Oracle Health breach tally rises to nearly 20 million
A cyberattack on Oracle Health's legacy Cerner systems early last year compromised the personal and medical information of nearly 20 million people. Bloomberg reported the figure, citing a report from the Texas attorney general.
The new number is much higher than the counts in earlier filings and patient notifications. Oracle has not commented publicly on how many individuals were affected, and it declined to comment to Bloomberg.
Cerner, which sells electronic health record (EHR) software, joined Oracle in June 2022 in a deal that valued the company at roughly $28.3 billion. The business now operates under the Oracle Health name.
Stolen credentials and an unmigrated server
Oracle began notifying healthcare customers in March 2025. The company said it learned "on or around February 20, 2025" of unauthorized access to Cerner data stored "on an old legacy server not yet migrated to the Oracle Cloud."
According to Oracle, the evidence showed that the attacker used stolen customer credentials to get into the server at some point after January 22, 2025. The attacker then copied data to a remote server.
Filings with regulators in Oregon put the breach window at January 22 through April 1, 2025, with February 20, 2025, given as the date of discovery.
A lone extortionist called "Andrew"
At the time, sources told BleepingComputer that the extortion attempts against affected hospitals came from a single threat actor using the name "Andrew". The actor did not claim ties to any known ransomware or extortion group.
The hacker asked for millions of dollars in cryptocurrency in exchange for not leaking or selling the stolen data. To add pressure, the attacker also set up public websites about the breach.
State filings show the scale
Cerner's entry on the Texas attorney general's data breach portal, published on October 2, lists 2,992,244 affected Texans. Breach notifications filed in South Carolina and Washington list about 283,000 and 69,000 affected residents.
A sample letter that Cerner filed with California regulators lists the data involved:
"The personal information involved in this incident may have included your name, Social Security number, and information included within patient medical records, such as medical record numbers, doctors, diagnoses, medicines, test results, images, care and treatment," the letter reads.
If the nearly 20 million figure is confirmed, the incident would rank among the largest healthcare data breaches ever reported in the US. Only a few incidents were bigger. One of them is the 2024 ransomware attack on Change Healthcare, which affected 192.7 million people.
Our Take
The Oracle Health case shows how a breach can look moderate at first and then grow as state-level filings pile up. Each US state has its own notification rules, so the full picture often appears in pieces. Readers whose data may be held by healthcare providers using Cerner systems should not assume the earlier, smaller counts were the final word.
The way in also matters. Stolen credentials and a legacy server waiting for migration are not exotic attack paths. They point to a familiar problem: old systems that stay online during cloud transitions without the same protection as newer ones. Other recent incidents, such as the ShinyHunters breach tied to a missed patch, suggest that basic maintenance gaps keep causing serious damage.
Healthcare data is especially sensitive. Unlike a password, a diagnosis or a medical record cannot be changed after it leaks. Smaller incidents, like the Clover Health and AngMar breaches, add to a steady stream of exposures in the sector.
It is worth watching whether Oracle confirms the total and explains the gap between the figures. Another open question is whether this case shapes the debate around the healthcare cybersecurity bill that is now heading to the House.
