PrivacySignal
Breach

Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner

HIPAA Journal · · US Federal · Data Breaches

A 2025 data breach at Oracle Health's legacy Cerner servers exposed electronic protected health information belonging to nearly 20 million individuals. The incident ranks among the largest known breaches of medical data reported this year.

Why this matters: Twenty million people's medical records is not an abstract number. That is diagnoses, prescriptions, mental health history, and treatment details that patients had no real choice but to share with a healthcare system. Oracle Health inherited these records through its Cerner acquisition. The breach happened on legacy servers, which is the kind of infrastructure that gets deprioritized after a big acquisition and then becomes a liability. Patients did not pick Oracle to hold their data. They had no say. And they are the ones living with the exposure.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Deep Signal · Part I of III

The Algorithm Said So

Federal rulemakers are deciding what to do when artificial intelligence produces the kind of conclusion that once required an expert. They disagree about how to regulate it. They also disagree about whether the problem has arrived.

· 10 min read Read →

Related stories

Breach
CyberScoop · · US Federal

Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions

Zohar Pinhasi allegedly deceived ransomware recovery clients into a payment scheme disguised as a specialized service that helped victims avoid paying cybercriminals. The post Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions appeared first on CyberScoop.

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
HIPAA Journal · · US Federal

Laboratory Services Cooperative Agrees to Pay $6.1 Million to Settle Data Breach Litigation

Laboratory Services Cooperative, a Seattle-based nonprofit lab serving Planned Parenthood affiliates, has agreed to pay $6.1 million to settle litigation stemming from a data breach. The organization provides clinical diagnostic and testing services, meaning the exposed data likely included sensitive health information.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance

#breach#healthcare Read original →
Breach
BleepingComputer · · International

OAuth grants pile up faster than you can review them. Here's how to keep up.

OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and exploiting forgotten OAuth grants to gain access to corporate data. This article covers why OAuth risks are so hard [...]

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · AI governance · Policy

#breach#ai#security Read original →