The scale of a 2025 data breach involving electronic protected health information stored on Oracle Health’s legacy Cerner servers is becoming clearer. While not independently verified, Bloomberg reports that the Texas Attorney General released information suggesting that the protected health information of almost 20 million individuals was compromised in the incident.
Oracle Health has not publicly disclosed how many Cerner clients were affected, or the total number of individuals affected. While some state attorneys general publish breach notices on their websites, only a handful disclose the number of individuals affected by each data breach. Based on those that do, it has been confirmed that the incident affected 2,992,244 individuals in Texas, 1,978,661 individuals in Oregon (1,970,332 + 8,329), 283,903 individuals in South Carolina, and 69,238 individuals in Washington.
The HHS’ Office for Civil Rights breach portal lists the final total number of affected individuals, although it has yet to be updated with the latest figures and still lists the incident with a placeholder total of 501 individuals. The Texas Attorney General was provided with an updated total on October 2, 2026, so the OCR breach portal should be updated in the next few weeks.
The Oracle Health/Cerner breach notice states that an unauthorized individual first gained access to legacy Cerner servers as early as January 22, 2025, and the security breach was identified by Oracle Health on March 7, 2025. The Oregon Attorney General lists the breach dates as January 22, 2025, to April 1, 2025. Data compromised in the incident included names, Social Security numbers, and medical record-related health information, including diagnoses, care and treatment information, medications, test results, medical images, medical record numbers, and physician names.
The security breach appears to have been the work of a solitary hacker rather than a ransomware group. The hacker demanded a ransom payment to prevent the publication of the stolen data, based on reporting in March 2025. The incident involved two legacy Cerner servers that had yet to be migrated to Oracle Cloud.
Oracle acquired Cerner Corporation in 2022 in a $28. 4 billion deal, and merged the company into Oracle Health. Oracle Health said its own systems were not affected and has distanced itself from the incident, which has been reported as a Cerner Corporation data breach.
Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy “This news story should serve as a warning for anybody looking to acquire another company.
Security due diligence absolutely needs to be part of the mergers and acquisitions process. It’s something we spend a lot of time doing for our customers. I don’t like the fact that Oracle is kind of hand-waving this away by saying these were legacy systems that hadn’t been migrated to their secure cloud services yet,” John Strand, Owner, Black Hills Information Security Inc.
, told the HIPAA Journal. “They’re still responsible. The moment you acquire a company, you become responsible for all aspects of that company, and that includes its security vulnerabilities.”
December 30, 2025: 80 Hospitals May Have Been Affected by the Oracle Health Data Breach The number of individuals affected by the hacking incident at Oracle Health has yet to be confirmed; however, the data breach is known to have affected up to 80 hospitals. Oracle Health has been notifying the affected healthcare provider clients, some of whom have only recently learned that they have been affected.
Lake Regional Health System in Missouri, OSF Saint Clare Medical Center in Illinois, Aultman Health System in Ohio, and NKC Health in North Kansas City have all recently confirmed that they were affected by the hacking incident and had patient data stolen. Each of those healthcare providers has started issuing notifications to the affected patients and has offered complimentary credit monitoring services.
The data compromised in the hacking incident varies from provider to provider and generally includes information typically stored in medical records, such as names, dates of birth, Social Security numbers, medical record numbers, diagnoses, medications, test results, and medical images. While data was compromised in the incident, there have been no known instances of data misuse to date.
Some of the affected healthcare providers have only recently received notices from Oracle Health informing them that they have been affected. For instance, OSF Saint Clare Medical Center and NKC Health only received a list of the affected individuals in November, 11 months after the hacking incident occurred. Multiple class action lawsuits have been filed in response to the data breach.
One of the lawyers representing a victim of the breach was told by Oracle Health’s attorneys that 80 hospitals may have been affected. Elena A. Belov, the attorney representing one of the victims in a lawsuit filed in the Western District of Missouri, suggests the data breach may affect millions of individuals.
One of the worst-affected healthcare clients was Munson Healthcare in Michigan, which has recently confirmed that more than 100,000 patients have been affected.
Originally published at hipaajournal.com


