost 20 million individuals affected, 3 million were residents of Texas.

Source
Image: cnet.com

The UK tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your UK list is ready.

Shop on Amazon UK — Discover deals Shop on Amazon UK — Discover deals