BREACH

Oracle Health’s Cerner breach hit nearly 20 million people. HHS still lists it at 501

The 2025 hack of Oracle Health’s legacy Cerner servers compromised personal and medical data on nearly 20 million people, including about 3 million Texans, according to a report from the Texas attorney general that Bloomberg surfaced on Oct 5. Cerner’s entry on the Texas portal, posted Oct 2, lists 2,992,244 affected Texans. Oracle has never published a total and declined to comment. As of Oct 7, the HHS breach portal still showed the incident at a 501-patient placeholder. If the figure holds, it ranks among the largest US healthcare breaches on record.

Oct 8, 2026 · 3 min read

What happened, per Oracle’s own notices. Oracle told customers it became aware on or around Feb 20, 2025 of unauthorized access to Cerner data “on an old legacy server not yet migrated to the Oracle Cloud.” The attacker used compromised customer credentials sometime after Jan 22, 2025 and copied data to a remote server. Oregon filings put the breach window at Jan 22 to Apr 1, 2025. A sample letter filed in California lists names, Social Security numbers, and medical record contents: record numbers, doctors, diagnoses, medicines, test results, images, care and treatment. Hospitals were extorted by an individual actor known as “Andrew,” per BleepingComputer’s sources at the time, with no link to a known ransomware crew.

Why the number took 19 months. Oracle pushed notification down to its hospital customers instead of filing one big federal number, so the count leaked out state by state: about 283,000 in South Carolina, about 69,000 in Washington, then the Texas filing. Dozens of health systems sent their own notices, including ChristianaCare, LifeBridge Health and Mosaic Life Care, which reported nearly 145,300 patients to HHS. Oracle is facing several proposed federal class actions. Oracle bought Cerner in 2022 for about $28.3B.

What we’d do if Oracle Health is your EHR. Ask for the specific list of your facilities’ data that sat on legacy Cerner hosts, and when each one moved to Oracle Cloud. “Not yet migrated” is the attack surface here, and it exists at every vendor mid-migration. Ask how customer credentials to those hosts are issued, whether MFA was enforced, and whether any shared or service accounts still authenticate by password. Then check your own notification exposure: if your patients were in the set and you notified late or not at all, that’s your regulator problem, not Oracle’s. For any vendor holding regulated data, put a per-incident record count and a notification deadline in the contract, because this case shows you may otherwise learn the size of your own breach from a state AG portal.

The buyer read. This is third-party risk with a migration clock attached. When a vendor is consolidating an acquired platform into its own cloud, the old estate is often the least monitored part of it. Make migration status a line item in vendor reviews, not a roadmap slide.

Desk sheet: Oracle Health legacy Cerner servers, access via stolen customer credentials after Jan 22, 2025, discovered about Feb 20, 2025. Nearly 20 million people per the Texas AG report (Bloomberg, Oct 5); Texas portal lists 2,992,244 Texans (posted Oct 2). HHS still at 501 placeholder. Oracle: no public count, declined comment. Ransom paid: Undisclosed.

Sources