HomeMalware & ThreatsOracle Health's Cerner EHR Breach Count Reaches 20 Million

Oracle Health’s Cerner EHR Breach Count Reaches 20 Million

Published on

spot_img

3rd Party Risk Management,
Cybercrime,
Data Breach Notification

Vendor Has Updated Breach Reports to Several States Including Texas

Oracle Health’s Cerner EHR Breach Count Reaches 20 Million
Oracle Health has reportedly informed Texas state regulators that its 2025 hack involving legacy Cerner health record data has affected approximately 20 million people. (Image: Oracle)

In a recent update concerning a significant security breach, it has been revealed that approximately 20 million patients were affected by a hacking incident involving health data stored on legacy servers managed by Cerner, an electronic health record vendor. This incident, which occurred in 2025, has drawn considerable attention due to its scale and implications for healthcare data security.

According to trusted sources, if the reported figure is accurate, this breach ranks among the three largest health data compromises disclosed to U.S. federal regulators in 2025. As of the latest updates, the U.S. Department of Health and Human Services had classified the Cerner breach as a hacking incident first reported on June 17, 2025, initially listing a placeholder estimate that included only 501 patients.

Bloomberg reported on Monday that information released by the Texas attorney general’s office has confirmed that the Cerner breach, which compromised health and personal data, involved a staggering total of 20 million individuals, including nearly 3 million residents of Texas alone. This shocking disclosure highlights the severe impact of data breaches on individuals and healthcare systems alike.

Despite inquiries, both Oracle and the Texas attorney general’s office failed to respond immediately to requests from Information Security Media Group (ISMG) for comments regarding the newly updated estimate of affected patients. This silence raises questions about transparency and accountability in the management of such critical data.

Moreover, the breach has not only affected Texas; attorneys general in several other states, including South Carolina and Oregon, have quietly updated their records to reflect the new number of residents impacted by the Oracle breach. Numerous healthcare systems and hospitals have also issued breach notifications over the past year, citing their patients’ involvement in this massive data incident.

Among those reporting impacts are notable institutions such as Delaware’s ChristianaCare, Maryland’s LifeBridge Health, and Missouri’s Heartland Regional Medical Center, the latter of which revealed in their report to the Department of Health and Human Services that around 145,300 of their patients were affected by this breach.

Oracle, which acquired Cerner for a substantial $28.3 billion in 2022, issued a breach notification in July 2025 indicating that the attack involved legacy systems holding critical patient information, including names, Social Security numbers, and details contained within medical records. Such information included medical record numbers, the identities of attending physicians, diagnoses, medications, test results, and treatment plans.

Research conducted by the security firm Blackfog has indicated that the incident was executed by an unknown threat actor who utilized stolen credentials to gain access to the old Cerner servers, which had not yet been migrated to Oracle’s cloud infrastructure. The breach reportedly began as early as January 22, 2025, but went undetected until February of that year, when Oracle recognized the intrusion and began notifying affected healthcare providers.

This incident is not isolated; it is one of several breaches that Oracle experienced last year. The Cerner data breach is one of the most significant examples, but it follows a March 2025 incident involving hackers under the alias “rose87168,” who were able to exploit vulnerabilities within Oracle Cloud’s Single Sign-On and Lightweight Directory Access Protocol. Additionally, a mass extortion campaign spearheaded by the Clop ransomware group targeted Oracle in September 2025, exploiting a previously unknown vulnerability within its E-Business Suite.

In light of these repeated incidents, Oracle is now facing multiple proposed federal class action lawsuits related to the Cerner breach. As the implications of this security breach continue to unfold, it raises deeper questions about data safeguards within healthcare systems and the accountability of large technology vendors managing sensitive personal information.

Source link

Latest articles

SonicWall’s Recent Critical Vulnerability Highlights a Security Trend Rather Than Just Another Isolated Issue

In the ever-evolving landscape of cybersecurity, concerns about the vulnerabilities associated with remote access...

Gartner Introduces a New Category for ISOC Security Tools

Gartner Introduces Integrated Security Operations Center (ISOC): A Shift in Cybersecurity Operations In a noteworthy...

Critical Progress DataDirect GenAI Vulnerability Allows Attackers to Execute Arbitrary OS Commands

Progress DataDirect Identifies Serious Security Vulnerability in AI Model Generator Agents Progress has revealed a...

More like this

SonicWall’s Recent Critical Vulnerability Highlights a Security Trend Rather Than Just Another Isolated Issue

In the ever-evolving landscape of cybersecurity, concerns about the vulnerabilities associated with remote access...

Gartner Introduces a New Category for ISOC Security Tools

Gartner Introduces Integrated Security Operations Center (ISOC): A Shift in Cybersecurity Operations In a noteworthy...

Critical Progress DataDirect GenAI Vulnerability Allows Attackers to Execute Arbitrary OS Commands

Progress DataDirect Identifies Serious Security Vulnerability in AI Model Generator Agents Progress has revealed a...