2 min Security

Oracle medical data breach affected nearly 20 million people

Oracle medical data breach affected nearly 20 million people

In last year’s hack of Oracle Health, hackers stole data on nearly 20 million people. This includes Social Security numbers, addresses, and medical information.

This is according to a report by the Texas Attorney General. The report states that Oracle itself reported that personal data from nearly 20 million people had been stolen. Approximately 3 million of them live in Texas, Oracle’s home state.

This is the first time a specific number of affected patients has been disclosed. At the time, Oracle did not disclose exactly how many electronic patient records had been compromised. However, in March 2025, the company did warn several customers that attackers had stolen patient data. The breach occurred sometime after January 22, 2025. According to earlier reports, the attackers used stolen login credentials.

The perpetrators accessed older servers belonging to Cerner, the healthcare software provider Oracle acquired in 2022. The company said the affected data had not yet been moved to Oracle’s cloud storage. Oracle confirmed the breach involved outdated servers but denied that Oracle Cloud Infrastructure (OCI) was compromised.

What data was compromised?

The severity of the breach varies by patient, according to the Texas healthcare system Christus Health and the Tri-City Medical Center in California. In addition to names and Social Security numbers, the data may include treating physicians, diagnoses, medications, and test results. Both organizations say they are just two of the many affected Oracle customers.

Oracle’s healthcare clients include regional hospitals and clinics, as well as the U.S. Department of Defense and the Department of Veterans Affairs. It is unclear whether all of these government clients were affected. A spokesperson for the Department of Veterans Affairs stated in March 2025 that the department had not been affected.

The FBI investigated the attack. As part of the investigation, the agency also looked into attempts by the hackers to extort healthcare institutions using the stolen data.