Oracle Health has confirmed a major data breach affecting nearly 20 million patient records across the United States. An unauthorized person accessed two legacy Cerner servers that had not yet been migrated to Oracle Cloud infrastructure.
The breach window spans from January 22, 2025, to April 1, 2025, according to state filings. Oracle Health became aware of the incident on or around March 7, 2025, though the company later stated it became aware on or around February 20, 2025.
Cerner, a major electronic health record platform serving more than 27,000 healthcare facilities across over 35 countries, was acquired by Oracle in 2022 for $28.4 billion and subsequently merged into Oracle Health.
Scope of Impact
Bloomberg reports the breach impacts as many as 80 hospitals nationwide. State-level filings reveal significant exposure in multiple jurisdictions: Texas with 2,992,244 affected individuals, Oregon with 1,978,661, South Carolina with 283,903, and Washington with 69,238.
Compromised Data
The stolen information includes names, Social Security numbers, medical record numbers, diagnoses, medications, test results, medical images, and physician names.
A hacker demanded ransom in connection with the breach to prevent publication of the files.
System Status
Oracle Health stated that its current systems and Oracle Cloud infrastructure were not affected by the breach, which was limited to the legacy servers not yet migrated to the cloud platform.

