Reporting relayed by the Texas Attorney General indicates that a 2025 breach of protected health information on Oracle Health's legacy Cerner servers may have compromised the records of almost 20 million individuals — a figure not independently verified and never publicly totalled by Oracle Health, which has not said how many Cerner clients or individuals were affected. Where state attorneys general publish numbers, the count runs to 2,992,244 in Texas, 1,978,661 in Oregon, 283,903 in South Carolina and 69,238 in Washington, while the HHS Office for Civil Rights portal still carries a placeholder total of 501 and is expected to be updated after the Texas AG was given a revised figure on 2 October. The breach notice states an unauthorised individual first gained access to legacy Cerner servers as early as 22 January 2025, identified by Oracle Health on 7 March 2025, and that compromised data includes names, Social Security numbers, diagnoses, treatment information, medications, test results, medical images, record numbers and physician names. The gap between the OCR placeholder and the state disclosures is itself a governance story about breach-reporting latency.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-10-09 |
| Source | HIPAA Journal |
| Reliability | Tier 2 |