Oracle Went 19 Months Without Saying How Many Patients Its Cerner Hack Hit. The Answer Is Nearly 20 Million
Patients whose Social Security numbers and medical details were stolen in early 2025 are only now learning how big the Oracle Health hack was, from a Texas state portal rather than from Oracle.

Last year's hack of Oracle Health hit 19,929,149 people. Oracle never announced it. The number surfaced in a filing on the Texas attorney general's data breach portal, posted on 2 October by Cerner Corp., the health records company Oracle bought in 2022 for about $28 billion.
That is more than 19 months after Oracle Health says it discovered the intrusion. Bloomberg reported the figure on Monday. Oracle declined to comment.
What was taken
The filing lists 2,992,244 affected Texans, notified by US mail, and says the stolen data included Social Security numbers, addresses and medical information. Affected providers such as Christus Health and Tri-City Medical Center in California have said that could mean names, doctors, diagnoses, medicines and test results, though how much was exposed varied from patient to patient.
Oracle Health says it became aware on or around 20 February 2025 of unauthorized access to "some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud." Attackers got in with compromised customer credentials sometime after 22 January 2025 and copied data to a remote server.
Your problem, not ours
The way Oracle handled it at the time is the part that stings. As BleepingComputer reported in March 2025, Oracle privately alerted some hospital customers but told them it would not notify patients directly. Deciding whether HIPAA required notification was their job. Oracle offered help identifying affected people, letter templates, credit monitoring and a mailing vendor.
The notices themselves came on plain paper rather than Oracle letterhead, signed by Oracle Health executive vice president Seema Verma. Customers were told to talk to Oracle's CISO office by phone, not email.
Then the extortion started. A threat actor calling himself "Andrew" went after the hospitals, demanding millions in cryptocurrency and putting up public websites to pressure them. The FBI investigated both the attack and the ransom attempts. Nobody has been publicly identified.
A separate denial
The same spring, Oracle was fighting a different fire. A hacker going by rose87168 claimed to have stolen 6 million records from Oracle Cloud login servers, and Oracle flatly said "There has been no breach of Oracle Cloud." It later privately told some customers that an older "legacy environment" had been breached. That is a separate incident from Cerner, but it fit a pattern of saying as little as possible in public.
Oracle has had a rough run on security lately, with ShinyHunters mass-exploiting unpatched Oracle PeopleSoft installs. And health data keeps leaking at scale, as the Aesto Health breach of 9.5 million patient records showed earlier this year.
Oracle Health's customers include regional hospitals and clinics as well as the Department of Defense and the Department of Veterans Affairs. A VA spokesperson said in March 2025 the agency wasn't affected; how other federal customers fared remains unclear. For nearly 20 million patients, the full picture arrived a year and a half late, and not from the company that lost their data.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free