|

Oracle Health Data Breach Exposed Nearly 20 Million People, What the Lawsuit Means

A 2025 cyberattack on legacy Cerner systems owned by Oracle Health compromised the personal information of nearly 20 million people, according to information released by the Texas Attorney General. About 3 million of them are Texans. The report, issued October 2, 2026, was covered by Bloomberg Law on October 5.

There is no settlement, claim form or claim deadline for this breach. The related lawsuits are pending in federal court in Missouri as a putative (proposed) class action, and no class has been certified. Do not submit personal information to any website claiming to be an Oracle Health settlement portal.

Oracle Health Data Breach Quick Facts

DetailInformation
CompanyOracle Corporation / Oracle Health (Cerner, acquired by Oracle in 2022)
IncidentUnauthorized access to legacy Cerner servers
Access beganAfter January 22, 2025
Customers alertedOracle alerted some customers in March 2025
People affectedNearly 20 million, per the Texas Attorney General report
Texans affectedAbout 3 million
Data compromisedSocial Security numbers, addresses and medical information. The exact data varied by person
Lead lawsuitBlount et al. v. Oracle Health, Inc., the master case for consolidated actions
Case number4:25-cv-00259-BP
CourtU.S. District Court, Western District of Missouri
JudgeChief Judge Beth Phillips
FiledApril 11, 2025
Class statusPutative class action. Not certified
SettlementNone
Official settlement websiteNone
Claim formNone
Claim deadlineNone
Settlement administratorNone

What Happened

Oracle acquired Cerner, an electronic health-records company, in 2022. According to Bloomberg Law’s report on the Texas Attorney General’s findings, Oracle alerted some customers in March 2025 that the hack happened sometime after January 22, 2025. Oracle did not release the number of affected patient records at that time.

The Texas Attorney General report indicates Oracle disclosed that Social Security numbers, addresses and medical information of almost 20 million people were taken. Oracle declined to comment on the figure when Bloomberg Law asked.

The Texas Attorney General report itself was not retrievable for this article, so the 20 million figure is attributed to Bloomberg Law’s account of that report.

What Information Was Exposed?

The reported data includes Social Security numbers, addresses and medical information. Exactly what was exposed depends on the person and the healthcare provider that held the records. Hospital and clinic notices sent to patients have described categories such as names, Social Security numbers and clinical information.

Check your own notice for the specific data involved.

The Lawsuit: Where It Stands

The lead case was filed on April 11, 2025, by Rebecca Blount and Cheryl McCulley in the U.S. District Court for the Western District of Missouri. An amended complaint followed on April 28, 2025. The docket lists Cerner Corporation d/b/a Oracle Health as a defendant, along with several hospital customers named in the consolidated cases:

  • Tallahassee Memorial Healthcare
  • Union Health System
  • Mosaic Life Care
  • Baptist Health South Florida
  • Glens Falls Hospital
  • Arkansas Heart Hospital

On June 30, 2025, Judge Phillips ordered a number of related cases consolidated into the master case. Later orders folded in more. On July 21, 2025, she appointed co-lead interim class counsel to represent the proposed class.

Plaintiffs allege the defendants failed to protect sensitive patient information. Those claims are allegations, and no court has found Oracle or any hospital liable.

Has a Class Been Certified?

No. The case is a putative class action. Interim class counsel is appointed to act for the proposed class before the court decides whether to certify it. Not everyone whose data was exposed is automatically part of a certified class, and a later class definition could be narrower than the full 20 million.

Reports indicate that the court has ruled on motions to dismiss in 2026, allowing at least some claims to proceed. This article could not confirm the details of those rulings from the court record. Claims that survive dismissal move on to discovery and further motions, and the case is not resolved.

Is There a Settlement, Claim Form or Deadline?

No. No settlement or court-approved claim process exists. If the case settles, a court would first review the proposed settlement and approve a notice process before any claim deadline applies. Until then, nobody can promise a payout amount.

Oracle Health Data Breach Exposed Nearly 20 Million People, What the Lawsuit Means

Could My Information Be Involved?

Possibly, but being a patient of a provider that uses Oracle Health software does not by itself mean your data was exposed. Notifications generally come from the hospital, clinic or health system that held your records, not always from Oracle. If you received a notice that mentions Oracle Health or Cerner, it likely applies to you. Keep it.

What to Do If You Received a Notice

  1. Keep the notice, including the date received and any attachments. It may matter if a settlement is later announced.
  2. Use any free credit monitoring or identity protection the notice offers.
  3. Check your credit reports for accounts or inquiries you don’t recognize.
  4. Consider a fraud alert or credit freeze. A freeze limits new-credit applications in your name. Monitoring only alerts you.
  5. Watch for medical identity theft. Review bills, insurance statements and explanations of benefits for services or providers you don’t recognize.
  6. Keep receipts for any documented costs you incur because of the breach.
  7. Report suspected identity theft to the FTC at IdentityTheft.gov.

If you want to explore legal options, consult a consumer-protection or data-breach attorney. Time limits can apply.

What Happens Next

  • Hospitals and health systems continue to notify patients under HIPAA and state breach-notification laws.
  • The federal case continues toward discovery, further motions and a possible class-certification decision.
  • Any settlement would need court approval and a formal notice process.
  • Regulators, such as the HHS Office for Civil Rights, can investigate separately from private lawsuits.

Key Dates

DateEvent
After January 22, 2025Unauthorized access to legacy Cerner servers began
March 2025Oracle alerted some customers to the incident
April 11, 2025Lead lawsuit filed in the Western District of Missouri
April 28, 2025Amended complaint filed
June 30, 2025Court consolidated numerous related cases into the master case
July 21, 2025Court appointed co-lead interim class counsel
October 2, 2026Texas Attorney General report issued
October 5, 2026Bloomberg Law reported the nearly 20 million figure
Not applicableNo settlement, claim form or claim deadline exists

Frequently Asked Questions

How many people were affected by the Oracle Health data breach?

Nearly 20 million, including about 3 million Texans, according to the Texas Attorney General report as covered by Bloomberg Law.

What information was taken?

Social Security numbers, addresses and medical information. The exact data varied by person.

When did the breach happen?

After January 22, 2025. Oracle alerted some customers in March 2025.

What is the case number?

4:25-cv-00259-BP, in the U.S. District Court for the Western District of Missouri.

Who filed the lawsuit?

Rebecca Blount and Cheryl McCulley filed the lead case on April 11, 2025. Other plaintiffs’ cases were later consolidated into it.

Is it a class action?

It is a putative class action. The court has not certified a class.

Has Oracle been found liable?

No. The claims are allegations. Oracle declined to comment on the 20 million figure.

Is there a settlement or claim form?

No. No settlement, claim form or deadline has been identified.

Can I get money?

Not at this time. Any future payment would depend on a court-approved settlement or judgment.

What should I do now?

Keep your breach notice, use any free monitoring offered, review your credit reports and medical statements, and consider a credit freeze.

Related Reading

Legal information disclaimer: AllAboutLawyer.com is a U.S. consumer legal information website. It is not a law firm and does not provide legal advice. Oracle has not been found liable, and all allegations are unproven. This article will be updated if a settlement, class-certification ruling or other official development occurs.

Sources

  1. Cameron Fozi, Bloomberg Law, “Oracle 2025 Health Breach Compromised Data of 20 Million People,” October 5, 2026. https://news.bloomberglaw.com/privacy-and-data-security/oracle-2025-health-breach-compromised-data-of-20-million-people
  2. Justia Dockets, Blount et al. v. Oracle Health, Inc., No. 4:25-cv-00259 (W.D. Mo.). https://dockets.justia.com/docket/missouri/mowdce/4:2025cv00259/182983
  3. Texas Attorney General data breach report, issued October 2, 2026, as reported by Bloomberg Law (the report itself was not retrieved).

About the Author

Israr Ahmad is a legal content researcher with 4+ years of experience covering class action settlements and consumer rights cases. He has researched and published coverage of 2,500+ settlements using verified court records, settlement administrator filings, and government sources. Learn more about Israr.

Leave a Reply

Your email address will not be published. Required fields are marked *