Oracle data breach exposes medical records of 20 million people
What's the story
A major cybersecurity breach at Oracle Corp.'s healthcare division has exposed the personal information of nearly 20 million people. The Texas Attorney General's office revealed that the attack resulted in the theft of sensitive data such as Social Security numbers, addresses, and medical information. Among those affected are around three million Texans.
Company statement
Oracle informed customers about the cyberattack in March 2025
In March 2025, Oracle informed some of its customers about the cyberattack, which took place after January 22.
However, the company did not disclose how many electronic health records were affected by the breach.
The tech giant's healthcare clients include regional hospitals and clinics as well as the Department of Defense and Veterans Affairs.
It remains unclear how this breach may have impacted these federal government customers.
Impact assessment
Breach severity differed from patient to patient
The Texas medical system Christus Health and California's Tri-City Medical Center have confirmed that the severity of the breach differed from patient to patient.
The compromised information could include names, Social Security numbers, doctors, diagnoses, medicines, and test results, among other things.
Both organizations were among many Oracle customers affected by this massive data breach incident.
Ongoing investigation
Hackers attempted to extort ransoms from medical companies
The FBI investigated the cyberattack and the hackers' attempts to extort ransoms from medical companies.
In its March 2025 disclosure, Oracle revealed that the attackers accessed older servers from Cerner Corp., which it acquired in 2022 for $28 billion.
The company also clarified that this data had not yet been transferred to its cloud storage service.