![]()
A cyberattack against Oracle Health last year exposed the personal data of almost 20 million people, according to a report from the Texas attorney general's office cited by Bloomberg. The breach hit a healthcare technology division of Oracle, affecting hospitals, clinics and government health systems across multiple states, including the Department of Defense and the Department of Veterans Affairs. As your consumer watchdog, I want you to know the risks here before scammers try to exploit them.
Oracle Health is the division formed after Oracle acquired healthcare technology company Cerner for $28.3 billion in June 2022. According to Bloomberg, the breach occurred after Jan. 22, 2025, and Oracle began alerting some customers in March of that year. Oracle told customers that attackers targeted older Cerner servers before their data could be migrated to Oracle's cloud storage. UK cybersecurity firm CyPro said the hacker compromised customer credentials to access two Cerner servers and copy patient data from them.
Neither Oracle nor the Texas attorney general's office named which specific hospitals or providers were affected. CyPro said at least 29 hospital and health systems have reported being affected. Of the nearly 20 million people impacted, 3 million were in Texas, according to the report.
Christus Health, a nonprofit healthcare system in Texas, and Tri-City Medical Center in California both confirmed they were affected. They said stolen data could include names, Social Security numbers, doctors' names, diagnoses, medicines and test results, Bloomberg reported.
How to spot it
- Scammers may use stolen details like your name, address or medical history to make fraudulent calls or messages sound convincing
- Watch for contact claiming to be from an insurance company or medical provider asking for sensitive information or demanding payment
What to do if it happened to you
- Christus said affected patients will receive letters about the incident and a complimentary two-year membership to credit monitoring and identity protection services
- If someone claiming to be from insurance or a medical provider asks for sensitive information or payment, hang up and call your provider back at a number you already know, such as the one on your insurance card, according to Cliff Steinhauer of the National Cybersecurity Alliance
- Find out exactly what data of yours was taken and enroll in any identity or credit monitoring offered
- Monitor your credit reports, financial accounts and healthcare statements for anything unfamiliar
- Consider freezing your credit with all three major credit reporting bureaus as a precaution, Steinhauer advised
CNET reached out to both the Texas attorney general's office and Oracle but did not receive an immediate response.
Source: CNET