Yaamlabs
Threat intel

Oracle Health Cerner breach count jumps to 20 million

A 2025 hack of legacy Cerner servers now reportedly affects nearly 20 million people. Why counts lagged, and what covered entities should check.

By Yaali. October 8, 2026, 6 min read, Threat intel, Resilience.

Cover illustration of a row of old server racks with one open rack holding glowing record folders and a heartbeat line, a cloud server cluster in the distance, with the Yaamlabs logo and the text: Oracle Health's old Cerner servers exposed nearly 20 million, 501, the count HHS still shows

The count of people hit by the 2025 breach of old Cerner servers run by Oracle Health has jumped. On October 5, Bloomberg reported that information released by the Texas attorney general's office puts the total at nearly 20 million people, close to 3 million of them in Texas. The Texas portal entry, posted October 2, lists Cerner Corp. (now Oracle Health) and says the exposed data includes addresses, Social Security numbers and medical information. Neither Oracle nor the Texas attorney general's office responded to ISMG's questions about the new figure, so the 20 million total is a reported number. Oracle has not confirmed it.

If your hospital or clinic ran Cerner electronic health records (EHR) before the move to Oracle's cloud, your patients may be in this data, whether or not you have heard from Oracle since 2025. The case also shows how far official breach counts can trail reality. The federal breach portal run by the Department of Health and Human Services (HHS) still lists the incident at 501 people.

Timeline of the Oracle Health Cerner breach: access after January 22, 2025, Oracle aware February 20, customers told in March, a 501 placeholder filed with HHS on June 17, 2025, the Texas portal entry on October 2, 2026, and Bloomberg's report of nearly 20 million on October 5, 2026

How it happened

Oracle bought Cerner in 2022 and has been moving Cerner customers onto Oracle Cloud since. In its notice to customers, Oracle said that on or around February 20, 2025 it became aware of unauthorized access to "some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud". The access happened sometime after January 22, 2025, and the attacker copied the data to a remote server. Oracle first told some customers in March 2025.

According to BleepingComputer's reporting on that notice, Oracle said the attacker got in with compromised customer credentials. Oracle has not said how one customer's login could reach data belonging to many organizations, and nobody outside Oracle has published a technical account. Treat the credential detail as Oracle's claim, reported second hand.

The exposed records came from EHR data. Hospitals that sent their own notices said the stolen records may include patient names, diagnoses, medications, treating doctors and test results, on top of the Social Security numbers and addresses listed in Texas.

Why the count was wrong for so long

Under the HIPAA breach notification rule, Oracle Health is a business associate: a vendor that handles protected health information (PHI) for hospitals and clinics, the covered entities. The business associate has to tell the covered entity, and the covered entity has to notify patients and HHS within 60 days of discovering the breach. Breaches affecting 500 or more people go on the public HHS portal.

When an organization knows a breach is large but has not finished counting, it often files with HHS using a placeholder of 500 or 501, just enough to trigger the public listing, and updates it later. Cerner filed its own HHS report on June 17, 2025 with 501 people, and it had not been updated as of this week. ISMG reports that attorneys general in several other states, including South Carolina and Oregon, have also raised their resident counts without announcing it.

Oracle also told hospitals in 2025 that it would not notify patients directly, and that each covered entity had to decide whether the stolen data triggered HIPAA notification, according to BleepingComputer and ISMG. So the real count was split across dozens of separate filings. Union Health System, for example, reported 262,831 people to HHS. Adding those filings by hand is how researchers had reached "at least 410,000" in 2025, well short of 20 million.

What attackers did with it

In March 2025, Bloomberg and BleepingComputer reported that someone calling themselves "Andrew" was contacting affected hospitals and demanding millions in cryptocurrency, threatening to sell the data. That person claimed no link to a known ransomware or extortion group, and it is not known whether ransomware was used or this was purely data theft. Bloomberg reported that the FBI was investigating. Neither Oracle nor the Texas attorney general has named the hospitals involved. One press tally counted at least 29 hospitals and health systems that had publicly confirmed impact by October 1, 2026, a figure we could not confirm in a second source.

What a covered entity should check now

Six checks for a covered entity whose data a vendor holds: confirm scope, finalise your filings, map every copy the vendor keeps, get deletion certified, review vendor accounts, and write notification terms into the BAA

  1. Find out, in writing, whether your data sat on the affected legacy servers. Ask your Oracle Health account team for the notice date, the data sets involved and the patient count for your organization. If you received a notice in 2025 and filed with a placeholder, compare your count with what Oracle now reports to the states.
  2. Check that your own filings are final. If your HHS entry or a state filing still carries an estimate, update it. A vendor's own filing with a state attorney general, as in Texas, can count your patients before your filing does.
  3. Map every place your vendor keeps copies of your data, including environments outside the live system. EHR migrations leave behind source servers, staging databases, conversion extracts and backups. Ask for a list of every environment holding your PHI and the date each one will be retired.
  4. Get deletion in writing. A HIPAA business associate agreement (BAA) must require the vendor to return or destroy PHI when the contract ends. Push for the same after a migration: a dated certificate that the legacy copies are gone, and a contract clause that makes it a deliverable of the project.
  5. Review the accounts your staff hold in the vendor's systems. If Oracle's account is right, a customer login was the way in. List every account your organization has on vendor support portals and hosted environments, remove leavers, require multi-factor authentication (MFA), and ask the vendor for sign-in logs for your accounts covering January and February 2025.
  6. Write notification terms into the BAA. Specify who notifies patients, who files with HHS and the states, how fast the vendor must hand over a per-entity count, and who pays for notification and credit monitoring. Without such terms, the HIPAA default leaves patient notice with the covered entity, which is the position Oracle took in 2025.

The wider lesson

Migration projects are planned around the new system. The old one keeps running until someone decides it can be switched off, still holding a full copy of the data, often with fewer people watching it. Put every legacy environment in the asset inventory with an owner and a retirement date, and apply the same monitoring and access rules to it as to production until the day it is wiped.

Our compliance and audit readiness work covers vendor data maps and BAA terms like the ones above, and our attack surface management service keeps track of systems that should have been retired but are still reachable. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: BankInfoSecurity (ISMG), Becker's Hospital Review, Techzine, Gizmodo, eSecurity Planet, teiss, BleepingComputer (2025), GovInfoSecurity (2025), HIPAA Journal, HHS breach notification rule.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.