TECHTALKS
ORACLE HEALTH BREACH EXPOSES NEARLY 20M
A 2025 cyberattack on Oracle’s healthcare unit exposed personal and medical information belonging to nearly 20 million people, according to a disclosure cited by the Texas attorney general.
The compromised data included Social Security numbers, addresses and medical information, with about 3 million Texans among those affected.
Oracle had notified some healthcare customers in March 2025 that attackers accessed older servers tied to Cerner, the electronic health records company it acquired for $28 billion in 2022.
The exposed information varied by patient but could include names, Social Security numbers, doctors, diagnoses, medications, test results and other medical records, according to healthcare organizations affected by the breach.
Oracle’s healthcare customers include hospitals and clinics as well as US federal agencies such as the Department of Defense and Department of Veterans Affairs.
The extent of any impact on federal customers remains unclear. Veterans Affairs previously said it was not affected.
The FBI investigated the cyberattack and related efforts by hackers to extort healthcare companies following the breach.
Oracle had said the compromised information was stored on older Cerner servers and had not yet been migrated to its cloud infrastructure.
The company declined to comment on the latest disclosure.