Curie Brief
Turn on cookies to sign in
Signing in saves your progress to your Curie account. We can only do that with cookies on — turn them on to continue.

A 2025 cyberattack on Oracle Health's legacy Cerner servers compromised the personal and medical data of nearly 20 million people nationwide. The breach — which exposed Social Security numbers, addresses, and medical records — triggered extortion demands, dozens of lawsuits, and a federal judge's ruling that healthcare organizations can't outsource their data protection duties to vendors.
A 2025 cyberattack on Oracle Health's legacy Cerner servers has turned out to be one of the largest healthcare data breaches on record. According to a report from the Texas attorney general, nearly 20 million people had their personal and medical information compromised — including roughly 3 million Texans. The breach, first detected on March 7, 2025, stemmed from an unauthorized individual gaining access to Cerner servers that hadn't yet been migrated to Oracle Cloud following the company's $28 billion acquisition of Cerner in 2022.
The fallout has been significant. Affected hospitals reportedly received extortion demands from a single threat actor seeking millions in cryptocurrency. Oracle now faces a consolidated federal class-action lawsuit in Missouri — drawn from 29 separate suits filed across 13 states — targeting both Oracle and eight health systems.
By the Numbers:
Why it matters: A federal judge's ruling that healthcare organizations cannot delegate their data protection responsibilities to third-party vendors sets a major precedent — meaning hospitals and health systems could be held liable for breaches even when the failure originates with a technology partner.