Trending: On-device modelsSearch
iHeartGeek
iTECH

Oracle Health breach exposed data on nearly 20 million people

A cyberattack on two legacy Cerner servers exposed the personal and medical records of almost 20 million people, Texas investigators have been told, in one of the largest healthcare data thefts on record.

Rows of dark server cabinets lining a data centre aisle, lit by cool cyan panels ahead and a red glow spreading across the floor

What the attack took, and who it hit

A cyberattack against Oracle Health exposed the personal data of almost 20 million people, Texas's attorney general's office has told investigators. The stolen information included Social Security numbers, home addresses and medical details, Oracle disclosed. The intrusion happened after 22 January 2025, and Oracle began alerting some customers in March that year.

Attackers compromised customer credentials, used them to reach two older Cerner servers, and copied patient data from those machines before it could be migrated to Oracle's cloud storage. Oracle Health is the division built on the company's $28.3bn acquisition of healthcare technology firm Cerner in June 2022.

Three million of the affected are in Texas

Oracle Health's customers include hospitals and clinics across the United States, as well as the Department of Defense and the Department of Veterans Affairs. Neither Oracle nor the attorney general has specified which providers were caught up in the theft, but Christus Health, a non-profit system in Texas, and Tri-City Medical Center in California have both confirmed they were affected. Christus Health says patients will receive letters and two years of complimentary credit monitoring and identity protection.

Legacy servers stayed a live risk

At least 29 hospital and health systems have said they were affected. Oracle's position is that its cloud infrastructure was not compromised, which is the point security analysts keep returning to: a migration programme is not a fix while the old estate is still holding patient records and still accepting credentials. Data that has not yet moved is data that has not yet been protected.

Our opinion

Health data is the worst data to lose, because it cannot be reissued. You can replace a bank card in a week; you cannot replace a diagnosis, a prescription list or a psychiatric record that has been copied out of a server and held somewhere else for eighteen months before anyone was told. The uncomfortable detail here is the timing rather than the technique: this was not a clever zero-day, it was stolen credentials opening two machines that should have been retired. Twenty million people are now living with the consequences of a cloud migration that was running late.