Oracle Health breach tally nears 20 million after Texas disclosure

Texas regulators have put the first hard number on a year-old Cerner server intrusion, and it is the largest healthcare breach figure of the year.

MedRisk Staff
By
2 Min Read

The true scale of a breach on Oracle Health’s legacy Cerner servers is finally coming into focus. Texas Attorney General data, first surfaced through Bloomberg reporting, points to nearly 20 million people whose protected health information was caught up in the 2025 intrusion.

No single figure covers the whole incident yet. State-level filings confirm 2,992,244 residents in Texas, 1,978,661 in Oregon, 283,903 in South Carolina, and 69,238 in Washington. Oracle Health has never publicly said how many Cerner clients or patients were affected, and the HHS Office for Civil Rights portal still shows a placeholder total of 501. Texas supplied an updated count on October 2, so the federal tally should move within weeks.

Breach notices trace the activity to legacy Cerner servers. An unauthorized party gained entry as early as January 22, 2025, and the intrusion ran until April 1, 2025, according to the Oregon Attorney General. Exposed data included names, Social Security numbers, and clinical detail such as diagnoses, medications, test results, medical images, and physician names.

Reporting suggests a lone hacker rather than a ransomware crew, with a ransom demand to block publication of the data. The affected servers had not been migrated to Oracle Cloud, and Oracle has argued its own systems were untouched. The company folded Cerner into Oracle Health after a $28.4B acquisition in 2022.

Why it matters for healthcare security teams — the case is a vendor-diligence warning. When one EHR business associate is compromised, dozens of hospitals inherit the notification burden months or years later. Sites should map every legacy system a partner still runs, force notification timelines into contracts, and assume inherited exposure is larger than any single breach portal shows.

Share This Article