Oracle Health (Cerner) Data Breach Hit Nearly 20 Million People: What to Do If You’re Affected

A Texas attorney general report puts the 2025 breach of legacy Oracle Health (Cerner) servers at nearly 20 million people, with Social Security numbers and medical information exposed. Here’s how to tell if you’re affected and how to protect yourself.

By Oscar Leiva

4–5 minutes
Illustration of a medical records folder and stethoscope next to an open padlock, with data leaking out, representing a health data breach

Last updated: October 9, 2026

The quick answer

A 2025 hack of old Cerner servers run by Oracle Health exposed data on nearly 20 million people, according to a Texas attorney general report first reported by Bloomberg, including names, addresses, Social Security numbers and medical information. If you were a patient at a hospital or clinic that used Cerner systems, watch your mail for a notification letter, verify it through your provider, and consider freezing your credit and checking your medical and insurance statements.

What happened

Cerner, an electronic health records company that Oracle bought in 2022 and now runs as Oracle Health, serves hospitals and health systems across the US. In early 2025, attackers used compromised customer credentials to reach legacy Cerner servers holding patient data that had not yet been moved to Oracle’s newer cloud. Reporting based on Oracle’s notification letters says the unauthorized access began around January 22, 2025, and that Oracle became aware of it around February 20, 2025.

The incident surfaced publicly in March 2025. At the time, Oracle said its Oracle Cloud service had not been breached, and it later told affected parties that the intrusion involved older Cerner data servers. What’s new this week is the scale: on October 5, 2026, Bloomberg reported that a Texas attorney general filing puts the total at nearly 20 million people, with close to 3 million of them in Texas. Oracle had not previously disclosed a total and declined to comment to Bloomberg.

The FBI investigated the attack, and reports say the data was used in extortion attempts against medical providers. Oracle Health also faces lawsuits over the incident.

What changes for you

Exposed Social Security numbers combined with names and addresses are exactly what criminals need to open credit in your name or file a fake tax return. Medical information adds another risk: medical identity theft, where someone uses your details to get care or bill insurance, which can leave false entries in your health records.

Because the breach happened in 2025, some people received letters months ago, and others may not have connected a letter from their hospital to this incident. Patients typically hear from the healthcare provider or from Oracle Health, not from a third party, which matters for spotting scams.

Steps to protect yourself

  1. Check whether you’re affected. Look for a notification letter in your mail. If you’re unsure, call your hospital or clinic using the number on its official website or a past bill, and ask whether it used Cerner systems and whether your data was involved.
  2. Use any protection offered in the letter. If your letter includes free credit or identity monitoring, enroll through the official site it names, after confirming the letter is genuine with your provider.
  3. Freeze your credit. In the US, a credit freeze is free at each of the three bureaus: Equifax, Experian and TransUnion. It blocks new accounts from being opened in your name, and you can lift it temporarily when you need to apply for credit.
  4. Read your health and insurance statements. Look for visits, prescriptions or procedures you don’t recognize on Explanation of Benefits forms and patient portals. Report anything unfamiliar to your insurer and provider.
  5. Protect your tax return. US taxpayers can request an Identity Protection PIN from the IRS, which stops someone else from filing a return with your Social Security number.
  6. Watch for breach-themed scams. Be suspicious of calls, texts or emails that mention the breach and ask for personal details, payment or a link click. Contact the organization directly instead.
  7. Report identity theft quickly. In the US, IdentityTheft.gov walks you through a recovery plan if you find fraudulent accounts.

Who it affects and who it doesn’t

SituationWhat it means
You received a notification letterYour data was involved. Follow the steps above, starting with a credit freeze.
You were a patient at a US hospital or clinic using Cerner systemsYou may be affected. Confirm with the provider directly.
Your provider uses a different records systemThis specific incident is unlikely to involve you, but the general precautions are still good practice.
You only use Oracle software or cloud services as a consumerThis breach involved legacy Cerner health data servers, not Oracle’s consumer products.

Scammers often time their campaigns to big breach headlines. Our guide to spotting real deals and avoiding scams covers the same warning signs to look for in messages.

FAQ

How many people were affected by the Oracle Health breach?

Nearly 20 million people, according to a Texas attorney general report cited by Bloomberg. Close to 3 million of them are in Texas. Oracle has not publicly confirmed a total.

What information was exposed?

Reports based on the filing list names, addresses, Social Security numbers and medical information. The exact data can vary by person, so check your letter.

I got a letter about this months ago. Should I still act?

Yes. Stolen Social Security numbers don’t expire, so a credit freeze and regular statement checks are worthwhile even long after a breach.

Sources

About the author

Oscar Leiva

Oscar edits Knowloft’s guides from San Salvador, El Salvador, as part of Edén Studio, a creative and software studio. Each guide is built from official data and current local prices, cites its sources and is updated when costs or rules change. Read our editorial standards.

Leave a Reply

More guides

Discover more from Knowloft

Subscribe now to keep reading and get access to the full archive.

Continue reading