Oracle Health Data Breach Details
The breach, which took place after January 22, 2025, was only discovered on February 20, 2025, when Oracle became aware of unauthorized access to legacy Cerner data migration servers. The breach has affected numerous healthcare organizations that rely on Oracle Health’s software for their electronic health record (EHR) systems. These systems store sensitive patient data and play a critical role in the daily operations of hospitals, clinics, and other healthcare facilities. As a result, patients’ personal and medical information could potentially be exposed to malicious actors.
The breach was carried out by exploiting compromised customer credentials, which allowed the attacker to access and potentially copy sensitive data to a remote server. While Oracle has not publicly disclosed the full details of the incident, private notifications to healthcare providers have confirmed that patient information from electronic health records (EHR) was among the data that was stolen. The stolen data may include personally identifiable information (PII), medical histories, treatment records, and other private health information.
What Information Was Compromised?
The information exposed in the breach may vary by individual, but it could include the following:
-
Name
-
Address
-
Social Security number
-
Driver’s license number
- Health information