A major cybersecurity breach at Oracle’s healthcare division has exposed the personal and medical information of nearly 20 million people, raising fresh concerns about the security of sensitive health records stored on legacy systems.
The Texas Attorney General’s office revealed that the breach compromised data including Social Security numbers, addresses and medical information. Around three million Texans are believed to be among those affected by the incident.
The scale of the breach makes it one of the more significant healthcare data security incidents involving a major technology provider. The information potentially exposed includes details that could allow attackers to identify individuals and gain insight into their medical histories.

Credits: Techzine
Oracle Disclosed Cyberattack in March 2025
Oracle informed some of its healthcare customers about the cyberattack in March 2025. The company said the incident occurred after January 22, although it did not disclose at the time how many electronic health records had been affected.
Oracle’s healthcare business serves a wide range of organizations, including regional hospitals and medical clinics. Its customers also include major US government agencies such as the Department of Defense and the Department of Veterans Affairs.
The extent to which federal government customers were affected remains unclear.
The lack of an immediate estimate of the number of compromised records has added to concerns surrounding the incident, particularly given the highly sensitive nature of healthcare information.
Medical Information May Have Been Compromised
The severity of the breach varied between patients, according to healthcare organizations affected by the incident.
Texas-based Christus Health and California’s Tri-City Medical Center have both confirmed that different patients may have had different types of information exposed.
The compromised data could include names, Social Security numbers, information about doctors and healthcare providers, diagnoses, medications and medical test results.
Such information can be particularly sensitive because medical records can reveal details about an individual’s health history and treatment. Unlike passwords, many types of medical and identity information cannot simply be changed following a breach.
Both Christus Health and Tri-City Medical Center were among numerous healthcare organizations using Oracle’s affected systems.
Attack Targeted Legacy Cerner Systems
Oracle’s March 2025 disclosure provided additional details about how the cyberattack occurred.
The company said hackers gained access to older servers associated with Cerner Corp., the healthcare technology company Oracle acquired in 2022 for $28 billion.
The compromised data was stored on these older systems and had not yet been transferred to Oracle’s cloud storage service, according to the company.
The incident therefore highlights the cybersecurity risks associated with legacy infrastructure, particularly when older systems continue to contain large amounts of sensitive information after an acquisition.
For Oracle, the breach also illustrates the challenges involved in integrating acquired healthcare technology and protecting historical records during a transition to newer cloud-based systems.

Credits: Moneycontrol
FBI Investigates Ransom Attempts
The FBI investigated the cyberattack as well as attempts by the hackers to extort medical companies, adding a potential ransomware and extortion dimension to the incident.
Healthcare organizations have increasingly become targets for cybercriminals because of the value and sensitivity of medical records. Hospitals and healthcare providers can also face significant pressure to restore systems quickly because disruptions can affect patient care.
The latest disclosure could therefore increase scrutiny of Oracle’s cybersecurity practices and the safeguards used by healthcare organizations relying on its technology.
With nearly 20 million people potentially affected, the incident also demonstrates how a breach involving a technology provider can have consequences far beyond a single hospital or healthcare network.
As investigations continue, affected organizations and authorities are expected to assess exactly what information was accessed and which individuals were exposed. The potential involvement of sensitive medical and identity data makes the incident particularly serious for patients whose information was stored on the affected systems.




