Personal data concerning nearly 20 million individuals was compromised in a cybersecurity breach at Oracle Health, based on details made public by the Texas attorney general. The security event exposed sensitive details such as medical records, addresses, and Social Security numbers.
Oracle Health breach affected nearly 20 million people
The full magnitude of the cyberattack emerged when the Texas Attorney General revealed that Oracle reported the theft of information impacting nearly 20 million people. Among those affected, approximately 3 million were Texas residents.
In March 2025, Oracle notified certain healthcare clients about the breach, stating at the time that unauthorized access to its systems occurred after January 22. The company, however, did not specify the total number of patients or electronic health records impacted.
Oracle has chosen not to comment on this recent disclosure, and the Texas attorney general’s office did not reply to inquiries seeking comment. According to a Reuters report from March 2025, the FBI was probing the cyberattack, including claims that hackers tried leveraging stolen patient records to coerce medical providers into paying ransoms.
Previously, Oracle stated that the breach impacted legacy Cerner infrastructure while emphasizing that its Oracle Cloud Infrastructure remained secure.
Sensitive Medical Information Exposed
The specific categories of exposed data differed from patient to patient. Impacted healthcare providers reported that the compromised files potentially encompassed names, medical record numbers, Social Security numbers, treating physicians, diagnoses, test results, and prescribed medications.
According to Tri-City Medical Center, the breach potentially affected medical files containing treatment specifics, whereas CHRISTUS Health noted that the compromised data could involve patient details and laboratory records. Both entities verified that they were among the numerous healthcare institutions impacted by the Oracle Health security incident.
Also Read: Why AI Agents Need Cybersecurity Memory to Protect Enterprise Data




