Oracle Health Data Breach Exposed Nearly 20 Million People, What the Lawsuit Means
A 2025 cyberattack on legacy Cerner systems owned by Oracle Health compromised the personal information of nearly 20 million people, according to information released by the Texas Attorney General. About 3 million of them are Texans. The report, issued October 2, 2026, was covered by Bloomberg Law on October 5.
There is no settlement, claim form or claim deadline for this breach. The related lawsuits are pending in federal court in Missouri as a putative (proposed) class action, and no class has been certified. Do not submit personal information to any website claiming to be an Oracle Health settlement portal.
Oracle Health Data Breach Quick Facts
| Detail | Information |
| Company | Oracle Corporation / Oracle Health (Cerner, acquired by Oracle in 2022) |
| Incident | Unauthorized access to legacy Cerner servers |
| Access began | After January 22, 2025 |
| Customers alerted | Oracle alerted some customers in March 2025 |
| People affected | Nearly 20 million, per the Texas Attorney General report |
| Texans affected | About 3 million |
| Data compromised | Social Security numbers, addresses and medical information. The exact data varied by person |
| Lead lawsuit | Blount et al. v. Oracle Health, Inc., the master case for consolidated actions |
| Case number | 4:25-cv-00259-BP |
| Court | U.S. District Court, Western District of Missouri |
| Judge | Chief Judge Beth Phillips |
| Filed | April 11, 2025 |
| Class status | Putative class action. Not certified |
| Settlement | None |
| Official settlement website | None |
| Claim form | None |
| Claim deadline | None |
| Settlement administrator | None |
What Happened
Oracle acquired Cerner, an electronic health-records company, in 2022. According to Bloomberg Law’s report on the Texas Attorney General’s findings, Oracle alerted some customers in March 2025 that the hack happened sometime after January 22, 2025. Oracle did not release the number of affected patient records at that time.
The Texas Attorney General report indicates Oracle disclosed that Social Security numbers, addresses and medical information of almost 20 million people were taken. Oracle declined to comment on the figure when Bloomberg Law asked.
The Texas Attorney General report itself was not retrievable for this article, so the 20 million figure is attributed to Bloomberg Law’s account of that report.
What Information Was Exposed?
The reported data includes Social Security numbers, addresses and medical information. Exactly what was exposed depends on the person and the healthcare provider that held the records. Hospital and clinic notices sent to patients have described categories such as names, Social Security numbers and clinical information.
Check your own notice for the specific data involved.
The Lawsuit: Where It Stands
The lead case was filed on April 11, 2025, by Rebecca Blount and Cheryl McCulley in the U.S. District Court for the Western District of Missouri. An amended complaint followed on April 28, 2025. The docket lists Cerner Corporation d/b/a Oracle Health as a defendant, along with several hospital customers named in the consolidated cases:
- Tallahassee Memorial Healthcare
- Union Health System
- Mosaic Life Care
- Baptist Health South Florida
- Glens Falls Hospital
- Arkansas Heart Hospital
On June 30, 2025, Judge Phillips ordered a number of related cases consolidated into the master case. Later orders folded in more. On July 21, 2025, she appointed co-lead interim class counsel to represent the proposed class.
Plaintiffs allege the defendants failed to protect sensitive patient information. Those claims are allegations, and no court has found Oracle or any hospital liable.
Has a Class Been Certified?
No. The case is a putative class action. Interim class counsel is appointed to act for the proposed class before the court decides whether to certify it. Not everyone whose data was exposed is automatically part of a certified class, and a later class definition could be narrower than the full 20 million.
Reports indicate that the court has ruled on motions to dismiss in 2026, allowing at least some claims to proceed. This article could not confirm the details of those rulings from the court record. Claims that survive dismissal move on to discovery and further motions, and the case is not resolved.
Is There a Settlement, Claim Form or Deadline?
No. No settlement or court-approved claim process exists. If the case settles, a court would first review the proposed settlement and approve a notice process before any claim deadline applies. Until then, nobody can promise a payout amount.

Could My Information Be Involved?
Possibly, but being a patient of a provider that uses Oracle Health software does not by itself mean your data was exposed. Notifications generally come from the hospital, clinic or health system that held your records, not always from Oracle. If you received a notice that mentions Oracle Health or Cerner, it likely applies to you. Keep it.
What to Do If You Received a Notice
- Keep the notice, including the date received and any attachments. It may matter if a settlement is later announced.
- Use any free credit monitoring or identity protection the notice offers.
- Check your credit reports for accounts or inquiries you don’t recognize.
- Consider a fraud alert or credit freeze. A freeze limits new-credit applications in your name. Monitoring only alerts you.
- Watch for medical identity theft. Review bills, insurance statements and explanations of benefits for services or providers you don’t recognize.
- Keep receipts for any documented costs you incur because of the breach.
- Report suspected identity theft to the FTC at IdentityTheft.gov.
If you want to explore legal options, consult a consumer-protection or data-breach attorney. Time limits can apply.
What Happens Next
- Hospitals and health systems continue to notify patients under HIPAA and state breach-notification laws.
- The federal case continues toward discovery, further motions and a possible class-certification decision.
- Any settlement would need court approval and a formal notice process.
- Regulators, such as the HHS Office for Civil Rights, can investigate separately from private lawsuits.
Key Dates
| Date | Event |
| After January 22, 2025 | Unauthorized access to legacy Cerner servers began |
| March 2025 | Oracle alerted some customers to the incident |
| April 11, 2025 | Lead lawsuit filed in the Western District of Missouri |
| April 28, 2025 | Amended complaint filed |
| June 30, 2025 | Court consolidated numerous related cases into the master case |
| July 21, 2025 | Court appointed co-lead interim class counsel |
| October 2, 2026 | Texas Attorney General report issued |
| October 5, 2026 | Bloomberg Law reported the nearly 20 million figure |
| Not applicable | No settlement, claim form or claim deadline exists |
Frequently Asked Questions
How many people were affected by the Oracle Health data breach?
Nearly 20 million, including about 3 million Texans, according to the Texas Attorney General report as covered by Bloomberg Law.
What information was taken?
Social Security numbers, addresses and medical information. The exact data varied by person.
When did the breach happen?
After January 22, 2025. Oracle alerted some customers in March 2025.
What is the case number?
4:25-cv-00259-BP, in the U.S. District Court for the Western District of Missouri.
Who filed the lawsuit?
Rebecca Blount and Cheryl McCulley filed the lead case on April 11, 2025. Other plaintiffs’ cases were later consolidated into it.
Is it a class action?
It is a putative class action. The court has not certified a class.
Has Oracle been found liable?
No. The claims are allegations. Oracle declined to comment on the 20 million figure.
Is there a settlement or claim form?
No. No settlement, claim form or deadline has been identified.
Can I get money?
Not at this time. Any future payment would depend on a court-approved settlement or judgment.
What should I do now?
Keep your breach notice, use any free monitoring offered, review your credit reports and medical statements, and consider a credit freeze.
Related Reading
- Lakeview Health Data Breach Settlement: another healthcare data breach that reached a settlement.
Legal information disclaimer: AllAboutLawyer.com is a U.S. consumer legal information website. It is not a law firm and does not provide legal advice. Oracle has not been found liable, and all allegations are unproven. This article will be updated if a settlement, class-certification ruling or other official development occurs.
Sources
- Cameron Fozi, Bloomberg Law, “Oracle 2025 Health Breach Compromised Data of 20 Million People,” October 5, 2026. https://news.bloomberglaw.com/privacy-and-data-security/oracle-2025-health-breach-compromised-data-of-20-million-people
- Justia Dockets, Blount et al. v. Oracle Health, Inc., No. 4:25-cv-00259 (W.D. Mo.). https://dockets.justia.com/docket/missouri/mowdce/4:2025cv00259/182983
- Texas Attorney General data breach report, issued October 2, 2026, as reported by Bloomberg Law (the report itself was not retrieved).
About the Author
Israr Ahmad is a legal content researcher with 4+ years of experience covering class action settlements and consumer rights cases. He has researched and published coverage of 2,500+ settlements using verified court records, settlement administrator filings, and government sources. Learn more about Israr.
