Skip to main content
Emerging ThreatsData Breaches

Healthcare Breach Exposes 20 Million Patient Records

Hospital corridor with staff, patient rooms, and a laptop on a medical cart.

“A cloud migration can increase breach risk when the migration server still holds the records attackers want.” — Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs

What Oracle Health told customers in March 2025

Oracle Health notified customers of a breach in March 2025, according to reporting. The company initially did not disclose how many patients were affected. Subsequent information released by the Texas attorney general said the stolen information included Social Security numbers, addresses and medical information; healthcare providers reported that compromised records could also include patient names, diagnoses, medications, doctors and test results.

Compromised Cerner legacy servers and the migration window

Security leaders described how the incident unfolded in technical and operational terms. Jacob Krell said attackers used compromised customer credentials to access older Cerner servers after January 22 and copy patient data to a remote location. Those servers “sat outside Oracle Cloud because the data had not yet been migrated,” Krell said, calling the situation a “data-lifecycle failure.” Krell argued that migration servers still holding patient data should be treated as live clinical systems until they are separately controlled, logged and the final copy deleted.

Scale of exposure: nearly 20 million patients, including about 3 million Texans

Sources cited in the reporting put the scale of the exfiltration at information belonging to nearly 20 million people, including about 3 million Texans. Hospitals notified in the wake of the breach also faced extortion attempts tied to the stolen records, according to the same reporting.

Security prescriptions from Jacob Krell and Damon Small

Two security voices offered overlapping prescriptions. Krell recommended that every migration server holding patient data be treated as a live clinical system with separate access controls, logging and deletion of final copies. Damon Small said the exfiltration of nearly 20 million patient records showed that technical debt from healthcare mergers and acquisitions can present “immediate, catastrophic operational liability.”

Small urged that electronic health records be treated as life-safety biomedical devices rather than “basic back‑office IT assets,” and he recommended enforcing multi-factor authentication, rigid network isolation and deep logging for unmigrated environments. Both speakers framed legacy, inherited systems as high-risk: Krell noted that “legacy” describes ownership and age but not the value of the data, and Small called for treating legacy infrastructure as “high-risk untrusted enclaves.”

Critical takeaways offered by security leaders

  • Classify EHR systems as mission-critical biomedical devices rather than standard back-office IT infrastructure.
  • Treat legacy systems inherited during M&A as untrusted enclaves with enforced multi-factor authentication, zero-trust network isolation, and centralized logging.
  • Prepare incident response strategies for high-impact post-exfiltration risks, including patient extortion, insurance fraud, and identity theft.

Damon Small directly challenged the idea of vendor invulnerability, saying the breach “directly refutes Larry Ellison's bold assertion that 'Oracle is unhackable.'”

What this means for healthcare providers, procurement leaders, and patients

Healthcare providers will continue migrating records between vendors and platforms, Krell noted, and where temporary migration environments receive weaker controls attackers will target those copies; providers therefore must harden migration environments or treat them as untrusted enclaves. Procurement leaders and executives completing M&A deals will face renewed pressure to include data-lifecycle and migration controls in integration plans, because Oracle’s acquisition of Cerner for $28 billion in 2022 left inherited systems unmigrated and exposed. Patients—whose Social Security numbers, addresses and medical information are expressly reported as stolen—face long-term risks including identity theft, insurance fraud and targeted extortion tied to the compromised records.

The breach lays bare a narrow operational fact with broad consequences: moving data does not erase older copies, and temporary or legacy environments can become the easiest route for exfiltration. Security leaders quoted in the reporting pushed concrete countermeasures—MFA, isolation, deep logging, and treating legacy EHR systems as life‑safety assets—that organizations may adopt or ignore. The question the facts of this incident leave open is whether vendors and providers will change migration practices fast enough to prevent a repeat when the next large-scale M&A creates more unmigrated copies of patient data.

Source: Security Magazine — Security Leaders Share Additional Thoughts on Oracle Health Breach