What if a hospital you visited years ago lost your medical records, and you only found out how big the damage was this week? That’s exactly where millions of Americans are right now. The Oracle Health data breach, which began in early 2025, exposed the personal and medical data of nearly 20 million people, according to a disclosure from the Texas attorney general.
The stolen data includes names, Social Security numbers, addresses and medical details such as diagnoses, medications and test results. If you received care from a hospital or clinic that used Oracle Health’s older Cerner systems, your information could be part of it. Here’s what happened, who’s affected and what you should do today.
| Key fact | Details |
|---|---|
| People affected | Nearly 20 million, including about 3 million Texans |
| Breach began | On or after January 22, 2025 |
| Systems hit | Legacy Cerner servers not yet moved to Oracle’s cloud |
| Data exposed | Names, Social Security numbers, addresses, doctors, diagnoses, medications, test results |
| Organizations affected | At least 29 hospitals and health systems, per Becker’s Hospital Review |
| How the number came out | Texas attorney general disclosure, reported by Bloomberg in October 2026 |
What happened in the Oracle Health data breach?
Let’s back up a little. In 2022, Oracle bought Cerner, one of the biggest electronic health records companies in the US, in a deal worth about $28 billion. Cerner’s systems power patient records at hospitals and clinics across the country.
Part of the plan was to move that data onto Oracle’s cloud. But not everything had moved yet. According to Oracle’s notice to customers, attackers got into “an old legacy server not yet migrated to the Oracle Cloud,” using stolen login credentials, and copied patient data out.
Sounds like a basic mistake, right? It is. Old servers with reused or stolen passwords are one of the most common ways attackers get in, and they’re exactly the kind of systems that slip through the cracks during a big migration.
The key takeaway here is simple: your data was only as safe as the oldest server holding it.
Why the 20 million number is only coming out now
Here’s the part that frustrates a lot of people. The breach itself isn’t new. Oracle began warning healthcare customers about it in March 2025, and some hospitals sent letters to patients later that year.
So why does the scale feel like fresh news? Because until now, nobody had published a total. The figure of nearly 20 million came from a breach report filed with the Texas attorney general, which Bloomberg reported on in early October 2026. It’s the first time a specific overall count has been made public.
Fast forward through the timeline and you can see how slowly this unfolded:
| Date | What happened |
|---|---|
| 2022 | Oracle completes its purchase of Cerner |
| January 22, 2025 | Earliest date of unauthorized access to legacy Cerner systems |
| March 2025 | Oracle begins alerting healthcare customers; reports surface of extortion attempts against hospitals |
| October 2025 | CHRISTUS Health says Oracle Health informed it of the incident |
| December 9, 2025 | CHRISTUS Health receives its list of affected patients |
| October 2026 | Texas attorney general’s report puts the total at nearly 20 million |
You see, in a third-party breach like this one, the vendor and the hospitals often split the job of notifying patients. That takes time. It also explains why you might be hearing about it from your hospital rather than from Oracle.
What data was exposed?
This is where the breach gets serious. Credit card numbers can be cancelled. Your medical history can’t.
According to notices from CHRISTUS Health and other providers, the exposed information can include:
- Identity details: names, addresses and Social Security numbers.
- Clinical details: physician names, diagnoses, medications and test results.
- Record details: medical record numbers, laboratory orders and results, and blood bank records.
Not every patient lost the same data. The mix depends on what your provider stored in the affected systems. CHRISTUS Health, for example, says the exposed data dates from before February 2025, and its current lab records weren’t affected.
“A stolen card number expires. A stolen diagnosis doesn’t. That’s why health data breaches hit harder.”
Who is affected?
The breach reaches far beyond one hospital. Becker’s Hospital Review reports that at least 29 hospitals and health systems were affected, and reporting from Bloomberg names regional hospitals, clinics and US government agencies among Oracle Health’s affected customers.
A few specific points worth knowing:
- Texas: about 3 million of the nearly 20 million people affected live in Texas.
- Named providers: CHRISTUS Health, Tri-City Medical Center and ChristianaCare have all published notices about the incident.
- Government agencies: the Department of Defense and Department of Veterans Affairs are among Oracle Health’s customers, but the VA said at the time that it wasn’t affected.
So how do you know if you’re one of them? Well, the most reliable sign is a letter from your hospital or health system. Many providers also post a notice page on their website with a dedicated call center number.
Was the stolen data used for extortion?
Unfortunately, yes, at least in attempts. The FBI investigated the attack, including efforts by the hackers to pressure healthcare organizations into paying ransoms to keep the data from leaking. Reports at the time described a threat actor emailing hospitals with multimillion-dollar demands.
Why does that matter to you? Because data stolen for extortion often ends up sold or leaked when the ransom isn’t paid. Even if nothing has surfaced in your name yet, it’s smart to act as if your details are out there.
The breach has also triggered legal action. Multiple class action lawsuits have been filed in federal court in the Western District of Texas.
What to do if your data was in the Oracle Health data breach
You can’t undo the breach. But you can make the stolen data far less useful to criminals. Here’s a practical plan.
1. Read your notification letter carefully
Your letter usually includes an engagement or enrollment code and details about free protection services. CHRISTUS Health, for example, is offering a complimentary two-year membership to credit monitoring and identity protection, with a toll-free line at 833-918-1131 (Monday to Friday, 8 a.m. to 8 p.m. Central). Use the number in your letter, not one from an unexpected email or text.
2. Freeze your credit with all three bureaus
A credit freeze stops anyone from opening new credit in your name. According to the FTC, it’s free to place and lift, and it doesn’t affect your credit score. You’ll need to contact Equifax, Experian and TransUnion separately.
3. Add a fraud alert if you want an extra layer
A fraud alert tells lenders to verify your identity before opening an account. An initial alert lasts one year, and you only need to contact one bureau, which then notifies the other two.
4. Watch your medical statements, not just your bank
Medical identity theft is the risk that’s easy to miss. Look for bills or Explanation of Benefits statements for care you never received, collection notices for unfamiliar medical debts, or warnings that you’ve hit your insurance limits. If you spot something, ask your providers for your records and report errors in writing.
5. Be suspicious of “helpful” calls and emails
Breach victims are prime targets for follow-up scams. Criminals know which hospitals were affected and may pose as your provider, your insurer or a lawyer. If someone contacts you out of the blue, hang up and call back using a number you trust. Our guide to deepfake-as-a-service scams shows how convincing these calls have become.
6. Report identity theft fast if it happens
If you find fraud, go to IdentityTheft.gov or call 1-877-438-4338 to report it and get a personal recovery plan. Acting quickly limits the damage.
The key takeaway here is simple: a credit freeze plus regular statement checks covers most of the risk, and both cost you nothing.
How this compares with other recent breaches
The Oracle Health breach is part of a rough stretch for personal data. In just the past few weeks, Technology Ripple has covered the Pentagon data breach that exposed 3 million people and the ShinyHunters FBI breach.
By headcount, Oracle Health dwarfs the Pentagon incident: nearly 20 million people, compared with about 3 million. But size isn’t what sets the Oracle case apart. The medical data is. That makes it more personal, and potentially more damaging, than a typical password or email leak.
What Oracle and hospitals are doing
Oracle has said little in public. Early on, the company denied that its cloud had been breached, saying “There has been no breach of Oracle Cloud.” It later told customers that the incident involved Cerner data on an old legacy server. Oracle declined to comment on the latest disclosure, according to Bloomberg.
Hospitals, meanwhile, have carried most of the patient-facing work. CHRISTUS Health says its current systems weren’t affected, that it’s mailing notifications, and that it’s tightening cybersecurity reviews of third-party partners.
Here’s the catch. Your hospital can choose a vendor, but you can’t. That’s why it’s worth taking the protective steps above, no matter what any company says next.
Frequently asked questions
Nearly 20 million people, according to a report filed with the Texas attorney general. About 3 million of them live in Texas.
Depending on the patient, the data can include names, addresses, Social Security numbers, physician names, diagnoses, medications, test results and medical record numbers.
The clearest sign is a notification letter from your hospital or health system. Many affected providers, including CHRISTUS Health and ChristianaCare, also posted notice pages with contact details.
Yes. Oracle bought Cerner in 2022, and the business now operates as Oracle Health. The breach involved older Cerner servers that hadn’t yet been moved to Oracle’s cloud.
That isn’t settled. Class action lawsuits have been filed in federal court in Texas, but there’s no public settlement yet. Keep your notification letter in case a settlement opens claims later.
It’s a smart move if your Social Security number was exposed. A credit freeze is free, doesn’t affect your score and blocks new accounts from being opened in your name.
The bottom line
The Oracle Health data breach is a reminder that your most personal information often lives on systems you’ll never see. You can’t control a vendor’s old servers, but you can control what happens next.
Freeze your credit, read every medical statement, and treat surprise calls with healthy suspicion. If you want to go further, our guides on how to tell if your phone is hacked and how AI helps detect and prevent fraud will help you stay a step ahead.
Patient notice details are from CHRISTUS Health’s official Oracle Health data incident notice.
