Excerpt from Bloomberg, Published on October 5, 2026
A cybersecurity breach at Oracle Health in 2025 compromised personal information belonging to nearly 20 million people, according to information released by the Texas Attorney General and reported by Bloomberg. The exposed information included sensitive health and personal data, with approximately 3 million affected individuals reportedly located in Texas.
The Oracle Health data breach involved legacy servers associated with Cerner, the electronic health records company Oracle acquired in 2022. The affected servers contained healthcare information that had not yet been migrated to Oracle’s newer cloud infrastructure. Attackers reportedly gained access to the legacy systems using compromised customer credentials.
The compromised information reportedly included Social Security numbers, physical addresses, and medical information. The exposed healthcare records could contain details such as treating physicians, diagnoses, medications, and test results, depending on the affected individual and healthcare organization. Oracle had notified some healthcare customers in March 2025 that unauthorized users had accessed legacy Cerner servers after January 22, 2025. The company subsequently identified the incident and notified affected organizations. The newly reported figure of nearly 20 million people provides a broader view of the potential scale of the breach than the figures previously associated with the incident.
The incident did not involve a reported compromise of Oracle’s newer cloud infrastructure. Instead, the breach highlighted risks associated with legacy systems that continued to store sensitive healthcare information during technology and cloud migration. The use of compromised credentials also demonstrates the importance of protecting accounts that retain access to older systems and sensitive data.
The Oracle Health data breach highlights the security challenges organizations can face when legacy infrastructure remains operational during migration. Healthcare organizations handling sensitive patient information need effective access controls, credential protection, monitoring, vulnerability management, and appropriate safeguards for data stored across both legacy and modern environments.
The full scope of the incident and the organizations affected remain under scrutiny. The breach serves as a reminder that systems scheduled for migration or replacement still require strong security controls for as long as they contain or provide access to sensitive information.
For additional information, visit Bloomberg.




