NEWS
Oracle’s Unfinished Cerner Move Exposed 20 Million People
Two leftover Cerner servers held files for nearly 20 million people. Texas published the count more than 18 months after the 2025 copy job.
A 2025 Oracle Health breach took personal data from nearly 20 million people, the Texas attorney general’s office said in an October 2 filing. About 3 million of them live in Texas. Social Security numbers, addresses and medical files were among the records Oracle told investigators were copied.
The copied files sat on leftover Cerner machines Oracle had not finished moving after it bought the hospital software maker in 2022. Oracle has said its cloud systems were not reached.
Two Obsolete Cerner Servers, Still Online
UK firm CyPro, reviewing the Texas filing and hospital notices, said an outsider used stolen customer logins to reach two obsolete servers still running leftover Cerner software. Once inside, the attacker copied patient files to a machine they controlled. CyPro said Oracle has described Oracle Cloud Infrastructure and customer cloud environments as untouched.
Hospital notices put the first access as early as January 22, 2025. In a March 2025 note to customers, Oracle Health said it became aware of the event on or around February 20, 2025, and that Cerner data on old kit not yet moved to Oracle Cloud had been reached. Seema Verma, then executive vice president and general manager of Oracle Health, signed that note. The company told hospitals it would not write to patients itself. Each provider had to decide what U.S. health-privacy rules required, with Oracle offering help to identify people and to draft letters.
Even though Oracle says its cloud infrastructure was unaffected, data held on two legacy servers was sufficient to expose information potentially belonging to millions of patients.
Rob McBride, founding partner, CyPro
McBride, a former Deloitte adviser who now runs CyPro’s managed service line, wrote that old kit remains a third-party risk while a vendor is still moving clients. The 2025 copy job is that problem in plain form: the product Oracle sells as the destination was not the store the thief opened.
Texas Forced the 20 Million Count Into View
Oracle told some hospital customers about the event in March 2025 and did not put a headcount on those first notes. The figure that now sits on the public record is the one Oracle later gave Texas. After the October 2 filing became public, Oracle declined to comment on the number. The attorney general’s office did not add a statement of its own.
Texas requires a company to file Texas data-breach reports to the attorney general when a breach of system security hits 250 or more Texans, as soon as practicable and no later than 30 days after discovery. The office then lists those reports. That listing, not a new Oracle press note, is how nearly 20 million people entered the story in October 2026.
The Texas total is being read in some corners as a fresh confession. It is a state publication of a count tied to a 2025 copy job. CyPro noted that as of October 6, 2026, the same combined total had not yet shown up in public files from the U.S. Department of Health and Human Services Office for Civil Rights, and said the Texas number may be an aggregate across many Oracle Health customers rather than a single hospital’s roster.
FROM THE CERNER PURCHASE TO THE TEXAS FILING
- June 8, 2022: Oracle closes its purchase of Cerner and folds the firm into Oracle Health.
- January 22, 2025: Hospital notices say an outsider first reached leftover Cerner systems on or after this date, using stolen customer logins.
- February 20, 2025: Oracle Health becomes aware of the event, starts an inquiry, and brings in outside specialists and federal law enforcement.
- March 2025: Oracle alerts some healthcare customers. Public reporting follows on March 28, 2025. The FBI looks at the case and at later attempts to squeeze hospitals.
- August 14, 2025: Public notices had named about 14,485 people, CyPro found, a fraction of the later Texas total.
- October and December 2025: Oracle sends hospitals lists of patients whose files may have been copied. CHRISTUS Health, among others, then starts its own letters.
- October 1, 2026: At least 29 hospital and health systems have said publicly they were hit, CyPro counted.
- October 2, 2026: Texas publishes Oracle’s disclosure that nearly 20 million people, including about 3 million Texans, had information taken.
That span from the first public reports on March 28, 2025, to the Texas filing is more than 18 months. The live complaint around the filing is the wait, not a second hack.
Which Hospitals Have Named Themselves
Neither Oracle nor the Texas filing named every hospital, clinic or agency in the blast radius. Oracle Health’s customers include regional hospitals and clinics, plus the Department of Defense and the Department of Veterans Affairs. A Veterans Affairs spokesperson said in March 2025 that the department was not affected. How Defense systems sit in the same event has not been spelled out.
CyPro counted at least 29 hospital and health systems that had acknowledged an impact by October 1, 2026. Earlier sector reporting, the firm noted, had suggested as many as 80 hospitals could be involved. Those are different counts: systems that have spoken, versus an earlier hospital-level estimate that was never officially consolidated.
Two of the systems that did publish patient pages sit at opposite ends of the calendar Oracle kept.
TWO HOSPITAL NOTICES, MONTHS APART
| Health system | When the patient list arrived | What the letters offer |
|---|---|---|
| CHRISTUS Health (Irving, Texas) | December 9, 2025, after Oracle first told the system in October 2025 | Two years of credit monitoring and identity protection |
| Tri-City Medical Center (Oceanside, Calif.) | Verified February 12, 2026 | Two years of credit monitoring and/or minor identity protection |
The CHRISTUS Health notice on the incident says Oracle Health had supplied lab-service systems the nonprofit previously used. CHRISTUS told patients the event did not hit its current IT systems or clinical work. People whose files were involved are to get a mailed letter, with a help line at 833-918-1131.
The Tri-City Medical Center incident notice, posted by Sharp HealthCare, uses the same outline: leftover Oracle Health/Cerner systems, no hit on Tri-City’s own network, letters in the mail. Questions go to 1-855-356-3059, with engagement number B164978.
The Cloud Pitch From the 2022 Cerner Buy
Oracle announced on June 1, 2022, that antitrust clearance was in and described an all-cash tender of about $28.3 billion at $95.00 a share. A follow-up on June 7 said a majority of Cerner shares had been tendered and that the deal would close on June 8. Cerner would sit as an industry unit inside Oracle, later branded Oracle Health.
The pitch at the time was speed. Oracle said Cerner’s clinical systems already ran on Oracle’s database, which would let the company modernize those products and move them onto its cloud. Chairman and chief technology officer Larry Ellison was booked to walk through a new suite of cloud health applications as soon as the deal closed.
Three years later, the files in the Texas filing were still on the old side of that move. Stolen customer credentials, not a newly published software bug, opened the door. CyPro found no product version numbers in the public record because the path in was a login, not a patch gap with a proof of concept.
How one customer’s logins unlocked files from many organizations has not been explained in the notices hospitals have posted. That unanswered point sits next to the leftover servers: a shared migration environment can turn one stolen password into a multi-hospital copy job.
Letters Waited Months After the Copy Job
Federal investigators asked Oracle Health and the affected organizations to hold patient letters while they worked the case, CHRISTUS and Tri-City both say. Oracle then dribbled out patient lists in the fall of 2025. CHRISTUS did not get its roster until December 9, 2025, about 10 months after Oracle says it learned of the event. Tri-City’s list was verified on February 12, 2026, almost a year after that February 20, 2025 discovery date.
Hospitals have also said Oracle directed much of the follow-up onto phone calls with its chief information security office rather than written reports, and that early customer notes went out on plain paper rather than letterhead. Oracle did agree to pay for credit monitoring and for a mailing vendor, while leaving each hospital to send its own letters.
A person using the name Andrew then tried to squeeze hospitals, according to people who dealt with the aftermath, demanding millions of dollars in cryptocurrency to keep the stolen files from being leaked or sold, and putting up public websites to raise the pressure. That person has not claimed a known ransomware brand. A separate March 2025 claim involving an actor using the handle rose87168 and alleged Oracle Cloud login data is a different episode. Oracle denied a breach of Oracle Cloud in that case.
WHAT WE KNOW
- The Texas count: Oracle disclosed to the state that nearly 20 million people, including about 3 million Texans, had information taken.
- The path in: Stolen customer logins reached two obsolete leftover Cerner servers, and files were copied off those machines.
- The cloud claim: Oracle says Oracle Cloud Infrastructure was not breached.
- The letters: Federal investigators asked organizations to delay patient notice, and hospitals then mailed after Oracle sent lists.
WHAT IS UNCONFIRMED
- The full roster: Oracle and Texas have not published a complete list of hospitals, clinics or federal programs in the copy.
- The HHS match: CyPro said the 20 million figure had not yet been independently corroborated on the public OCR breach tool.
- The actor: No public set of technical indicators has been released, and Andrew’s identity has not been confirmed in hospital notices.
Proposed class actions over the event are pending in the U.S. District Court for the Western District of Missouri, where Oracle Health’s Cerner operations have long been based. No class has been certified, and there is no settlement portal. Sites that ask patients for personal data in the name of an Oracle Health payout are not part of any court process that has been completed.
What a Stolen Lab Record Can Do
CHRISTUS says the type of information varies by person and can include names, Social Security numbers, and material inside laboratory records. The health system was explicit that the copied lab data is all from before February 2025, so current lab results were not in the set it was given.
DATA CHRISTUS SAYS MAY HAVE BEEN IN THE COPY
- Identity: Names and Social Security numbers.
- Record keys: Medical record numbers used inside the old lab systems.
- Clinical detail: Doctors, diagnoses, medicines and test results.
- Lab files: Laboratory orders and blood-bank records, all dated before February 2025.
Tri-City’s list is broader on the clinical side and can include images plus care and treatment notes, again varying by patient. A Social Security number plus a diagnosis is a working kit for a convincing phone scam. Passwords can be reset. A blood-bank file and a medication list cannot.
If someone contacts you claiming to be from insurance or a medical provider and asks for sensitive information or demands payment, hang up and call your provider back at a number you know belongs to them (like the back of your insurance card).
Cliff Steinhauer, director of information security and engagement, National Cybersecurity Alliance
Steinhauer also told people caught in this event to learn what was taken, use any monitoring on offer, watch credit reports and medical statements, and freeze credit at all three major bureaus as a preventative step.
Freeze the File at Equifax, Experian and TransUnion
CHRISTUS and Tri-City are mailing two years of credit monitoring. That product watches for some new-account fraud. A freeze goes further. The Federal Trade Commission’s consumer advice on free credit freezes at all three bureaus is that a freeze blocks new credit in your name until you lift it, costs nothing, and does not change a credit score. You still have to contact Equifax, Experian and TransUnion separately. Online or phone requests must be placed within one business day. You can lift a freeze the same way when a lender needs a look.
A freeze does not close a hospital bill that has already been redirected, and it does not stop a caller who already has a diagnosis and a date of birth. It does stop a stranger from opening a card or a loan on the back of a Social Security number pulled from an old Cerner box. Patients who got a letter should use the engagement number on it, then treat the two-year monitoring as a supplement, not the whole defense.
Oracle Health’s leftover servers are now a matter of public count because Texas makes companies file one. The cloud those records were supposed to occupy, on Oracle’s account, never had to open.
Disclaimer: This article is news reporting and analysis of a disclosed data event and is for information only. It is not medical advice, not legal advice, and not a guide to any claim, lawsuit or credit product, and it does not tell any reader whether they are in the affected group. Anyone who thinks their health or financial records were copied should use the phone number on an official hospital letter if they received one, and should speak with a qualified attorney or a certified identity-theft counselor before taking legal or credit steps. Headcounts, hospital lists, case status and monitoring offers reflect the Texas filing, company notices and other sources cited here as of the dates on those documents and can change as more providers write to patients or as courts act.
-
NEWS1 month agoInstinct’s $2.5 Billion Raise Still Binds the User as Agent
-
NEWS1 month agoCity’s £125m Enzo Deal Caps a £327m Midfield Rebuild
-
NEWS1 month agoCSIRTs Inherit Europe’s Missing security.txt Before Article 14
-
BUSINESS1 month agoTreasury’s First Iran Bank Shot Lands on an Ally
-
NEWS1 month agoMeta’s Teen Settlement Leaves Chat Off the Clock
-
BUSINESS2 months agoBerkshire Anchors Alphabet’s Record Raise With a $10 Billion Check
-
NEWS1 month agoOpenAI Codes a Persistent Agent the Week Persistence Backfired
-
ENTERTAINMENT2 months agoRolex Made Drake the Daytona It Fights Jewelers Over
