A 2025 data breach of Oracle Health’s legacy Cerner system compromised personal information belonging to nearly 20 million people, Bloomberg reported Monday, citing information released by the Texas attorney general.
In a report issued October 2, the Texas attorney general said the company disclosed that Social Security numbers, addresses and medical information of almost 20 million people, including about 3 million Texans, were compromised in the incident, Bloomberg reported.
Oracle Health has not publicly disclosed how many Cerner clients were affected, or the total number of individuals affected.
The original breach notice said an unauthorized individual gained access to the servers on Jan. 22, 2025, with the breach identified on March 7, 2025, The HIPAA Journal reported.
According to the Texas attorney general’s data breach portal, Cerner Corp. reported nearly 3 million affected Texans and said exposed data included addresses, Social Security numbers and medical information. The entry in the data breach portal was dated Oct. 2, and Oracle Health/Cerner notified affected individuals in Texas by U.S. mail.
Becker's Hospital Review reported that at least 29 health systems were impacted by the massive data breach. The HIPAA Journal reported that 80 hospitals may have been affected by the hack.
According to a notice sent to impacted Oracle customers in late February 2025, Oracle Health learned that cybercriminals had gained access to patient information through legacy Cerner servers that were not yet migrated to the Oracle Cloud. The software giant acquired Cerner in 2022 for $28 billion.
According to media reports that same month, impacted hospitals received extortion demands related to the breach. Per Bleeping Computer, the extortions came from a single threat actor demanding millions in cryptocurrency.
Oracle faces legal action over the data breach, including a major consolidated federal class-action lawsuit currently unfolding in the U.S. District Court for the Western District of Missouri. In April 2025, two women filed a class action lawsuit accusing the company of negligently failing to protect patient data. According to the complaint, Oracle "negligently and unlawfully failed to safeguard plaintiffs and class members' private information by allowing cyberthieves to access its computer network and systems, which contained unsecured and unencrypted private information."
The complaint alleges that, as a result of the breach, a hacker exfiltrated patient data including names, Social Security numbers, dates of birth, driver’s license numbers, medication details and diagnostic information.
The data breach was a "direct result of Oracle’s failure to implement adequate and reasonable cybersecurity procedures and protocols necessary to protect individuals’ private information," the plaintiffs argue in the complaint. They also claim that Oracle delayed necessary notifications.
The lawsuit accuses Oracle of violating several federal and state laws, including HIPAA, the Federal Trade Commission Act and multiple California privacy laws.
Twenty-nine separate class action lawsuits filed across 13 states were consolidated into a single master case in Missouri. The consolidated class action suit also targets eight health systems.
In June, a federal judge ruled that the data breach lawsuit against Oracle Health and the eight health systems can move forward. Becker's Hospital Review reported that the court rejected the health systems’ argument that the breach was Oracle Health’s responsibility alone, writing that the providers had not shown their duty to protect patient data was delegable and could not be “absolved of liability by contracting them out to a third party.”
The court's ruling that healthcare organizations cannot delegate their data protection responsibility to a vendor could carry weight well beyond this specific breach.
Oracle Health has not publicly responded to the lawsuit and did not respond to a request for comment on the Bloomberg report.