New Delhi: A cybersecurity breach at Oracle Corp.’s healthcare unit compromised personal information belonging to nearly 20 million people, including around 3 million residents of Texas, according to information released by the Texas attorney general.

The breach exposed sensitive information including Social Security numbers, addresses and medical data, raising fresh concerns over the security of patient information held by healthcare technology providers. The disclosure was made in a report issued by the Texas attorney general, with details of the scale of the incident emerging more than a year after Oracle first alerted some customers about the cyberattack.

Oracle had notified some customers in March 2025 that its healthcare systems had been targeted in a cyberattack. At the time, the company said the attack had occurred sometime after January 22, 2025, but did not disclose how many patients’ electronic health records may have been affected.

What data was exposed in the Oracle breach?

According to the Texas attorney general’s report, the information taken in the hack included Social Security numbers, addresses and medical information belonging to almost 20 million people.

The exact information compromised could vary from one patient to another. Two healthcare organisations affected by the incident — Christus Health in Texas and Tri-City Medical Center in California — said the stolen information could include patients’ names, Social Security numbers, doctors’ details, diagnoses, medicines, test results and other medical information.

The scale and sensitivity of the information make the incident particularly significant because healthcare records can contain a combination of personally identifiable and highly sensitive medical details.

Nearly 3 million Texans affected

The Texas attorney general’s disclosure indicates that about 3 million Texans were among the people whose information was taken during the cyberattack.

The breach involved customers across the United States, rather than being limited to Texas. Christus Health and Tri-City Medical Center said they were among many Oracle healthcare customers affected.

The organisations indicated that the extent of information compromised differed between patients. This means that not every affected individual necessarily had the same categories of personal or medical information exposed.

Oracle had alerted customers in 2025

Oracle first disclosed the cyberattack to some customers in March 2025. The company said attackers had gained access to older servers associated with Cerner Corp., the healthcare technology company Oracle acquired in 2022 for $28 billion.

According to the notice issued to customers, the affected information had not yet been transferred to Oracle’s cloud storage service when the attackers accessed the older infrastructure.

The disclosure at the time did not provide the total number of patients whose electronic health records were affected. The much larger figure of nearly 20 million people has now emerged through information released by the Texas attorney general.

Oracle healthcare customers include major institutions

Oracle’s healthcare business serves a broad range of organisations, including regional hospitals and clinics. Its customers also include major US government healthcare and defence institutions.

Among them are the US Department of Defense and the US Department of Veterans Affairs.

The potential impact on Oracle’s federal government customers remains unclear. A Veterans Affairs spokesperson had said following Oracle’s March 2025 disclosure that the department was not affected by the incident.

Oracle declined to comment on the latest disclosure, while the Texas attorney general’s office did not respond to requests for comment, according to Bloomberg News.

FBI investigated the cyberattack

The incident also drew the attention of US federal investigators. The FBI investigated the cyberattack as well as attempts by hackers to pressure medical companies into paying ransom, Bloomberg News reported in March 2025.

Cyberattacks targeting healthcare organisations have become a major concern because hospitals and healthcare technology providers hold large volumes of valuable personal and medical information.

Unlike ordinary financial information, medical records can contain details about a person’s health history, diagnoses, prescriptions and treatment. The exposure of such information can therefore have consequences that extend beyond immediate financial fraud risks.

The Oracle incident highlights the security challenges involved in maintaining legacy healthcare systems while organisations transition to newer cloud-based platforms.

Why the Oracle breach matters

The latest disclosure puts the size of the incident into perspective. What was initially reported as a cyberattack affecting an undisclosed number of healthcare records has now been linked to personal information belonging to almost 20 million people.

The breach also highlights the risks associated with older technology infrastructure. Oracle’s acquisition of Cerner brought a large healthcare technology business into its operations, but the affected data was reportedly still stored on older servers rather than having been moved to Oracle’s cloud environment.

For healthcare providers, the incident is another reminder of the importance of securing legacy systems, monitoring access to patient information and protecting sensitive data during technology migrations.

As regulators and affected organisations continue to assess the consequences, the full impact of the Oracle healthcare breach could depend on precisely what information was accessed for each affected patient and how that information may have been used.