Oracle Health Breach of Old Cerner Servers Exposed Data on Nearly 20 Million People, Including 3 Million Texans
HPV Vaccination Before First Pregnancy Linked to 15% Lower Odds of Very Preterm Birth in Swedish Registry DataA BMJ study of 624,713 Swedish births linked HPV vaccination before pregnancy to 15% lower odds of very preterm birth. What families should know. Ozempic and Zepbound Makers Report Slower Aging Clocks, but Unreviewed Data Do Not Prove Patients Age SlowerNovo Nordisk and Eli Lilly say GLP-1 drugs slowed aging clocks, but the data are early and unreviewed. Here is what patients should know. Had Gestational Diabetes or Postpartum Depression? Large Study Links Pregnancy History to Later Heart and Kidney RiskA study of 1.4 million women links pregnancy complications to later heart, diabetes, and kidney risk. What to tell your doctor at checkups. Dementia Patients Overweight or Obese at Diagnosis Had Up to 27% Lower Death Risk, Raising Caregiver Nutrition QuestionsA national study of 4,523 U.S. adults with dementia linked higher weight at diagnosis to longer survival. Here is what it means for caregivers. Mental Health Frequent Mental Distress in Adults 18 to 29 Climbed From 12.7% to 21.3% Since 2012 Despite Recent DeclinesCDC data show 1 in 5 adults 18 to 29 report frequent mental distress, up from 2012 but down two years straight. Where to find help today. Veterans’ PTSD and Depression Relief After Ibogaine Largely Held for a Year in Small Stanford Study of 30Most veterans in a small Stanford ibogaine study kept their PTSD gains at 12 months, but the study had no control group, and heart risks remain. Hymns and Childhood Songs Topped the Phantom Music 81 Patients Heard, and Hearing Loss Was Often Not the CauseA Dutch study of people who hear music that isn’t playing found that half had no documented hearing loss, and most found the music a burden. Childhood Abuse Linked to Brain Structure Differences in 3,711 Brain Scans, with Stronger Patterns Seen in Young WomenA UCLA-led study of 3,711 brain scans links childhood abuse to brain structure differences. It shows an association, not a cause, and needs follow-up. Innovation Tech and AI Firms Lobbied Federal Health Officials in a CMS-Run Slack as Medicare Promotes Commercial Health AppsA KFF Health News probe found tech firms lobbying officials in a CMS-run Slack. What it means for seniors using Medicare-promoted health apps. CDC Closes Angola and South Sudan Offices, with Zimbabwe Next as U.S. Ties Health Aid to Country DealsThe CDC shut its Angola and South Sudan offices Oct. 1, with Zimbabwe next. Here is what the new aid deals require and what they mean for U.S. travelers. Vanderbilt Surgeons Transplant Children as Young as 2 Days Old Using Donor Hearts Recovered with Cold Oxygen FlushVanderbilt surgeons used a cold oxygen flush called REUP to recover donor hearts for children as young as 2 days old. Results are early but promising. Rhapsido Becomes First FDA-Approved Treatment for Hives Triggered by Scratching, but Fewer Than a Third Fully ClearedThe FDA approved Rhapsido for symptomatic dermographism, hives set off by scratching. In its trial, 29.3% fully cleared vs. 14.0% on placebo. Healthy Living Pallone Bill Would End Surprise Billing Arbitration in 2028 and Set Out-of-Network Pay at Insurers’ Median RatesA new House bill would replace No Surprises Act arbitration with a median in-network payment standard. What it could mean for premiums and bills. Carnivore Dieters’ LDL Cholesterol Jumped Nearly 100 Points in a German Study, and a 2026 Review Won’t Endorse the Diet Long TermA German study saw carnivore dieters’ LDL jump nearly 100 points, and a 2026 review says the meat-only diet can’t be recommended long-term. Twice as Many U.S. Hospitals Closed as Opened From 2010 to 2025, Leaving More Than 24,000 Fewer BedsA JAMA analysis finds 432 U.S. hospitals closed and 216 opened since 2010, with urban and rural areas hit at similar rates. What it means for care. Three Colorado Women Developed Blurred Vision and Weakness After Unapproved Botulinum Toxin Shots at a Medical SpaA CDC report links symptoms in three Colorado women to an unapproved botulinum toxin product used at a medical spa. What patients should ask first. Covid – 19 FDA Proposes Requiring Companies to Report Food Additives That Now Reach Grocery Shelves Without Federal ReviewFDA has released its proposed GRAS rule requiring companies to notify the agency about food additives. Here is what the proposal does and does not do. Federal Regulators Warn Some Hair Dryer Brushes Lack the Part That Stops ElectrocutionCPSC warns hair dryer brushes sold on Walmart.com and TikTok Shop lack immersion protection. The seller has not agreed to a recall or refund. A Recalled Teething Toy Broke the Pattern Parents Were Told to Look ForA newly recalled pull-string teething toy has a different model number and design from earlier recalls, and one choking incident has been reported. Trying to Lower Blood Sugar, Cholesterol or Blood Pressure? Different Workouts Suited Different MarkersA pooled analysis of 53 trials found that different exercise types helped different metabolic markers. Most of the evidence was low certainty. RDNE Stock project Share on Twitter Share on Facebook Share on Pocket A 2025 hack of old Cerner servers run by Oracle Health exposed personal and medical information belonging to nearly 20 million people, according to a Texas attorney general report that Bloomberg described on Oct. 5. About 3 million of those people live in Texas. The figure is the first public count for a breach that Oracle privately disclosed to hospital customers in March 2025.
According to the Texas report, the exposed data included Social Security numbers, addresses, and medical information, Gizmodo reported, citing Bloomberg. Hospitals that have notified patients say the details vary by person and may also include treating doctors, diagnoses, medications, and test results.
For many families, a hospital letter about the Oracle Health or Cerner incident may be the only notice they receive. According to Bloomberg Línea, the Texas report said Oracle itself disclosed the total. Oracle declined to comment on the figure, and the Texas attorney general’s office did not respond to Bloomberg’s requests for comment.
Oracle bought the health records company Cerner for $28 billion in 2022. Its 2025 notice to affected customers, signed by Oracle Health executive Seema Verma and first reported by BleepingComputer, said: “We are writing to inform you that, on or around February 20, 2025, we became aware of a cybersecurity event involving unauthorized access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud.” Oracle said an intruder used compromised customer credentials to get in sometime after Jan. 22, 2025, and copied data to a remote server.
Oracle told hospitals it would not notify patients directly. Each hospital had to decide whether federal privacy law required notice, though Oracle agreed to pay for credit monitoring and a mailing vendor. BleepingComputer’s sources said a person using the name “Andrew” was trying to extort affected hospitals for millions of dollars in cryptocurrency.
That same month, Oracle publicly denied a separate hacker claim, saying, “There has been no breach of Oracle Cloud.”The health breach involved a legacy server that had not yet been moved to that cloud, a distinction that meant little to patients whose records were taken.
The scale stayed hidden partly because federal law enforcement asked affected organizations to delay patient notices while it investigated, according to hospital notices. Bloomberg reported in March 2025 that the FBI was investigating the theft and the extortion attempts.
The result has been a slow trickle of letters, sent hospital by hospital and sometimes many months after the theft. Baltimore’s LifeBridge Health said in a notice to its patients that Oracle gave it a list of affected patients on Sept. 19, 2025. Texas-based CHRISTUS Health said Oracle notified it in October 2025 and sent a patient list on Dec. 9, 2025. CHRISTUS said the affected laboratory data all predates February 2025.
In the Kansas City area, NKC Health posted a patient notice on Nov. 25, 2025, and Mosaic Life Care in St. Joseph, Missouri, also notified patients, The Beacon reported. Elena A. Belov, a lawyer with Almeida Law Group who represents patients in a federal class action filed in the Western District of Missouri, said Oracle’s attorneys told her that 80 hospitals’ patient records may be involved. “This is one of the most massive breaches in the health care industry in the last couple of years,” Belov said.
The patients most likely to be affected are those treated at hospitals or labs that used legacy Cerner systems before early 2025. Oracle’s health clients also include the Defense Department and the Department of Veterans Affairs. A VA spokesperson said in March 2025 that the department was not affected, and the impact on other federal customers has not been made clear.
Affected hospitals are offering two years of free credit monitoring and identity protection, and some, such as LifeBridge, also offer minor identity protection services. AdventHealth’s notice said, “This incident has not impacted AdventHealth’s current IT systems or the safe and reliable operation of our clinical services.” Letters include an engagement number that patients use when they call the toll-free help line.
Readers who receive a letter can enroll in the free monitoring and, as hospital notices advise, review statements from providers and insurers and report any visit, prescription or test they do not recognize. A credit freeze with the major credit bureaus can also block new accounts opened in a stolen name.
People who have not received a letter should not assume they are unaffected. Oracle has not published a list of affected hospitals, and notices are still arriving one health system at a time.
Oracle has not said publicly how many hospitals were involved, whether every affected patient has been notified, or whether the stolen data was sold or leaked.
The sensible response is calm verification. Keep any hospital letter, call only the number printed on it, and be wary of unsolicited calls or emails that mention the breach. A notice does not mean fraud has happened, but it is worth a few minutes of checking.
What happened in the Oracle Health breach? An intruder used compromised customer credentials to reach old Cerner servers that had not yet been moved to Oracle Cloud, sometime after Jan. 22, 2025. Oracle said it learned of the event around Feb. 20, 2025, and began warning hospital customers in March 2025.
Where does the 20 million figure come from? It comes from a Texas attorney general report that cited Oracle’s own disclosure, as described by Bloomberg on Oct. 5, 2026. Oracle declined to comment on the number.
What information was exposed? It varies by person. The Texas report cited Social Security numbers, addresses and medical information, and hospital notices add items such as doctors, diagnoses, medications, test results and images.
How will I know if my data was involved? Affected hospitals, not Oracle, are mailing letters. The letters include an engagement number and a toll-free number for enrolling in free credit monitoring.
Should I freeze my credit? A freeze is a reasonable step for anyone who receives a notice. Checking insurance statements for unfamiliar care can also catch misuse early.
Were veterans or military families affected? The VA said in March 2025 that it was not affected. The impact on other federal customers, including the Defense Department, has not been publicly clarified.
Reported by medicaldaily.com.
Read Original Report at medicaldaily.com ↗
Comments (0)
No comments yet. Be the first to share your opinion!