Oracle Health Breach Reportedly Exposed Data of Nearly 20 Million People
Attackers accessed an unmigrated legacy Cerner server, with nearly 3 million affected residents listed in Texas alone.
Personal and medical information of nearly 20 million people was reportedly compromised in a breach of Oracle Health systems, SecurityWeek reports.
What happened
- The incident affected legacy Cerner systems that Oracle acquired in 2022.
- Unauthorized access to an unmigrated server reportedly began around February 2025.
- State breach listings in Texas alone cover nearly 3 million residents.
The legacy-system problem
The breach highlights a recurring risk in large acquisitions: older systems that have not yet been moved to a new platform often miss the security controls applied elsewhere. Health records are especially valuable to attackers because, unlike credit card numbers, they cannot be reissued.
A heavy week for security news
The report arrived alongside other major incidents. In Denmark, attackers abused a private company's legitimate access to the national Central Person Register to extract data tied to about 8.8 million people. In South Korea, attacks on seven financial firms may have exposed data on more than 67,000 people. And at Pwn2Own Ireland, researchers demonstrated 45 previously unknown vulnerabilities in a single day.
Patients who received care at facilities using Cerner systems should watch for breach notification letters and consider a credit freeze.