Oracle Health Hack Exposes Data of Nearly 20 Million People

A cyberattack against Oracle Health last year exposed the personal data of almost 20 million people, the Texas attorney general’s office said in a report, according to Bloomberg.
The personal information taken by the attacker included Social Security numbers, addresses and medical information, Oracle disclosed to investigators. The cybersecurity breach happened after Jan. 22, 2025, and Oracle alerted some customers about it in March of that year, Bloomberg reported.
Oracle Health is a division of Oracle, which acquired healthcare technology company Cerner for $28.3 billion in June 2022.
More from CNET
Oracle told its customers that attackers had targeted older Cerner servers before the data stored on them could be migrated to Oracle’s cloud storage service, Bloomberg said. The hacker compromised customer credentials and used them to access two Cerner servers and then copied patient data from those servers, according to UK cybersecurity firm CyPro.
Neither Oracle nor the Texas attorney general specified which hospitals, clinics or other healthcare providers were affected by the data theft.
CNET reached out to both the Texas AG’s office and Oracle, but representatives did not immediately respond.
Who’s affected by the Oracle Health breach?
Oracle healthcare customers include hospitals and clinics in Texas and other states, as well as the Department of Defense and the Department of Veterans Affairs. Of the nearly 20 million people affected, 3 million were Texans.
Christus Health, a nonprofit healthcare system in Texas, and Tri-City Medical Center in California — both affected by the breach — said stolen patient data could include names, Social Security numbers, doctors, diagnoses, medicines and test results, Bloomberg reported.
Christus said that patients whose data was compromised would receive letters about the incident and also would be offered a complimentary two-year membership to credit monitoring and identity protection services.
CyPro noted Tuesday that at least 29 hospital and health systems said they had been affected by the breach.
“The incident demonstrates how older infrastructure can remain a material source of third party risk during cloud migration,” CyPro founding partner Rob McBride wrote. “Even though Oracle says its cloud infrastructure was unaffected, data held on two legacy servers was sufficient to expose information potentially belonging to millions of patients.”
KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.