Almost 20 Million Individuals Affected by 2025 Data Breach at Oracle Health/Cerner
A 2025 data breach at Oracle Health's legacy Cerner servers exposed electronic protected health information belonging to nearly 20 million individuals. The incident ranks among the largest known breaches of medical data reported this year.
Why this matters: Twenty million people's medical records is not an abstract number. That is diagnoses, prescriptions, mental health history, and treatment details that patients had no real choice but to share with a healthcare system. Oracle Health inherited these records through its Cerner acquisition. The breach happened on legacy servers, which is the kind of infrastructure that gets deprioritized after a big acquisition and then becomes a liability. Patients did not pick Oracle to hold their data. They had no say. And they are the ones living with the exposure.
Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.