Oracle Health Cerner breach reportedly nears 20 million people

Oracle Health Cerner breach reportedly nears 20 million people

The Oracle Health data breach affecting legacy Cerner systems may have exposed the personal and medical information of nearly 20 million people, according to SecurityWeek, which cites a Bloomberg report based on a Texas attorney general filing. The figure has not been confirmed by Oracle, which has made no public statement on the number of people affected and declined to comment to Bloomberg.

If accurate, the count is far higher than earlier filings and patient notifications suggested. No CVE is involved; the intrusion reportedly used stolen customer credentials.

What we know about the Oracle Health data breach

  • Oracle began alerting healthcare customers in March 2025. Its notice said it became aware of unauthorized access to Cerner data around February 20, 2025, on an old legacy server that had not yet been migrated to the Oracle Cloud.
  • Oracle told customers the evidence suggested the attacker used stolen customer credentials to access the server some time after January 22, 2025, and copied data to a remote server.
  • Filings with Oregon regulators give January 22 through April 1, 2025 as the breach dates and February 20, 2025 as the discovery date.
  • Cerner, an electronic health record (EHR) vendor, became part of Oracle in June 2022 and now operates as Oracle Health.

Who is affected and what data was involved

Cerner’s entry on the Texas attorney general’s breach portal, published on October 2, lists 2,992,244 affected Texans. Notifications filed in South Carolina and Washington list roughly 283,000 and 69,000 residents respectively.

A sample notification letter filed with California regulators says the information may have included:

  • Names and Social Security numbers
  • Information in patient medical records, such as medical record numbers, doctors, diagnoses, medicines, test results, images, care and treatment

What has not been confirmed

  • The total count. The nearly 20 million figure comes from Bloomberg’s reporting on the Texas filing. Oracle has not confirmed it, and SecurityWeek frames it as conditional (“If confirmed”).
  • The attacker. Sources told BleepingComputer at the time that extortion attempts against affected hospitals came from an individual threat actor known as ‘Andrew’, who had not claimed links to an established ransomware or extortion gang. This is a source claim, not an official attribution.
  • Extortion details. Reportedly the actor demanded millions of dollars in cryptocurrency and set up public websites about the breach to pressure victims. Whether any data was leaked or sold is not disclosed in the source.

Why this matters

Analysis, not new facts. If the figure holds, this would be one of the largest healthcare data breaches on record in the US, according to SecurityWeek. Only a handful of incidents were bigger, including the 2024 ransomware attack on Change Healthcare, which affected 192.7 million people.

Medical records combined with Social Security numbers are hard to change and valuable for identity theft, fraud and targeted phishing. The reported entry point, stolen customer credentials on an unmigrated legacy server, is a pattern worth checking for in your own estate: forgotten systems that sit outside normal patching, MFA and monitoring.

What to do

  1. If you received a notification letter, follow the instructions in it and consider a credit freeze and fraud alerts, since Social Security numbers were involved.
  2. Watch for follow-on scams. Expect phishing or phone calls that reference real medical details; do not share information with unsolicited callers.
  3. Healthcare organizations that used Cerner, check your notices from Oracle, confirm whether your patients are included in state filings, and review your own regulatory notification duties.
  4. Rotate and protect credentials for any vendor-connected accounts, enforce MFA, and review vendor access logs for the January to April 2025 window.
  5. Inventory legacy and unmigrated systems holding sensitive data, and hunt for logins from unfamiliar locations followed by large outbound transfers to external servers.

Sources

Spotted an error or outdated detail? Email contact@cyberstrikenews.com with the article link. We correct and note every change. Read our Editorial Policy.

Similar Posts