Dailytech

Oracle Health Breach Hits Nearly 20 Million as Company Expands Investigation

Security·October 6, 2026

Oracle Health Breach Hits Nearly 20 Million as Company Expands Investigation

Oracle Health disclosed a significant data breach this week after discovering unauthorized access to systems containing sensitive health and personal information belonging to nearly 20 million individuals. The company, which provides electronic health records and patient management software to thousands of healthcare providers across North America, said the compromise stemmed from a cyberattack that went undetected for several months.

The scope of the breach extends across multiple healthcare organizations that use Oracle's cloud-based platforms. Compromised data includes patient names, medical record numbers, Social Security numbers, dates of birth, insurance information, and in some cases, clinical notes and diagnoses. Oracle said it discovered the intrusion in September and has since secured the affected systems and notified healthcare partners.

The timing of the disclosure comes as healthcare institutions face mounting pressure from regulators and lawmakers over cybersecurity practices. Healthcare data remains a prime target for criminals because it can be resold on dark web markets or used for identity theft and insurance fraud. Several major hospital networks have suffered ransomware attacks in recent years, disrupting patient care and costing hundreds of millions in recovery efforts.

Oracle said it is working with the FBI and other law enforcement agencies to investigate the breach and is offering affected individuals complimentary credit monitoring and identity theft protection services. The company did not reveal the identity of the attackers or specify how long the unauthorized access persisted before detection. Healthcare organizations using Oracle's systems are notifying patients and regulators as required by federal privacy laws.

Reporting based on an external source.