A cyberattack against Oracle Health last year exposed the personal data of almost 20 million people, the Texas attorney general’s office said in a report, according to Bloomberg.
The personal information taken by the attacker included Social Security numbers, addresses and medical information, Oracle disclosed to investigators. The cybersecurity breach happened after Jan. 22, 2025, and Oracle alerted some customers about it in March of that year, Bloomberg reported.
Oracle Health is a division of Oracle, which acquired healthcare technology company Cerner for $28.3 billion in June 2022.
Oracle told its customers that attackers had targeted older Cerner servers before the data stored on them could be migrated to Oracle’s cloud storage service, Bloomberg said. The hacker compromised customer credentials and used them to access two Cerner servers and then copied patient data from those servers, according to UK cybersecurity firm CyPro.
Neither Oracle nor the Texas attorney general specified which hospitals, clinics or other healthcare providers were affected by the data theft.
CNET reached out to both the Texas AG’s office and Oracle, but representatives did not immediately respond.
Who’s affected by the Oracle Health breach?
Oracle healthcare customers include hospitals and clinics in Texas and other states, as well as the Department of Defense and the Department of Veterans Affairs. Of the nearly 20 million people affected, 3 million were Texans.
Christus Health, a nonprofit healthcare system in Texas, and Tri-City Medical Center in California — both affected by the breach — said stolen patient data could include names, Social Security numbers, doctors, diagnoses, medicines and test results, Bloomberg reported.
Christus said that patients whose data was compromised would receive letters about the incident and also would be offered a complimentary two-year membership to credit monitoring and identity protection services.
CyPro noted Tuesday that at least 29 hospital and health systems said they had been affected by the breach.
“The incident demonstrates how older infrastructure can remain a material source of third party risk during cloud migration,” Rob McBride, a CyPro founding partner, wrote. “Even though Oracle says its cloud infrastructure was unaffected, data held on two legacy servers was sufficient to expose information potentially belonging to millions of patients.”
What if your data was stolen?
Stolen data can be used to make scam attempts much more convincing, especially if the would-be criminals know your name, address or healthcare details, says Cliff Steinhauer, director of information security and engagement at the digital safety nonprofit National Cybersecurity Alliance.
“If someone contacts you claiming to be from insurance or a medical provider and asks for sensitive information or demands payment, hang up and call your provider back at a number you know belongs to them (like the back of your insurance card),” Steinhauer told CNET via email.
Steinhauer said that people whose data was stolen in the Oracle breach should find out what data was taken and use any identity or credit monitoring being offered.
“Keep an eye on your credit reports, financial accounts and healthcare statements for anything you don’t recognize,” he added. “It’s always a good idea to freeze your credit with all three major credit reporting bureaus as a preventative measure.”

