Oracle Health’s 2025 data breach compromised personal information belonging to nearly 20 million people, Bloomberg reported, citing a report released by the Texas attorney general.
The Texas attorney general’s data breach portal lists Cerner Corp. (now known as Oracle Health) as reporting almost 3 million affected Texans. Exposed data included addresses, Social Security numbers and medical information. The entry was posted Oct. 2, and Cerner notified affected Texans by U.S. mail.
The attorney general’s report said the company disclosed the total of almost 20 million people, according to the Oct. 5 Bloomberg story.
Oracle started alerting healthcare customers in March 2025 that attackers had accessed older Cerner servers sometime after Jan. 22, 2025. The data on those servers had not yet been migrated to Oracle’s cloud. Oracle Health had not previously disclosed how many patient records were affected. Oracle acquired Cerner in 2022 for $28.4 billion.
At least 29 hospitals and health systems have reportedly been affected by the breach, and Oracle Health faces litigation over the incident.
Oracle’s healthcare customers include regional hospitals and clinics, the Defense Department and the Department of Veterans Affairs. A VA spokesperson said at the time of the March 2025 disclosure that the agency was not affected, per Bloomberg. The FBI investigated the attack and hackers’ attempts to extort ransom payments from medical organizations.
Oracle declined to comment to Bloomberg. Becker’s has reached out to Oracle and the Texas attorney general’s office for comment and will update this story if more information becomes available.