October 8, 2026

Oracle Health Data Breach Tally Climbs to Nearly 20 Million

The figure is far higher than the counts that surfaced in earlier filings and patient notifications.

Oracle Health Data Breach Tally Climbs to Nearly 20 Million

The personal and medical information of nearly 20 million people was compromised in a cyberattack on Oracle Health’s legacy Cerner systems early last year, Bloomberg reported, citing a report from the Texas attorney general.

The figure is far higher than the counts that surfaced in earlier filings and patient notifications. Oracle has not made a public statement on the number of affected individuals and declined to comment to Bloomberg.

Cerner, an electronic health record (EHR) vendor, became part of Oracle in June 2022, after a deal that valued the company at roughly $28.3 billion. The business now operates as Oracle Health.

Oracle began alerting healthcare customers in March 2025. “We are writing to inform you that, on or around February 20, 2025, we became aware of a cybersecurity event involving unauthorized access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud,” its notice read.

Oracle told customers that the available evidence suggested the attacker had used stolen customer credentials to access the server sometime after January 22, 2025, and had copied data to a remote server.

Sources told BleepingComputer at the time that the extortion attempts against affected hospitals came from an individual threat actor known as ‘Andrew’. The actor had not claimed links to any established ransomware or extortion gang.

To keep the stolen data from being leaked or sold, the hacker demanded millions of dollars in cryptocurrency, and set up public websites about the breach to increase pressure on the victims.

Cerner’s entry on the Texas attorney general’s data breach portal, published on October 2, lists 2,992,244 affected Texans.

Breach notifications filed in South Carolina and Washington list roughly 283,000 and 69,000 affected residents, respectively. Filings with Oregon regulators give January 22 through April 1, 2025, as the dates of the breach, and February 20, 2025, as the discovery date.

A sample notification letter filed by Cerner with California regulators describes the types of data involved.

“The personal information involved in this incident may have included your name, Social Security number, and information included within patient medical records, such as medical record numbers, doctors, diagnoses, medicines, test results, images, care and treatment,” the letter reads.

If confirmed, the nearly 20 million figure would make the incident one of the largest healthcare data breaches on record in the US. Only a handful of reported incidents were bigger, including the 2024 ransomware attack on Change Healthcare, which affected 192.7 million people.

Originally published on SecurityWeek