ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Oracle Health Data Breach Hits Over 2.6 Million Individuals

Oracle Health, a U.S.-based health IT platform provider, said a data security breach last year exposed the sensitive personal information of more than 2.6 million people.

 

Formerly known as Cerner, Oracle Health is a healthcare software service provider offering Electronic Health Records (EHR) and business operations systems to hospitals and healthcare organisations across the country. In 2022, Cerner was merged with Oracle Health, and migrated its systems to Oracle Cloud.

 

In a notice sent to affected individuals, Oracle Health said that on February 20, 2025 it became aware of a data security incident involving the legacy Cerner data migration servers.

 

“We are writing to inform you that, on or around February 20, 2025, we became aware of a cybersecurity event involving unauthorised access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud,” reads the notice. 

 

The company added that around January 22, the threat actor who infiltrated the legacy server used compromised customer credentials and copied data to a remote server. This stolen data “may” include patient information from electronic health records.

 

Several healthcare providers, including North Country Healthcare, Covenant Health, Central Maine Healthcare, Hamilton Health Care System and Premier Health, reported being affected by the Oracle Health data breach. The incident impacted dozens of hospitals and healthcare organisations across the United States.

 

In a recent filing with Texas state regulators, Oracle Health said it has identified as many as 2,658,388 individuals affected by the incident. The company added that  hackers used compromised customer credentials to access legacy Cerner environments. 

 

While Oracle did not publicly identify the perpetrators, multiple reports stated that the threat actor used the alias “Andrew” and attempted to extort affected hospitals by demanding cryptocurrency in exchange for not leaking the stolen patient data.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543