On October 2, 2026, the Texas Attorney General’s office reportedly put the number of people affected by Oracle Health’s 2025 data breach at nearly 20 million, including about 3 million Texans. The disclosure concerns a breach from the previous year, not a new 2026 incident.
Reported total approaches 20 million
The reported figure covers nearly 20 million people, with about 3 million Texans included in that total. Those numbers were attributed to a Texas Attorney General’s report. The incident itself took place in 2025.
Reported access involved legacy Cerner servers
The reported intrusion involved two older Cerner servers that had not yet been migrated to Oracle cloud storage. Attackers reportedly used compromised customer credentials to access the servers and copy patient data. Oracle was reported to have said that its cloud infrastructure was unaffected by the incident.
The distinction is between the legacy servers involved in the reported access and Oracle’s cloud infrastructure. The cloud statement remains Oracle’s reported position.
What patient information may have been involved
Reported categories include Social Security numbers, addresses and medical information. CHRISTUS Health says the information potentially involved in its patients’ records varied by person and could include names, Social Security numbers, medical record numbers, doctors, diagnoses, medicines, laboratory orders, blood-bank records and test results.
CHRISTUS Health says the data involved predates February 2025 and does not include present-day laboratory records.
What CHRISTUS Health tells affected patients
CHRISTUS Health says Oracle informed it about the incident in October 2025 and sent it a list of potentially affected patients on December 9, 2025. The provider says it is mailing letters to affected patients with an offer of two years of credit monitoring and identity-protection services. Its notice also advises patients to review provider and insurer statements and report inaccuracies.