INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Oracle Health/Cerner Data Breach Affects Almost 20 Million Individuals

| 2026-10-08 07:12 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
A 2025 data breach involving electronic protected health information stored on Oracle Health's legacy Cerner servers has affected almost 20 million individuals, with the Texas Attorney General reporting that nearly 2.99 million individuals were impacted in Texas alone. The breach was identified by Oracle Health on March 7, 2025, and is believed to have been caused by a solitary hacker who demanded a ransom payment from Oracle Health. The data compromised included names, Social Security numbers, medical record-related health information, and diagnoses, care and treatment information, medications, test results, medical images, and physician names. As of October 2, 2026, the Texas Attorney General had been provided with an updated total number of affected individuals, but this figure has yet to be reflected on the HHS' Office for Civil Rights breach portal, which currently lists a placeholder total of 501 individuals.
Technical Mitigations AI-generated
• Migrate legacy Cerner servers to Oracle Cloud as soon as possible. • Implement robust security due diligence during mergers and acquisitions, including thorough vulnerability assessments of acquired companies' systems. • Regularly review and update system access controls for all employees with elevated privileges.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2021-35587CVE-2021-35587
Target & Sectors
Global Scope legallegal healthhealth
Incident Timeline
‎December 2021
Oracle announced an agreement to buy Cerner Corporation in December 2021.
‎June 2022
Threat actors exploited a previously unknown vulnerability in the merged Oracle Health/Cerner system to compromise sensitive data of nearly 20 million individuals.
‎January 2025
A class action lawsuit has been filed against Oracle Corporation on behalf of individuals whose personal data was compromised in a January 2025 data breach.
tactic Data Breach
organisation Healthcare Data Breach
organisation Oracle Corporation
organisation the Department of Health and Human Services
organisation HHS) Office for Civil Rights
organisation Shamis & Gentile
‎January 22, 2025
Threat actors allegedly exploited a vulnerability in Oracle Access Manager (CVE-2021-35587) to access and exfiltrate sensitive data from over 140,000 customers using Oracle Cloud services.
industry Health
industry Legal
organisation the U.S. Department of Health and Human Services
organisation CVE-2021-35587
organisation Oracle Access
organisation the Health Insurance Portability
organisation Oracle Health’s Chief Information Security Office
organisation Oracle Cloud
data_breach 6 records
organisation rose87168
organisation SSO
organisation CloudSEK
victims 140,000 customers
‎around January 22, 2025
Threat actors used stolen credentials to access Oracle Health/Cerner servers on or around January 22, 2025.
‎February 20, 2025
The two named plaintiffs claim Oracle Health failed to issue timely breach notifications, violating both the HIPAA Breach Notification Rule and a Texas data breach notification statute.
industry Health
industry Legal
organisation the HIPAA Breach Notification Rule
organisation the U.S.
organisation District Court
organisation Cerner
financial $28.3 acquisition
organisation HIPAA
‎March 7, 2025
Threat actors exploited a vulnerability in Oracle Health/Cerner's systems to breach sensitive data, affecting nearly 20 million individuals.
industry Health
industry Legal
‎March 2025
Threat actors exploited unsecured legacy systems at Cerner Corporation, which was acquired by Oracle in 2022 and subsequently merged into Oracle Health, to steal data that would be published unless a ransom payment is made.
organisation Cerner Corporation
financial $28.4 deal
organisation Owner
organisation Black Hills Information Security Inc.
organisation the HIPAA Journal
‎March 31, 2025
Threat actors exploited a vulnerability in Oracle Health's systems to access and potentially exfiltrate sensitive patient data related to Cerner's electronic health records.
industry Health
industry Legal
organisation EHR
‎April 1, 2025
A solitary hacker exploited vulnerabilities to breach Oracle Health/Cerner's systems between January 22, 2025, and April 1, 2025.
industry Health
industry Legal
organisation Social Security
‎April 3, 2025
Threat actors used a sophisticated attack vector to breach the combined health records of Oracle Health and Cerner, compromising data from nearly 20 million individuals.
industry Health
industry Legal
‎April 7, 2025
Threat actors, claiming to be rose87168 and Andrew, are attempting to sell stolen data records from Oracle Health's Gen1 cloud services.
industry Health
industry Legal
organisation Oracle Cloud Infrastructure
organisation OCI
organisation Gen1
organisation The Oracle Health
organisation The Federal Bureau of Investigation
data_breach 6 records
‎April 15, 2025
Threat actors exploited a vulnerability in Oracle Health/Cerner's systems to breach sensitive data of nearly 20 million individuals.
industry Health
industry Legal
‎April 21, 2025
Threat actors have stolen sensitive data from Oracle's legacy cloud environment, which can be enriched with information from prior breaches and potentially sold to other threat actors or used for phishing campaigns.
industry Health
industry Legal
tactic Data Breach
organisation Oracle Data Breach
organisation BEC
organisation Oracle
‎August 14, 2025
Threat actors used unknown methods to target Oracle Health/Cerner, resulting in the breach of sensitive data affecting more than 14,480 confirmed individuals.
industry Health
industry Legal
‎December 30, 2025
Threat actors used unknown methods to target Oracle Health, resulting in the theft of patient data affecting up to 80 hospitals and potentially millions of individuals.
industry Health
industry Legal
tactic Data Breach
organisation the Oracle Health Data Breach
general_metric 80 Hospitals
organisation Lake Regional Health System
organisation OSF Saint Clare Medical Center
organisation NKC Health
organisation Munson Healthcare
‎March 31, 2025:
Oracle Health and Cerner experienced a data breach affecting nearly 20 million individuals, with the exact date of discovery not specified in this snippet.
‎April 3, 2025:
A Florida resident filed a class action lawsuit against Oracle Corporation in the U.S. District Court for the Western District of Texas on April 3, 2025, alleging that the company was responsible for a January 2025 data breach affecting almost 20 million individuals.
tactic Data Breach
organisation Healthcare Data Breach
organisation Oracle Corporation
‎April 15, 2025:
Oracle confirmed a hacking incident on April 15, 2025.
organisation Oracle Confirms Hacking Incident
‎August 14, 2025:
At least 14,485 individuals are known to be affected by a data breach at Oracle Health/Cerner.
tactic Data Breach
organisation AdventHealth
organisation Baptist Health
organisation Mosaic Life Care
organisation Tallahassee Memorial Healthcare
organisation Florida Union Health
organisation Oracle Health/Cerner Data Breach
general_metric 14,485 Individuals
‎October 2, 2026
Unauthorized individual gained access to legacy Cerner servers as early as January 22, 2025.
industry Health
industry Legal
organisation OCR
organisation The Oracle Health/Cerner
organisation Oracle Health on March 7, 2025
‎Oct 8, 2026
Almost 20 million individuals' protected health information was compromised in a data breach involving Oracle Health's legacy Cerner servers.
industry Health
industry Legal
tactic Data Breach
general_metric 20 Individuals
data_breach 2025 Data Breach
organisation Oracle Health/Cerner Posted
organisation Oracle Health’s
organisation Oracle Health
organisation The HHS’ Office for Civil Rights
‎2026/10/08
Oracle Health/Cerner experienced a 2025 data breach affecting at least 14,485 residents across multiple states.
organisation Data Breach
organisation Oracle Health/Cerner
data_breach 2025 Data Breach
organisation The HHS’ Office for Civil Rights
organisation California Unknown Total
‎November, 11 months
Oracle Health/Cerner notified OSF Saint Clare Medical Center and NKC Health with a list of nearly 20 million affected individuals in November, approximately 11 months after the reported hacking incident.
‎2027/09/03
Threat actors compromised Oracle Health/Cerner's systems in 2025, resulting in the exposure of sensitive data that was not disclosed to affected individuals until November 2026.
Tactical Metrics
Metrics
data_breach
2,025
Data Breach
Metrics
financial
28,400,000,000
Deal
Metrics
financial
28,300,000,000
Acquisition
Metrics
data_breach
6,000,000
Records
Metrics
victims
140,000
Customers
Intelligence Sources