A 2025 cyberattack on Oracle Health compromised personal and medical information belonging to nearly 20 million people, revealing a much larger impact than initially disclosed. The breach affected people across the US, with around 3 million victims reportedly based in Texas. According to the Texas Attorney General , data taken during the incident included Social Security numbers, addresses and medical information.
Oracle Health, formerly known as Cerner, notified some healthcare customers about the incident in March 2025. The company said an unauthorised party had accessed older Cerner servers.
Oracle acquired Cerner in 2022 for about USD 28 billion. The compromised systems contained healthcare data that had not yet been moved to Oracle’s cloud infrastructure.
The company said the intrusion took place sometime after January 22, 2025. However, Oracle did not initially reveal the number of people whose information may have been affected.
The incident shows the security challenges companies can face while moving data from legacy systems to newer cloud environments.
The breach also prompted a federal investigation. The FBI examined the attack and reported attempts by hackers to pressure healthcare companies into paying ransoms, according to Bloomberg's earlier reporting. It remains unclear how the incident affected federal customers. A Veterans Affairs spokesperson said in March 2025 that the department was not affected.
Oracle has declined to comment on the latest disclosure, while the Texas Attorney General's office did not respond to requests for comment. The incident highlights the risks of retaining sensitive healthcare information on older infrastructure. Unlike conventional account data, medical records and Social Security numbers cannot simply be replaced after exposure.
For affected patients, the incident could therefore create long-term privacy and identity-security concerns.
Also Read: du Tech, Rilian Partner to Boost Sovereign AI Cybersecurity in UAE