What Happened
In late January 2025, a threat actor breached Oracle Health (formerly Cerner) servers and stole patient data belonging to multiple US healthcare organizations. BleepingComputer reported the breach in March 2025, revealing Oracle Health had been notifying affected hospital clients quietly via telephone — avoiding paper trails.
The attacker gained access to legacy Cerner data migration servers that stored patient data from before hospitals completed their Oracle Cloud migrations.
Scope
- 140+ US hospitals and healthcare organizations affected
- Data includes: patient names, dates of birth, diagnoses, treatment records, insurance information
- Attacker is reportedly selling data to other parties while demanding per-hospital ransoms
- Oracle Health has not made a public statement as of April 2025
Healthcare Sector Context
This follows the Change Healthcare ransomware attack in 2024 (affecting 100M+ patients) and a string of targeted attacks on US healthcare. The HHS Office for Civil Rights (OCR) has opened investigations into multiple affected organizations.
Recommended Actions for Healthcare IT
- Contact Oracle Health to determine if your organization's data was included
- Identify all data stored on legacy Cerner servers and confirm migration completion status
- Review BAA (Business Associate Agreement) terms with Oracle Health
- Prepare patient notification procedures per HIPAA Breach Notification Rule (60-day window)
- Engage legal counsel for OCR reporting obligations