VYPR
breachPublished Oct 7, 2026· 1 source

Oracle Health Cerner EHR Breach Impacts 20 Million Patients

Oracle Health's Cerner EHR system breach, initially reported in 2025, has now affected an estimated 20 million patients, making it one of the largest health data compromises of that year.

Oracle Health has informed Texas state regulators that a hacking incident in 2025 involving legacy Cerner electronic health record data has impacted approximately 20 million individuals. This figure, if accurate, places the breach among the top three largest health data compromises reported to U.S. federal regulators in 2025. The U.S. Department of Health and Human Services' HIPAA Breach Reporting Tool had previously listed the incident with a placeholder estimate of only 501 patients.

The expanded scope of the breach was revealed through information released by the Texas attorney general's office, which indicated that nearly 3 million Texans were among the affected individuals. Attorneys general in other states, including South Carolina and Oregon, have also quietly updated their resident counts for the Oracle hack. Numerous healthcare systems and hospitals have issued breach notices over the past year, confirming that their patients were affected.

Notable healthcare providers reporting patient impact include ChristianaCare in Delaware, LifeBridge Health in Maryland, and Heartland Regional Medical Center (Mosaic Life Care) in Missouri. Mosaic Life Care, for instance, reported to HHS OCR in June 2025 that the incident affected nearly 145,300 patients.

Oracle, which acquired Cerner in 2022 for $28.3 billion, stated in a July 2025 breach notice that the attack targeted legacy Cerner systems. The compromised information included patient names, Social Security numbers, medical record numbers, doctors' names, diagnoses, medications, test results, and treatment details.

Security researchers at Blackfog reported that an unknown threat actor gained access to these legacy Cerner servers, which had not yet been migrated to Oracle Cloud, using stolen credentials. The breach is believed to have begun as early as January 22, 2025, and was detected in February 2025 when Oracle identified the intrusion and initiated notifications to affected healthcare providers.

This Cerner data breach was not an isolated incident for Oracle in 2025. Other breaches included a March 2025 hack exploiting a vulnerability in Oracle Cloud's Single Sign-On and Lightweight Directory Access Protocol, and a September 2025 extortion campaign by the Clop ransomware group targeting a zero-day vulnerability in Oracle's E-Business Suite.

In response to the Cerner hack, Oracle is currently facing several proposed federal class action lawsuits. The scale of this breach underscores the persistent risks associated with managing legacy systems and the critical importance of robust third-party risk management in the healthcare sector.

Synthesized by Vypr AI
Oracle Health Cerner EHR Breach Impacts 20 Million Patients · VYPR