Nearly 20M people had their medical records taken in an attack on Oracle Health, with about 3M of them in Texas, according to a filing the state's attorney general has now published. That is the first confirmed scale for a breach Oracle told hospital customers about in March 2025 without putting a number on it. The gap between the warning and the count is almost 20 months.
Oracle Health is the former Cerner, bought by Oracle in 2022 and one of two companies that between them hold the patient records of most American hospitals. The attack did not reach Oracle's modern systems.
Someone obtained a customer's login details and used them, at some point after 22 January 2025, to get into old Cerner servers holding data that had not yet been moved across to Oracle's cloud. Oracle found out on 20 February 2025 and has consistently denied that its cloud infrastructure itself was compromised.
What the attacker took is the part that matters to the people in the filing. The records included Social Security numbers, names and addresses alongside medical detail: treating physicians, diagnoses, medications and test results.
An individual using the alias Andrew then demanded millions of dollars in cryptocurrency from hospitals to stop the data being leaked or sold, claiming no affiliation with any known ransomware group. The Federal Bureau of Investigation has been examining those demands, and around 80 hospitals were caught in the original compromise.
A State Law Produced The Number
The reason anyone can state a figure today is a Texas statute that has nothing to do with healthcare. Since September 2021, any organisation whose breach affects 250 or more Texas residents has had to notify the state attorney general. The attorney general publishes the notice on a public list within 30 days, and removes it a year later if nothing further is reported.
Counting Texans meant counting everyone, because the 3M figure for the state could not be produced without a total. Once that total existed in a public filing it stopped being Oracle's to withhold, and the threshold is low enough that almost any national breach crosses it.
No federal mechanism works quite that way. American health regulators do publish large breaches, but the notice flows through the hospital rather than the technology supplier. A national figure for a vendor incident can therefore sit unstated for most of two years. Europe took the opposite approach for connected products, writing reporting duties into its cyber law rather than leaving disclosure to each company's judgement.
Oracle Left Hospitals To Tell Patients
How the notification was handled became its own story among the affected health systems. Oracle sent its warnings on plain paper rather than company letterhead, signed by Seema Verma, the executive who runs Oracle Health, and directed customers to telephone its chief information security officer rather than put anything in email.
The company agreed to pay for credit monitoring and for the mailing vendors, and declined to send notifications to patients on the hospitals' behalf. That split follows the structure of American health privacy law, where the hospital is the regulated entity holding the relationship with the patient and the software supplier is a contractor to it.
The practical effect was that hundreds of health systems each had to run their own notification exercise over a breach that happened on somebody else's servers. Several of them went to court over exactly that.
Hospitals Cannot Contract It Away
The litigation produced a ruling in July 2026 that matters well beyond this incident. Eight health systems, among them Baptist Health South Florida, Mosaic Life Care and Tallahassee Memorial, argued that liability belonged to Oracle because the intrusion happened on Oracle's systems. The court rejected that defence, holding that providers cannot be absolved of their duty to protect patient data simply by contracting the work to a third party.
The same ruling cut in the other direction too, because patients of certain systems can now pursue Oracle directly for breach of contract, as third-party beneficiaries of the agreements between hospital and vendor. That route did not previously exist in practice.
Both findings together describe a sector where exposure now sits at both ends of the contract. The hospital cannot point at its supplier, and the supplier cannot hide behind the hospital's relationship with the patient.
The Data Was Caught Mid-Migration
The detail easiest to overlook is where the records were sitting when they were taken. They were on legacy Cerner servers used for data migration, holding information on its way to Oracle's cloud and not yet there. Oracle paid $28.3B for Cerner in June 2022 and has spent the years since moving customers onto its own infrastructure, which means a large quantity of hospital data has been living in that in-between state.
Migrations create exactly this condition. Old systems stay running longer than anyone intends, and credentials issued years earlier still work. The security attention follows the new platform rather than the one being emptied.
Oracle Health was under commercial pressure through the same period. KLAS Research put Epic at 42.3% of the American hospital records market for 2024, up from 39.1%, against Oracle Health at 22.9%, down from 23.4%. Oracle lost 74 hospitals and 17,232 beds over the year, while Epic gained 176.
Twenty Months To A Number
What changed this week is not what happened, which has been known since early 2025, but how many people it happened to. The count arrived because one American state requires breaches to be published rather than merely reported, and because Oracle had enough Texan patients in the affected records to trigger it. Had the attack landed on a differently distributed set of hospitals, the figure might still be unstated.
The case continues on both fronts. Hospitals are defending claims they argued were not theirs to answer, and Oracle faces direct claims it argued patients had no standing to bring. The records themselves have been in someone's possession for 20 months.