An unmigrated Cerner server may have exposed 20 million patients
Key takeaways
- Texas Attorney General filings put the Oracle Health breach at nearly 20 million people, including about 3 million Texans
- The attackers reached older Cerner servers whose data had not yet been migrated to Oracle's cloud
- Exposed records can include Social Security numbers, addresses, diagnoses, medications and lab results
Nearly 20 million people. That is the first hard number for the Oracle Health breach, and it took more than a year to arrive. Filings with the Texas Attorney General's office, first reported by Bloomberg, put the total at close to 20 million, with about 3 million of them in Texas.
The detail that explains it is mundane. The data sat on old servers that had never been moved.
What happened in the Oracle Health Cerner data breach
Oracle bought the health records company Cerner in 2022 for $28 billion. In March 2025 it told some customers that attackers had got into older Cerner servers at some point after 22 January that year. The data on those machines had not yet been migrated to Oracle's cloud service. At the time, Oracle gave no figure for how many patients were affected.
According to reports, the exposed information includes Social Security numbers, home addresses and medical details. Hospitals caught up in it, including Tri-City Medical Center and CHRISTUS Health, said records could contain treatment details, diagnoses, medications and lab results.
The public record still leaves gaps. As eSecurity Planet notes, nobody has explained how the attackers obtained the credentials they used, or why one customer credential opened data belonging to several healthcare organisations. Oracle declined to comment on the new figure.
Why the unmigrated server is the story
Migrations are where security tends to slip. When a company buys another, the old systems keep running while the new platform is built, and those leftovers often get less attention than either the old owner's live systems or the new cloud. They still hold real patient data, and attackers go where the attention is lowest.
Big breaches this year have shown how much personal data sits in places people never think about, as we covered with Denmark's CPR breach and the European Space Agency breach. In this case, the weak point was a system that was meant to be on its way out.
What to do if you might be affected
Medical data cannot be reset like a password, so the practical steps are about limiting follow-on damage. Watch for letters from your healthcare provider, check insurance statements for treatments you never had, and consider a credit freeze if your Social Security number may be involved.
Breach victims also tend to get targeted phishing that uses the stolen details to sound convincing. Protecting your email account matters most here, since it is the reset route for everything else. A hardware security key such as the YubiKey 5 NFC makes phishing logins far harder on accounts that support it; check current pricing on Amazon.
What to watch next
Watch for official notification letters, for further state filings that could move the total, and for any explanation of how the credentials were taken. That last one decides whether this was a single mistake or a problem in how Oracle manages access across customers.
Some links in this article are affiliate links. We may earn a small commission at no extra cost to you.