Security Leaders Share Additional Thoughts on Oracle Health Breach

Recently, additional information was released regarding the data breach Oracle Health faced in Spring 2025. The Texas attorney general revealed that the stolen information included Social Security numbers, addresses and medical information. Healthcare providers affected by the incident have said compromised records could also include patient names, diagnoses, medications, doctors and test results. Oracle initially notified customers of the breach in March 2025 but did not disclose how many patients were affected.
Security leaders share some thoughts on this recently revealed information.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“A cloud migration can increase breach risk when the migration server still holds the records attackers want. Oracle Health told affected customers in March 2025 that attackers had used compromised customer credentials to access older Cerner servers after January 22 and copy patient data to a remote location. Those servers sat outside Oracle Cloud because the data had not yet been migrated. Oracle acquired Cerner for $28 billion in 2022, but moving the destination did not remove the older copy. That is a data-lifecycle failure.
I would treat every migration server holding patient data as a live clinical system until its access is separately controlled, its activity is logged, and its final copy is deleted. “Legacy” describes ownership and age. It does not describe the value of the data. The scale makes the lesson harder to ignore. Information belonging to nearly 20 million people was compromised, including about 3 million Texans. Hospitals also faced extortion attempts connected to the stolen records.
Healthcare providers will keep moving records between vendors, platforms, and acquisition-era systems. If temporary migration environments receive weaker controls than production systems, attackers will target the copy that organizations have already stopped watching.”
Damon Small, Board of Directors, Xcape, Inc.:
“Exfiltrating nearly 20 million patient records proves that technical debt in healthcare M&A presents immediate, catastrophic operational liability. When Oracle acquired Cerner for $28 billion, inherited legacy systems remained unmigrated, leaving Social Security numbers and medical histories exposed to credential compromise and cyber extortion. The market reality directly refutes Larry Ellison's bold assertion that "Oracle is unhackable." Healthcare IT data is just as critical as the patients themselves, meaning software vendors and healthcare providers must treat electronic health records (EHR) as life-safety biomedical devices rather than basic back-office IT assets. Compromised EHR data unleashes severe risks, including long-term identity theft, medical insurance fraud, and targeted extortion. Security leadership must mandate multi-factor authentication, rigid network isolation, and deep logging across all unmigrated environments while treating legacy infrastructure as high-risk untrusted enclaves.”
Critical Takeaways:
- Classify EHR systems as mission-critical biomedical devices rather than standard back-office IT infrastructure.
- Treat legacy systems inherited during M&A as untrusted enclaves with enforced multi-factor authentication, zero-trust network isolation, and centralized logging.
- Prepare incident response strategies for high-impact post-exfiltration risks, including patient extortion, insurance fraud, and identity theft.
It turns out "unhackable" legacy servers are surprisingly easy to hack.”
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!





