Oracle Health Data Breach Surpasses 20 Million Records Exposed

www.news4hackers.com-oracle-health-data-breach-surpasses-20-million-records-exposed-oracle-health-data-breach-surpasses-20-million-records-exposed

Oracle Health Data Breach Exposes Nearly 20 Million Individuals, Texas Attorney General Reports

Overview of the Breach

The personal and medical information of approximately 20 million individuals was exposed in a cybersecurity incident targeting legacy Cerner systems under Oracle Health, according to a report from the Texas attorney general. This figure surpasses earlier estimates disclosed through regulatory filings and patient notifications, highlighting the scale of the breach.

Acquisition by Oracle

Cerner, an electronic health record (EHR) provider, was acquired by Oracle in June 2022 through a transaction valued at $28.3 billion. The company now operates as Oracle Health. Oracle has not publicly addressed the specific number of affected individuals and has not commented on the findings.

Investigation Findings

Oracle initiated notifications to healthcare clients in March 2025, disclosing that a cybersecurity event occurred on or around February 20, 2025. The investigation revealed that an unauthorized actor gained access to a server using compromised customer credentials, copying data to a remote server.

According to sources connected to BleepingComputer, extortion attempts were attributed to an individual threat actor identified as “Andrew.” This actor was not linked to any known ransomware or extortion groups. The hacker demanded substantial cryptocurrency payments to prevent the release or sale of stolen data, while also establishing public websites to pressure victims.

Regulatory Filings and State Reports

Regulatory filings provide additional details about the breach’s scope. The Texas attorney general’s data breach portal lists 2,992,244 affected residents, while South Carolina and Washington regulators reported 283,000 and 69,000 impacted individuals, respectively. Oregon’s records specify the breach period as January 22 to April 1, 2025, with the discovery date noted as February 20, 2025.

Sample Breach Notification

A sample breach notification letter submitted to California regulators outlines the types of data involved. The document states that personal information may have included names, Social Security numbers, and medical records such as medical record numbers, physician details, diagnoses, medications, test results, imaging, and treatment histories.

Comparison to Other Breaches

If verified, the breach would rank among the largest healthcare data compromises in U.S. history. Only a few incidents, such as the 2024 ransomware attack on Change Healthcare—which affected 192.7 million people—exceeded this scale.

Implications and Recommendations

The breach underscores vulnerabilities in healthcare infrastructure, particularly following organizational transitions like Cerner’s acquisition by Oracle. The incident also highlights the evolving tactics of threat actors, who increasingly exploit stolen credentials and leverage extortion strategies to target critical sectors. Regulatory scrutiny is ongoing, with multiple states investigating the breach’s impact. Affected organizations are advised to monitor for unauthorized activity and implement additional safeguards to mitigate risks associated with data exposure.



About Author

en_USEnglish