← Oracle Cerner

2025 Oracle Health (legacy Cerner) — credential-led access to unmigrated EHR infrastructure; U.S. hospital client notifications

2025 Unknown records affected Share on X

Data compromised

Patient PHI as summarized in hospital substitute notices (ChristianaCare, CHRISTUS Health, and others mirrored HIPAA Journal reporting)

Technical writeup

Oracle Health disclosed to hospital customers that compromised credentials enabled access to legacy Cerner-hosted systems not yet fully shifted to Oracle Cloud, with HIPAA-oriented journalism tying the activity to a January–February 2025 window before remediation. Affected providers issued substitute breach letters listing PHI classes—including demographics, record numbers, clinical results, and insurance identifiers—while aggregate individual counts stayed distributed across dozens of health-system notices rather than a single vendor total.

Root cause

Credential compromise against legacy Cerner migration / hosting planes described in client alerts and specialty health press

References