Oracle Health Data Breach: Old Cerner Servers, Hospital Letters, No Settlement
Questions about this case?
AI Legal Assistant · free · answers in seconds · general information, not legal advice
If your hospital wrote to you about a breach at “our electronic health record (EHR) vendor, Cerner,” this is that incident. An intruder got into legacy Cerner systems at least as early as January 22, 2025 and took patient data. Cerner is now Oracle Health. The letters come in your hospital's name, and some were still being mailed in June 2026. More than 40 hospital and health-system entities are parties in one federal case in Missouri. As of September 30, 2026, there is no settlement and no claim form.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened to the Old Cerner Servers
Oracle bought Cerner in 2022 and renamed it Oracle Health, then began moving Cerner systems to Oracle Cloud. Some data still sat on older Cerner servers. In its notice to hospital customers, Oracle Health wrote that on or around February 20, 2025 it became aware of “unauthorized access to some amount of your Cerner data that was on an old legacy server not yet migrated to the Oracle Cloud.” Hospital letters put the start of the access at least as early as January 22, 2025. Per that customer notice, as reported by BleepingComputer, the intruder used compromised customer credentials — and Oracle Health's customers are hospitals and clinics, not patients.
Oracle stayed quiet in public. On March 28, 2025, BleepingComputer reported that Oracle Health “has not yet publicly disclosed the incident,” had not answered questions sent since March 4, and sent its letters to hospitals on plain paper rather than letterhead. Oracle's own account has since surfaced mainly in a July 25, 2025 filing by Cerner Corporation with the California Attorney General and in its court filings. There, Cerner says law enforcement asked it to delay notifying its hospital customers, and that the hacker “copied some of this data to a nonpublic external location.” BleepingComputer's sources also said affected hospitals were being extorted for millions of dollars in cryptocurrency — a claim, not a court finding.
Case Details
The patient suits are consolidated as In re: Cerner/Oracle Data Breach Litigation, No. 4:25-cv-00259-BP, in the U.S. District Court for the Western District of Missouri, before Judge Beth Phillips. The lead case, Blount v. Oracle Health, Inc., was filed on April 11, 2025. On June 30, 2025, the judge consolidated 17 cases “at least for all pretrial purposes,” and more have been folded in since. This is not an MDL: the court notes the transfers “have been arranged by the parties and not the Judicial Panel on Multidistrict Litigation.”
The defendants are Cerner Corporation, doing business as Oracle Health, and the hospitals themselves. The Consolidated Complaint named Cerner and ten providers. Patients added later join through Short Form Complaints; a batch filed on August 28 and September 3, 2026 names additional health systems.
Status: Negligence Claims Survive, No Settlement
Since then: newly added patients sued more hospitals through Short Form Complaints. On September 28, 2026, the court set that day as Cerner's deadline for one consolidated motion to dismiss them, adding that the motion is no ground for delaying discovery. Several hospitals are still responding; Advocate Health and Atrium Health have until October 19, 2026. As of September 30, 2026, the docket shows no settlement, no fund and no claim form. In September 2025 the court called a class-certification deadline premature.
Follow this case
There's no claim deadline yet. We'll email you if a settlement opens a claim period.
Is My Hospital on the List?
Your letter is the test. Notices come from your hospital or health system, not from Oracle, and name Cerner as the vendor. In court, Cerner says its only customers are healthcare providers and it has no relationship with their patients.
Named as defendants in the court case (docket, as of September 30, 2026): Advocate Health, Advocate Aurora Health, Atrium Health, Navicent Health and The Charlotte-Mecklenburg Hospital Authority; AdventHealth Port Charlotte and Adventist Health System/Sunbelt; Albany Med Health System and Glens Falls Hospital; Arkansas Heart Hospital; Ascension Health; Aultman Health Foundation; Baptist Health South Florida; Bon Secours Charity Health Systems, Bon Secours Community Hospital, Good Samaritan Hospital and St. Anthony Community Hospital; CHS/Community Health Systems and Campbell County HMA; CGH Medical Center; ChristianaCare (Christiana Care Health Services); Children's National Hospital; Christus Health; Hamilton Medical Center; Huntington Hospital (Pasadena Hospital Association); The Health Care Authority of the City of Huntsville; Integris Health; Jupiter Medical Center; Lake Regional Health System; Methodist Le Bonheur Healthcare; Mosaic Life Care (Heartland Regional Medical Center); Munson Healthcare; North Kansas City Hospital and Meritas Health; St. Joseph's Health; St. Marys Hospital of St. Marys County; Tallahassee Memorial HealthCare; Tampa General Hospital Citrus, Tampa General Hospital Hernando, Tampa General Medical Group and Florida Health Sciences Center; Union Health System; University Medical Center. LifeBridge Health and Sapphire Community Health were named earlier and dropped when the patients suing them dismissed their claims.
Posted their own notices (among others): Marshall Health Network (letters mailed June 5, 2026), Great River Health, ChristianaCare, LifeBridge Health and Glens Falls Hospital. Union Health reported 262,831 people to the HHS Office for Civil Rights, per HIPAA Journal, which also reported more than 100,000 Munson Healthcare patients and estimated that up to 80 hospitals may have been affected.
Being named in a lawsuit is an allegation by patients, not a finding. And a hospital missing here is not proof you are safe: we found no official list of affected Oracle Health customers.
Is There Money? Not Yet
If a settlement ever comes, healthcare-breach settlements have generally paid documented out-of-pocket losses first and a smaller flat amount to everyone else. With patients of many health systems in one case, a per-person flat payment could be small. Keep receipts for anything the breach costs you.
Oracle Health / Cerner Breach Timeline
- 1
January 22, 2025 — The Access Begins
An unauthorized party gets into legacy Cerner systems at least as early as this date, per the letters hospitals later mailed.
- 2
February 20, 2025 — Oracle Health Finds Out
Oracle Health's notice to hospital customers says it became aware on or around this date. Per Cerner's court filings, law enforcement then asks it to delay notifying customers.
- 3
April 11, 2025 — The Lead Case Is Filed
Blount v. Oracle Health, Inc. is filed in the Western District of Missouri. On June 30, 2025, Judge Beth Phillips consolidates 17 cases into it.
- 4
July 2025 to June 2026 — Letters in Waves
Cerner files a sample patient letter with California's Attorney General on July 25, 2025. ChristianaCare receives its patient list on September 29, 2025; Atrium Health's letters go out around April 30, 2026, per a complaint; Marshall Health Network mails on June 5, 2026.
- 5
June 22, 2026 — Negligence Claims Survive
Judge Phillips finds the patients have standing and keeps negligence claims against Cerner and the hospitals, while dismissing unjust enrichment, invasion of privacy and several other counts.
- 6
Now — More Hospitals, No Settlement
Short Form Complaints filed August 28 and September 3, 2026 add more health systems. As of September 30, 2026, there is no settlement, no fund and no claim form.
Three Things to Watch For
A breach that reached patients through their own hospitals — with letters arriving more than a year later — gives imposters plenty of cover:
“Oracle Health settlement” claim pages
There is no settlement, so there is no claims site. A page that wants your Social Security number or a fee to “register” for an Oracle Health or Cerner payout is collecting data, not filing anything.
Paid “protection” that copies the real letter
The real offer is free: the sample letter says no credit card is needed to enroll in Experian IdentityWorks. Real letters carry your hospital's name and an engagement number, and several hospitals post the same phone number and engagement number on their websites — compare before you call.
Bills for care you never got
The stolen records included diagnoses and medicines — and, per the patients' complaint, insurance details — enough to bill for treatment in your name. Read every statement from your insurer and providers and report anything you don't recognize, as the letters themselves advise.
Oracle Health Breach — Questions Patients Ask
Is my hospital part of the Oracle Health data breach?
The surest sign is a letter from your hospital that mentions Cerner. The list above shows health systems named in the court case or that posted their own notices. It is not complete: we found no official list of affected Oracle Health customers, and letters were still being mailed in June 2026. If you are unsure, call the number on your hospital's own notice page.
What is HealtheLife, and was it hacked?
HealtheLife is Cerner's patient portal, which many hospitals offer. The notices, court filings and reports we reviewed describe data taken from legacy Cerner data-migration servers; none says HealtheLife portal accounts or passwords were accessed. Changing your portal password does no harm, but your hospital's letter is what tells you whether your records were involved.
What was stolen in the Cerner data breach?
It varies by patient. Hospital letters list name, Social Security number and medical-record details: medical record numbers, doctors, diagnoses, medicines, test results, images, care and treatment. The Consolidated Complaint adds dates of birth, driver's license numbers, dates of service and health insurance information. Your own letter says which applied to you.
Is there an Oracle Health lawsuit settlement I can claim from?
No. As of September 30, 2026, In re: Cerner/Oracle Data Breach Litigation (No. 4:25-cv-00259-BP, W.D. Mo.) is in pretrial proceedings. There is no settlement, no fund, no claim form and no deadline. You do not need to sign up anywhere to be part of a future class; if a settlement is reached, notice goes out through a court-approved process.
Is the letter I received real?
Genuine letters come in your hospital's name, describe a breach at its EHR vendor Cerner, date the access to at least as early as January 22, 2025, and offer 24 months of Experian IdentityWorks with an engagement number. Hospitals such as ChristianaCare and Marshall Health Network posted matching notices online. If the phone number in your letter matches your hospital's own notice, it is very likely real.
Is this the same as other Oracle breaches in the news?
No. This page covers patient data taken from legacy Cerner servers. Around the same time, a hacker claimed to have breached Oracle Cloud login servers, which Oracle denied. Separately, The Estée Lauder Companies reported unauthorized access around August 9, 2025 to an Oracle E-Business Suite system it uses for HR. Those involve different systems and are not part of the Cerner case.
Why did notification take more than a year for some patients?
Cerner says law enforcement asked it to delay notifying its hospital customers. In September 2025, Cerner/Oracle told the court that all or most providers would be notified by the end of October 2025. Hospitals then reviewed their own patients' data — Atrium Health's letter says its review concluded on March 12, 2026. The patients argue the delay is part of the harm; the defendants dispute liability.
What should I do right now?
Enroll in the free Experian monitoring before the deadline in your letter. Freeze your credit at Equifax, Experian and TransUnion — free and reversible. Read your insurer's statements for care you never received. Keep the letter and envelope; they show which hospital's records were involved. You do not need to hire anyone to be included in a future class.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
Change Healthcare Data Breach
Where the Change Healthcare breach lawsuits stand
TriZetto Data Breach
Billing-vendor breach that reached patients through doctors
MyChart Class Action Tracker
Patient-portal pixel settlements, hospital by hospital
Data Breach Settlement Calculator
Estimate what a data-breach settlement might pay