US patient data reportedly stolen following Oracle Health breach

  • 2 April 2025
US patient data reportedly stolen following Oracle Health breach
Credit: Shutterstock.com
  • A breach at Oracle Health has reportedly led to patient data in the US being stolen by a cyber criminal, BleepingComputer reports
  • In a notice sent to impact customers, Oracle Health confirmed that it became aware of a breach of legacy Cerner data migration servers on 20 February 2025
  • Oracle Health previously denied claims that its public cloud was compromised

An alleged breach at Oracle Health has impacted multiple healthcare organisations and hospitals in the US after a cyber criminal reportedlyĀ  stole patient data from legacy servers.Ā 

Oracle Health is yet to publicly disclose the incident, but BleepingComputer reported that it had seen private communications sent to customers that confirmed patient data was stolen in the attack.

The notice from Oracle Health to impacted customers said that the firm became aware of a breach of legacy Cerner data migration servers on 20 February 2025.

It said: “We are writing to inform you that, on or around 20 February 2025, we became aware of a cybersecurity event involving unauthorised access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud.ā€

Oracle said the threat actor used compromised customer credentials to breach the servers sometime after 22 January 2025, and copied data to a remote server. This stolen data “may” have included patient information from electronic health records (EHRs)

According to BleepingComputer, multiple sources confirmed that patient data was stolen during the attack.

Details of the attack were not shared with customers and it is not known if ransomware was deployed in the attack or if it was purely data theft.

It is also unclear how a customer’s credentials could have allowed the theft of data from multiple organisations.

Sources told BleepingComputer that the impacted hospitals are being extorted by an individual threat actor going by the name ā€œAndrewā€ who has not claimed affiliation with any known ransomware or extortion groups.

Oracle Health, formerly known as Cerner, is a healthcare software-as-a-service (SaaS) company offering EHRs and business operations systems to hospitals and healthcare organisations.

After being acquired by Oracle in 2022, Cerner was merged into Oracle Health, with its systems migrated to Oracle Cloud.

Oracle had previously denied claims that its public cloud offering was compromised and had information stolen after a threat actor advertised on an online cyber crime forum what was alleged to be Oracle Cloud customer security keys and other sensitive data taken.

A spokesperson for Oracle told The Register on 21 March 2025: ā€œThere has been no breach of Oracle Cloud.

ā€œThe published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data.ā€

Digital Health News contacted Oracle Health but had not received a response at the time of publication.

Subscribe to our newsletter

Subscribe To Our Newsletters

Related News

Patient death linked to cyber attack on NHS pathology provider

Patient death linked to cyber attack on NHS pathology provider

The first patient death linked to the cyber attack last year on NHS pathology system provider Synnovis has been confirmed.
Barts Health deploys imaging de-identification tool

Barts Health deploys imaging de-identification tool

Barts Health NHS Trust has implemented Sectra’s Anonymise and Export functionality, which de-identifies medical images for research purposes.
Two NHS trusts affected by cyber attack on mobile phone software

Two NHS trusts affected by cyber attack on mobile phone software

NHSE is investigating a cyber incident at two NHS trusts after hackers exploited a vulnerability in software used to manage mobile phones.