The personal and medical information of nearly 20 million individuals has been compromised following a cyberattack on Oracle Health's legacy Cerner systems. This breach, which occurred early last year, was recently reported by the Texas attorney general and marks a significant increase from earlier estimates. Oracle Health, formerly known as Cerner before its acquisition in June 2022, has not publicly commented on the number of affected individuals.

Oracle began notifying healthcare customers in March 2025, stating that they discovered unauthorized access to some Cerner data around February 20, 2025. The breach involved stolen customer credentials used to access a legacy server, allowing data to be copied to a remote server. This incident has been linked to a threat actor known as 'Andrew', who demanded cryptocurrency ransom to prevent the data from being leaked or sold.

The breach has affected millions across several states, including nearly 3 million Texans, and tens of thousands in South Carolina and Washington. Notifications to state regulators indicate the breach occurred between January 22 and April 1, 2025, with the discovery made on February 20, 2025. The compromised data includes sensitive personal and medical information such as Social Security numbers, medical records, and treatment details.

If confirmed, this breach could be one of the largest healthcare data breaches in the United States. It highlights the urgent need for enhanced cybersecurity measures in the healthcare sector to protect against similar incidents.